Security Affairs newsletter Round 487 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22527 | Unauthenticated OGNL Template Injection RCE in Atlassian Confluence Data Center/Server Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability (CWE-74) in which attacker-controlled input is evaluated by the application as an OGNL expression. A remote, unauthenticated attacker can trigger the flaw by sending a crafted HTTP request that injects OGNL expressions, which the server then executes. Successful exploitation leads to remote code execution on the host running Confluence, giving the attacker control of the system without any credentials. Any organization running self-hosted Confluence Data Center or Server is potentially affected — the available data does not specify version ranges, so operators should consult Atlassian's advisory — with internet-facing instances at highest risk. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-24 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). Do: Patch to the fixed release specified in Atlassian's advisory immediately, prioritizing internet-exposed instances, since the flaw is in CISA's KEV with known ransomware use and carries a 100% EPSS. If patching is not immediately possible, apply the vendor's mitigations per the KEV required action — or discontinue/restrict use — for example by limiting unauthenticated access to Confluence from the internet. Review Confluence access and application logs for anomalous unauthenticated requests and indicators of command execution or ransomware activity. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed Confluence instances (order of 10,000–100,000) | |
| CVE-2024-37085 | Authentication Bypass in VMware ESXi via AD Group Recreation VMware ESXi is vulnerable to an authentication bypass (CWE-305) when the host is configured to use Active Directory for user management. An attacker who has sufficient Active Directory permissions can delete the AD group tied to ESXi administration (typically the default 'ESXi Admins' group) and then re-create it, causing ESXi to treat the re-created group as the original administrator group. This grants the actor full access to the ESXi host without needing ESXi credentials themselves. Only ESXi hosts that were joined to and configured with Active Directory for user management are affected; hosts using local authentication are not. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-30 with known ransomware use, and EPSS assigns a high 26.8% probability of exploitation in the next 30 days (98th percentile). Do: Apply the security updates or mitigations published in the vendor's (VMware/Broadcom) advisory for your ESXi release, per the CISA KEV required action. As interim mitigation, protect the configured AD admin group (default 'ESXi Admins') from deletion or re-create it with the original identity, and restrict AD permissions that allow arbitrary group deletion. Since ransomware use is known, audit AD logs for deletion/re-creation of the 'ESXi Admins' group and verify integrity of any AD-joined ESXi hosts. | 7.2 | 27% | KEV ransomware |
| mass≈100,000+ ESXi hosts (tens of thousands are internet-exposed in public scans, and the installed base is far larger, though only AD-joined hosts are vulnerable) |
Full article785 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 01, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
Telegram messaging app CEO Durov arrested in France
Thousands of travelers, airport operations impacted by Port of Seattle cyberattack
Hacker who stole 3 billion US data was discovered and is Brazilian
Reward for Information: Belarusian National Volodymyr Kadariya
Phishing in Style: Microsoft Sway Abused to Deliver Quishing Attacks
French Authorities Charge Telegram CEO with Facilitating Criminal Activities on Platform
Scam Sites at Scale: LLMs Fueling a GenAI Criminal Revolution
2 men from Europe charged with ‘swatting’ plot targeting former US president and members of Congress
Malware
Unveiling “sedexp”: A Stealthy Linux Malware Exploiting udev Rules
Malware infiltrates Pidgin messenger’s official plugin repository
RansomHub ransomware-as-a-service
StopRansomware: RansomHub Ransomware
The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers “Voldemort”
Hacking
Identify and Exploit Vulnerabilities in Routers: An Introductory Guide & Technical Case Studies
How to discover a major hacker’s identity with OSINT — Solution 1
May 2024 Cyber Attacks Statistics
Beware the Unpatchable: Corona Mirai Botnet Spreads via Zero-Day
Linux Detection Engineering – A Sequel on Persistence Mechanism
How AitM Phishing Attacks Bypass MFA and EDR—and How to Fight Back
Analysis of two arbitrary code execution vulnerabilities affecting WPS Office
Threat Actors Target the Middle East Using Fake Palo Alto GlobalProtect Tool
When Get-Out-The-Vote Efforts Look Like Phishing
Bypassing airport security via SQL injection
Intelligence and Information Warfare
New 0-Day Attacks Linked to China’s ‘Volt Typhoon’
Taking the Crossroads: The Versa Director Zero-Day Exploitation
Peach Sandstorm deploys new custom Tickler malware in long-running intelligence gathering operations
Telegram Founder Was Wooed and Targeted by Governments
I Spy With My Little Eye: Uncovering an Iranian Counterintelligence Operation
Russian government hackers found using exploits made by spyware companies NSO and Intellexa
State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
North Korean threat actor Citrine Sleet exploiting Chromium zero-day
North Korea Still Attacking Developers via npm
Cybersecurity
FAA to issue cyber rule for newly built airplanes and equipment
SonicWall Issues Critical Patch for Firewall Vulnerability Allowing Unauthorized Access
Dutch DPA imposes a fine of 290 million euro on Uber because of transfers of drivers’ data to the US
Research AI model unexpectedly attempts to modify its own code to extend runtime
Chinese broadband satellites may be Beijing’s flying spying censors, think tank warns
EU investigating Telegram over user numbers
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167865/breaking-news/security-affairs-newsletter-round-487-by-pierluigi-paganini-international-edition.html