ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 436 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2023-34039CVE-2023-33246

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33246
Unauthenticated Remote Command Execution in Apache RocketMQ

CVE-2023-33246 is an unauthenticated remote command execution flaw in Apache RocketMQ: when NameServer, Broker, or Controller components are exposed without access controls, an attacker can invoke the update-configuration function or forge RocketMQ protocol messages to inject and run operating-system commands. Commands execute with the privileges of the system user running RocketMQ, giving an attacker full control of the message broker host. Any organization running RocketMQ 5.1.0 or below (5.x) or versions below 4.9.6 (4.x) with these components reachable by untrusted networks is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-06, carries a 96.6% EPSS probability of exploitation, has multiple public PoC exploits, and is being leveraged by the Muhstik botnet to expand DDoS operations alongside other malware campaigns.

Do: Upgrade to RocketMQ 5.1.1 or above for 5.x deployments, or 4.9.6 or above for 4.x, per the KEV required action. Until patched, restrict NameServer, Broker, and Controller ports to trusted clients only and avoid exposing them to the internet without authentication or access filtering. Check patched hosts for signs of compromise (unauthorized processes, cron jobs, or botnet activity such as Muhstik), since active exploitation is documented.

9.897% KEV PoC ×4
  • Apache RocketMQ 5.x through 5.1.0 (upgrade to 5.1.1 or above)
  • Apache RocketMQ 4.x below 4.9.6 (upgrade to 4.9.6 or above)
largeTens of thousands of internet-exposed instances plausible (thousands confirmed in public scans; total installed base larger, exact count unknown)
CVE-2023-34039
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

NVD description · AI analysis pending
9.867% PoC
  • vmware aria operations for networks
Full article699 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 10, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog
Ragnar Locker gang leaks data stolen from the Israel’s Mayanei Hayeshua hospital
North Korea-linked threat actors target cybersecurity experts with a zero-day
Zero-day in Cisco ASA and FTD is actively exploited in ransomware attacks
Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warns
Zero-days fixed by Apple were used to deliver NSO Group’s Pegasus spyware
Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs
A malvertising campaign is delivering a new version of the macOS Atomic Stealer
Two flaws in Apache SuperSet allow to remotely hack servers
Chinese cyberspies obtained Microsoft signing key from Windows crash dump due to a mistake
Google addressed an actively exploited zero-day in Android
A zero-day in Atlas VPN Linux Client leaks users’ IP address
MITRE and CISA release Caldera for OT attack emulation
ASUS routers are affected by three critical remote code execution flaws
Hackers stole $41M worth of crypto assets from crypto gambling firm Stake
Freecycle data breach impacted 7 Million users
Meta disrupted two influence campaigns from China and Russia
A massive DDoS attack took down the site of the German financial agency BaFin
X will collect biometric data from its premium users
“Smishing Triad” Targeted USPS and US Citizens for Data Theft
Publicly available Evil_MinIO exploit used in attacks on MinIO Storage Systems
University of Sydney suffered a security breach caused by a third-party service provider
Cybercrime will cost Germany $224 billion in 2023
PoC exploit code released for CVE-2023-34039 bug in VMware Aria Operations for Networks
LockBit ransomware gang hit the Commission des services electriques de Montréal (CSEM)

Cybercrime

“Smishing Triad” Targeted USPS And US Citizens For Data Theft   

Crypto gambling site Stake sees $41M withdrawn in confirmed hack

Cisco warns of VPN zero-day exploited by ransomware gangs

Massive DDoS attack on U.S. financial company thwarted by cyber firm  

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach  

Russian infosec boss gets nine years for $100M insider-trading caper using stolen data

Pandora’s box is now open: the well-known Mirai trojan arrives in a new disguise to Android-based TV sets and TV boxes  

Malware

Mac users targeted in new malvertising campaign delivering Atomic Stealer  

NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild   

CISA: Malware Analysis Report – Attack on Aeronautical Sector organization

Hacking

VMWARE Aria Operations for Networks  

New Attack Vector In The Cloud: Attackers caught exploiting Object Storage Services   

German financial agency site disrupted by DDoS attack since Friday

7 Million Users Possibly Impacted by Freecycle Data Breach        

From NTAuthCertificates to “Silver” Certificate   

Zero-Day Alert: Latest Android Patch Update Includes Fix for Newly Actively Exploited Flaw

Apache Superset Part II: RCE, Credential Harvesting and More  

Exposing RocketMQ CVE-2023-33246 Payloads  

Intelligence and Information Warfare

Raising Online Defenses Through Transparency and Collaboration  

Results of Major Technical Investigations for Storm-0558 Key Acquisition  

CNMF and Partners Illuminate Multiple Nation-State Exploitation Efforts  

Active North Korean campaign targeting security researchers  

Probe reveals DHS relies on fake social media accounts to investigate targets  

Potential New EvilNum Campaign  

The International Criminal Court Will Now Prosecute Cyberwar Crimes  

Cybersecurity

National Grid to set ‘honeypots’ to trap hackers – amid rising risk from digitisation  

Who’s Your Next Cyber Chief? Good Question  

ASUS routers vulnerable to critical remote code execution flaws

MITRE & CISA Release Open-Source MITRE Caldera™ Extension for Operational Technology   

How Quantum Computing Will Impact Cybersecurity

Apple discloses 2 new zero-days exploited to attack iPhones, Macs

A Brief History of the Internet’s Biggest BGP Incidents  

Make smart choices to protect your privacy. Search for products. Read expert reviews. Get tips and tricks  

Norway court rules against Facebook owner Meta in privacy case   

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150562/breaking-news/security-affairs-newsletter-round-436-by-pierluigi-paganini-international-edition.html