Security Affairs newsletter Round 436 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-33246 | Unauthenticated Remote Command Execution in Apache RocketMQ CVE-2023-33246 is an unauthenticated remote command execution flaw in Apache RocketMQ: when NameServer, Broker, or Controller components are exposed without access controls, an attacker can invoke the update-configuration function or forge RocketMQ protocol messages to inject and run operating-system commands. Commands execute with the privileges of the system user running RocketMQ, giving an attacker full control of the message broker host. Any organization running RocketMQ 5.1.0 or below (5.x) or versions below 4.9.6 (4.x) with these components reachable by untrusted networks is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-06, carries a 96.6% EPSS probability of exploitation, has multiple public PoC exploits, and is being leveraged by the Muhstik botnet to expand DDoS operations alongside other malware campaigns. Do: Upgrade to RocketMQ 5.1.1 or above for 5.x deployments, or 4.9.6 or above for 4.x, per the KEV required action. Until patched, restrict NameServer, Broker, and Controller ports to trusted clients only and avoid exposing them to the internet without authentication or access filtering. Check patched hosts for signs of compromise (unauthorized processes, cron jobs, or botnet activity such as Muhstik), since active exploitation is documented. | 9.8 | 97% | KEV PoC ×4 |
| largeTens of thousands of internet-exposed instances plausible (thousands confirmed in public scans; total installed base larger, exact count unknown) | |
| CVE-2023-34039 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI. NVD description · AI analysis pending | 9.8 | 67% | PoC |
| — |
Full article699 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 10, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
Cybercrime
“Smishing Triad” Targeted USPS And US Citizens For Data Theft
Crypto gambling site Stake sees $41M withdrawn in confirmed hack
Cisco warns of VPN zero-day exploited by ransomware gangs
Massive DDoS attack on U.S. financial company thwarted by cyber firm
Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach
Russian infosec boss gets nine years for $100M insider-trading caper using stolen data
Malware
Mac users targeted in new malvertising campaign delivering Atomic Stealer
NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
CISA: Malware Analysis Report – Attack on Aeronautical Sector organization
Hacking
VMWARE Aria Operations for Networks
New Attack Vector In The Cloud: Attackers caught exploiting Object Storage Services
German financial agency site disrupted by DDoS attack since Friday
7 Million Users Possibly Impacted by Freecycle Data Breach
From NTAuthCertificates to “Silver” Certificate
Zero-Day Alert: Latest Android Patch Update Includes Fix for Newly Actively Exploited Flaw
Apache Superset Part II: RCE, Credential Harvesting and More
Exposing RocketMQ CVE-2023-33246 Payloads
Intelligence and Information Warfare
Raising Online Defenses Through Transparency and Collaboration
Results of Major Technical Investigations for Storm-0558 Key Acquisition
CNMF and Partners Illuminate Multiple Nation-State Exploitation Efforts
Active North Korean campaign targeting security researchers
Probe reveals DHS relies on fake social media accounts to investigate targets
Potential New EvilNum Campaign
The International Criminal Court Will Now Prosecute Cyberwar Crimes
National Grid to set ‘honeypots’ to trap hackers – amid rising risk from digitisation
Who’s Your Next Cyber Chief? Good Question
ASUS routers vulnerable to critical remote code execution flaws
MITRE & CISA Release Open-Source MITRE Caldera™ Extension for Operational Technology
How Quantum Computing Will Impact Cybersecurity
Apple discloses 2 new zero-days exploited to attack iPhones, Macs
A Brief History of the Internet’s Biggest BGP Incidents
Norway court rules against Facebook owner Meta in privacy case
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150562/breaking-news/security-affairs-newsletter-round-436-by-pierluigi-paganini-international-edition.html