ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2883
Unauthenticated RCE in Oracle WebLogic Server via T3/IIOP

CVE-2020-2883 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle WebLogic Server that is reachable over the network via the T3 and IIOP protocols. An attacker with network access to a WebLogic listener can trigger the flaw without credentials or user interaction, and successful exploitation results in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact. The supported affected releases are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Oracle rates the flaw CVSS 9.8 (Critical), and it carries a very high EPSS of 94.9% (100th percentile), indicating near-certain near-term exploitation likelihood. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 amid active exploitation, with reports of hackers targeting WebLogic servers and the flaw included in Oracle's January 2025 patch cycle.

Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server — Oracle's January 2025 patch release includes WebLogic fixes, and the affected releases (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0) must be patched per vendor instructions. Until patched, restrict network access to the T3 and IIOP listeners (e.g., firewall them to trusted hosts only), prioritize internet-facing instances, and hunt for signs of exploitation. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.895% KEV
  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
largetens of thousands of internet-exposed WebLogic instances
CVE-2024-41713
Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging

CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days.

Do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement).

9.198% KEV ransomware
  • Mitel MiCollab (NuPoint Unified Messaging component) through 9.8 SP1 FP2 (9.8.1.201)
largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed
CVE-2024-55550
Authenticated Path Traversal in Mitel MiCollab Enables Local File Reading

Mitel MiCollab contains a path traversal vulnerability (CWE-22) caused by insufficient input sanitization of file-path input. It is triggered when an authenticated user with administrative privileges submits crafted paths that escape the intended directory, allowing the attacker to read local files on the MiCollab server. On its own the flaw requires admin credentials, but it can be chained with CVE-2024-41713, an unauthenticated remote arbitrary file-read flaw in the same product, enabling remote attackers to read files without valid credentials. Any organization running Mitel MiCollab is affected; the available data does not specify affected or fixed version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, although no public proof-of-concept is known.

Do: Apply Mitel's updates or mitigations per the vendor advisory immediately, prioritizing internet-facing MiCollab servers, and address the chained CVE-2024-41713 issue in the same maintenance cycle; where mitigations are unavailable, restrict or discontinue use per CISA KEV guidance. Check the Mitel advisory for exact fixed versions (not provided here), limit administrative access to trusted users, and review server logs for evidence of arbitrary file reads or follow-on ransomware activity.

2.738% KEV ransomware
  • Mitel MiCollab
moderatethousands of internet-exposed MiCollab servers (roughly 1k-10k instances)
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
Full article970 words · extracted from helpnetsecurity.com · click to collapse

Week in review

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)
Ivanti has fixed two vulnerabilities affecting Ivanti Connect Secure, Policy Secure and ZTA gateways, one of which (CVE-2025-0282) has been exploited as a zero-day by attackers to compromise Connect Secure VPN appliances.

January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance
Microsoft released a small set of updates that only applied to Windows 10, Windows 11, Office, and Sharepoint. There were no standalone SSU updates and only a single development tool update for the relatively obscure Microsoft/Muzic.

Job-seeking devs targeted with fake CrowdStrike offer via email
Cryptojackers are impersonating Crowdstrike via email to get developers to unwittingly install the XMRig cryptocurrency miner on their Windows PC, the company has warned.

Banshee Stealer variant targets Russian-speaking macOS users
The Banshee Stealer is a stealthy threat to the rising number of macOS users around the world, including those in Russian-speaking countries, according to Check Point researcher Antonis Terefos.

Preventing the next ransomware attack with help from AI
In this Help Net Security interview, Dr. Darren Williams, CEO at BlackFog, talks about how employee training plays a crucial role in preventing ransomware attacks.

The U.S. Cyber Trust Mark set to launch
The White House has announced the launch of the U.S. Cyber Trust Mark, a voluntary cybersecurity labeling program for consumer-grade internet-connected devices.

GitLab CISO on proactive monitoring and metrics for DevSecOps success
In this Help Net Security interview, Josh Lemos, CISO at GitLab, talks about the shift from DevOps to DevSecOps, focusing on the complexity of building systems and integrating security tools.

Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackers
CISA has added Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic Server (CVE-2020-2883) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

Scaling penetration testing through smart automation
In this Help Net Security interview, Marko Simeonov, CEO of Plainsea, discusses how organizations can move beyond compliance-driven penetration testing toward a more strategic, risk-based approach.

UN aviation agency investigating possible data breach
The United Nation’s International Civil Aviation Organization (ICAO) confirmed on Monday that it’s “actively investigating reports of a potential information security incident allegedly linked to a threat actor known for targeting international organizations.”

eBay CISO on managing long-term cybersecurity planning and ROI
In this Help Net Security interview, Sean Embry, CISO at eBay, discusses key aspects of cybersecurity leadership.

CISA says Treasury was the only US agency breached via BeyondTrust
The US Cybersecurity and Infrastructure Security Agency (CISA) has shared on Monday that the Treasury Department was the only US federal agency affected by the recent cybersecurity incident involving compromised BeyondTrust Remote Support SaaS instances.

Balancing proprietary and open-source tools in cyber threat research
In this Help Net Security interview, Thomas Roccia, Senior Security Researcher at Microsoft, discusses how threat research drives faster, better decision-making in cybersecurity operations.

The SBI fake banking app shows that SMS authentication has had its day
As a company fortunate enough to have and maintain our own pentesting team, we often do outreach with other organizations to assist with or provide our expertise in offensive security.

Open source worldwide: Critical maintenance gaps exposed
In this Help Net Security video, Nick Mistry, SVP and CISO of Lineaje, discusses where the deepest layers of open-source software component dependencies originate from and their critical vulnerabilities.

Users receive at least one advanced phishing link every week
Phishing remains one of the most significant cyber threats impacting organizations worldwide, according to SlashNext.

Cybersecurity in 2025: Global conflict, grown-up AI, and the wisdom of the crowd
As we look ahead to cybersecurity developments in 2025, there’s bad news and good—expect to see new challenging attacks and the cybersecurity community increasingly working together to counter threats that are beyond the scope of individual organizations.

Sara: Open-source RouterOS security inspector
Sara is an open-source tool designed to analyze RouterOS configurations and identify security vulnerabilities on MikroTik hardware.

Only 26% of Europe’s top companies earn a high rating for cybersecurity
With the EU’s Digital Operational Resilience Act (DORA) deadline approaching on 17th January, 2025, Europe’s top 100 companies face an urgent cybersecurity challenge, according to SecurityScorecard.

Why an “all gas, no brakes” approach for AI use won’t work
Machine learning and generative AI are changing the way knowledge workers do their jobs. Every company is eager to be “an AI company,” but AI can often seem like a black box, and the fear of security, regulatory and privacy risks can stymie innovation.

The top target for phishing campaigns
Despite organizations’ repeated attempts at security awareness training, with a particular emphasis on how employees can avoid being phished, in 2024 enterprise users clicked on phishing lures at a rate nearly three times higher than in 2023, according to Netskope.

Making the most of cryptography, now and in the future
Enterprise cryptography faces risks beyond just the advent of quantum computers.

Cyberbro: Open-source tool extracts IoCs and checks their reputation
Cyberbro is an open-source application that extracts IoCs from garbage input and checks their reputation using multiple services.

How AI and deepfakes are redefining social engineering threats
This article presents key insights from 2024 reports on the rise of phishing attacks, focusing on how advancements in AI and deepfake technology are making social engineering tactics more sophisticated.

Is healthcare cybersecurity in critical condition?
This article highlights key findings and trends in healthcare cybersecurity for 2024.

Cybersecurity jobs available right now: January 8, 2025
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: January 10, 2025
Here’s a look at the most interesting products from the past week, featuring releases from BioConnect, BreachLock, McAfee, Netgear, and Swimlane.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/12/week-in-review-exploited-ivanti-connect-secure-zero-day-patch-tuesday-forecast/