ZeroHour
The Recordpublished ()ingested

Allied spy agencies blame 3 Chinese tech companies for Salt Typhoon attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21887
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
CVE-2024-3400
Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect

Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Palo Alto Networks PAN-OS
large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled
Full article517 words · extracted from therecord.media · click to collapse

Intelligence and cybersecurity agencies from more than a dozen allied countries published an advisory on Wednesday blaming three Chinese technology companies for cyber-espionage campaigns targeting global critical infrastructure.

The activity identified by the intelligence services partially overlaps with campaigns reported by the cybersecurity industry and tracked as Salt Typhoon, RedMike, OPERATOR PANDA, UNC5807 and Ghost Emperor among others, stated the document.

The campaign first came to light last year after threat actors intercepted the correspondence of senior officials within both presidential campaigns, including from President-elect Donald Trump and his running mate JD Vance. In December, U.S. officials said dozens of other countries had been impacted.

The group more recently breached devices linked to seven telecommunications companies — including Comcast and MTN Group — since February, according to research from Recorded Future. The Record is an editorially independent unit of the company.

Thirteen countries co-sealed the announcement on Wednesday, including agencies from the United States, Australia, Canada, New Zealand, United Kingdom, Czech Republic, Finland, Germany, Italy, Japan, Netherlands, Poland and Spain.

The three Chinese companies — Huanyu Tianqiong Information Technology Co., Ltd, Sichuan Zhixin Ruijie Network Technology Co., Ltd and Sichuan Juxinhe Network Technology Co. Ltd, which was sanctioned by the United States back in January — were accused of providing “cyber-related products and services to China’s intelligence services, including multiple units in the People’s Liberation Army and Ministry of State Security” since at least 2021, according to the advisory.

Data obtained through these companies’ intrusions against the telecommunications, lodging and transportation sectors, has provided “Chinese intelligence services with the capability to identify and track their targets’ communications and movements around the world,” it warned.

A list of vulnerabilities included in the advisory include CVE-2024-21887, which in January the U.S. Cybersecurity and Infrastructure Security Agency warned was being exploited in attacks targeting federal agencies, and CVE-2024-3400, a zero-day discovered in Palo Alto Networks’ VPN product in April last year.

The advisory comes as Brett Leatherman, the top cyber official at the FBI, told the Wall Street Journal that more than 80 countries had been impacted by a China-sponsored espionage campaign known as Salt Typhoon targeting telecommunications providers.

Richard Horne, the chief executive of Britain’s National Cyber Security Centre, said: “We are deeply concerned by the irresponsible behaviour of the named commercial entities based in China that has enabled an unrestrained campaign of malicious cyber activities on a global scale.

“It is crucial organisations in targeted critical sectors heed this international warning about the threat posed by cyber actors, who have been exploiting publicly known — and so therefore fixable — vulnerabilities.”

The advisory stresses that these bugs have all been patched and provides remediation advice for companies still running the exploitable software, as well as ways for companies in the co-authors’ countries to contact their respective cybersecurity authorities.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/allied-spy-agencies-blame-chinese-companies-salt-typhoon