ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Five Eyes agencies detail how Chinese hackers breached US infrastructure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-27860
Unauthenticated Arbitrary File Upload in FatPipe WARP, IPVPN, and MPVPN

CVE-2021-27860 is an unrestricted file upload flaw (CWE-434) in the web management interface of FatPipe WARP, IPVPN, and MPVPN appliances, allowing a remote, unauthenticated attacker to upload a file to any location on the device's filesystem. It is triggered simply by sending an upload request to the exposed management interface, with no credentials required. An attacker who abuses it can place files anywhere on the appliance, which can be used to tamper with device configurations or plant files that may enable further compromise or code execution. Any organization running an internet-exposed FatPipe WARP, IPVPN, or MPVPN device — typically deployed as edge/SD-WAN and WAN failover appliances at enterprise and branch sites — is affected. The flaw is confirmed exploited in the wild (added to CISA KEV on 2022-01-10), carries a high EPSS of 39.8% (99th percentile) for near-term exploitation, and while no public PoC is known, ransomware involvement is listed as unknown.

Do: Apply updates per vendor instructions, as required by CISA's KEV listing, since no specific fixed version numbers are provided in this data. In the interim, restrict access to the FatPipe web management interface with firewall rules or ACLs so it is not reachable from the internet. Check exposed devices for unexpected or recently modified files and configuration changes, given the unknown possibility of ransomware-related abuse.

8.840% KEV PoC
  • FatPipe WARP software
  • FatPipe IPVPN software
  • FatPipe MPVPN software
moderatelikely on the order of thousands to low tens of thousands of internet-exposed FatPipe appliances (estimate; no public scan count provided)
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
Full article308 words · extracted from helpnetsecurity.com · click to collapse

The National Security Agency (NSA) and Five Eyes partner agencies have identified indicators of compromise associated with a People’s Republic of China (PRC) state-sponsored cyber actor dubbed Volt Typhoon, which is using living off the land techniques to target networks across US critical infrastructure.

Volt Typhoon loves living off the land

The joint cybersecurity advisory provides an overview of hunting guidance and associated best practices. It includes examples of the actor’s commands and detection signatures.

The authoring agencies also includes a summary of indicators of compromise (IOC) values, such as unique command-line strings, hashes, file paths, exploitation of CVE-2021-40539 and CVE-2021-27860 vulnerabilities, and file names commonly used by this actor.

As one of their primary tactics, techniques, and procedures (TTP) of living off the land, the PRC actor uses tools already installed or built into a target’s system. This allows the actor to evade detection by blending in with normal Windows systems and network activities, avoiding endpoint detection and response (EDR) products, and limiting the amount of activity that is captured in default logging configurations.

Detection and threat hunting

The NSA recommends network defenders apply the detection and hunting guidance in the cybersecurity advisory, such as logging and monitoring of command line execution and WMI events, as well as ensuring log integrity by using a hardened centralized logging server, preferably on a segmented network.

Defenders should also monitor logs for Event ID 1102, which is generated when the audit log is cleared.

The behavioral indicators noted in the CSA can also be legitimate system administration commands that appear in benign activity. Defenders must evaluate matches to determine the significance, applying their knowledge of the system and baseline behavior.

Microsoft and Secureworks researchers have also released details about the Volt Typhoon (aka Bronze Silhouette) campaigns they detected. They have shared indicators of compromise and mitigation and protection guidance.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/05/25/volt-typhoon/