ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Vulnerability Exploitation on the Rise as Attackers Ditch Phishing

criticalVulnerability exploited in the wildimportance 60CVE-2023-34362CVE-2022-21587CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-21587
Unauthenticated Arbitrary File Upload in Oracle E-Business Suite

Oracle E-Business Suite versions 12.2.3 through 12.2.11 contain a critical, unauthenticated arbitrary file upload flaw (CWE-306, missing authentication) in the Upload component of the Web Applications Desktop Integrator. Because exploitation requires no credentials and no user interaction, any attacker with HTTP network access to the affected component can trigger the flaw remotely and achieve takeover of Oracle Web Applications Desktop Integrator, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Organizations running any affected E-Business Suite 12.2 release are exposed, particularly where EBS interfaces are reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-02 with known ransomware use, EPSS assigns a 98.3% probability of exploitation within 30 days, and exploitation attempts were observed after a public proof-of-concept was released.

Do: Apply the Oracle Critical Patch Update that addresses CVE-2022-21587 (October 2022 CPU or later) on all E-Business Suite 12.2.3-12.2.11 systems, per CISA's required action. Until patched, restrict internet access to EBS, especially the Web Applications Desktop Integrator upload endpoints, and review logs and uploaded-file locations for signs of exploitation. Prioritize remediation given confirmed active exploitation and ransomware use.

9.898% KEV ransomware PoC
  • Oracle E-Business Suite (Web Applications Desktop Integrator, Upload component) 12.2.3 through 12.2.11
largetens of thousands of E-Business Suite deployments worldwide, with thousands of internet-exposed instances (estimate)
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
CVE-2023-34362
Unauthenticated SQL Injection in Progress MOVEit Transfer

CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.

Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies.

9.8100% KEV ransomware PoC
  • Progress MOVEit Transfer
large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans)
Full article851 words · extracted from infosecurity-magazine.com · click to collapse

In a move away from traditional phishing scams, attackers are increasingly exploiting vulnerabilities in computer systems to gain initial network access, according to Mandiant’s M-Trends 2024 Report.

In 2023, attackers gained initial access through exploiting vulnerabilities in 38% of intrusions, a 6% increase from the previous year.

Mandiant also found phishing’s prevalence declined from 22% of intrusions in 2022 to 17% in 2023. However, it was still the second most common initial access vector assessed by Mandiant.

Zero-Day Vulnerabilities Actively Exploited

Researchers observed 97 unique zero-day vulnerabilities exploited in the wild in 2023, up by 56% compared to 2022.

Chinese cyber espionage groups were the most prolific attackers to exploit zero-days, primarily for the purposes of intelligence gathering and strategic advantage. Vulnerabilities that are unknown to software vendors can provide long term access to systems and sensitive data.

Additionally, financially motivated cybercriminals continued to utilize zero-days to infiltrate systems and steal financial data. This includes a group tracked as FIN11, which frequently targets file transfer applications that can provide fast access to large amounts of sensitive data.

The most frequently targeted vulnerability observed by Mandiant in 2023 was CVE-2023-34362, a high-risk SQL injection vulnerability in MOVEit Transfer.

This was followed by CVE-2022-21587, a critical unauthenticated file upload vulnerability in Oracle E-Business Suite.

In third place was CVE-2023-2868, a critical command injection vulnerability in Barracuda Email Security Gateways.

Stuart McKenzie, EMEA Consulting MD at Mandiant, a subsidiary of Google, noted phishing is now often used to steal credentials for later credential-based attacks rather than to deploy malware.

This is partly a result of improved security tooling that protects users from receiving malicious email messages.

The shift towards software vulnerability exploitation requires a more sophisticated approach by attackers compared to traditional “spray and hope” phishing attacks.

Zero day and n-day vulnerabilities, which are either not discovered or patched, allow attackers to pick and choose how they target organizations at their leisure.

McKenzie said: “If you’ve got time on your side, you’re able to deploy those against any organizations when you want to.”

Initial infection vector in 2023 (when identified). Source: Mandiant
Initial infection vector in 2023 (when identified). Source: Mandiant

Ransomware Drives Down Dwell Time

Attacker dwell time – the period from compromise to detection – fell to just 10 days in 2023 from 16 in 2022, Mandiant found.

While this demonstrates advancements in detection capabilities, Mandiant cautioned that the growth in ransomware attacks in 2023 helped drive down dwell time as the threat actors wanted their presence to be known to launch extortion negotiations.

For example, for ransomware-related intrusions, 70% of organizations were externally notified, mostly by the attackers.

McKenzie explained: “We see a lot more cybercriminals interested in ransomware. For a ransomware attack to be successful, they need to organization to know.”

The median global dwell time for ransomware intrusions was five days in 2023, which compares to 13 days for non-ransomware intrusions.

Global dwell time by investigation type 2023. Source: Mandiant
Global dwell time by investigation type 2023. Source: Mandiant

The proportion of global investigations involving ransomware increased by five percentage points to 23% last year compared to the 2023 M-Trends report.

Despite this, Mandiant found many attackers are focusing on evasion to maintain persistence on networks for as long as possible. This is particularly the case for those targeting data theft or nation-state groups.

McKenzie noted threat actors are moving away from targeting endpoints due to significant improvements in endpoint detection and response (EDR). Therefore, they are increasingly targeting edge devices, such as routers and email gateways.

“Not many companies have detection capabilities there, so the attackers move to where they can be most successful,” said McKenzie.

Over 4000 Threat Groups Tracked by Mandiant

Mandiant revealed that it tracks more than 4000 threat groups, 719 of which were newly tracked in 2023.

A high proportion of the groups tracked are designated as uncategorized (UNC). UNC means that new threat activity encountered cannot confidently be linked to an existing group.

Over half (52%) of the groups tracked by Mandiant in 2023 were primarily motivated by financial gain, up from 48% in 2022, while 10% principally pursued espionage activities.

Just 2% were judged to be operating for hacktivist motivations. In 36% of threat groups, a specific motivation could not be determined.

The increase in financially motivated groups is partially explained by the growth in ransomware-related activity, the researchers said. Of all financially motivated intrusions tracked by Mandiant, ransomware made up almost two-thirds of cases.

McKenzie observed that attributing attacks to particular groups is becoming harder due to the complex cybercrime ecosystem, with many incidents now involving multiple actors.

“We’ve seen such a change in the lifecycle between the initial access, onto the access brokers, onto the criminal group – it’s no longer a single flow,” he noted.

Ransomware-as-a-service (RaaS) groups also have a number of affiliates using their tooling, further complicating the picture for threat researchers, McKenzie added.

In a separate report published on April 17, Mandiant announced it had upgraded the Russian state group known as Sandworm into a named Advanced Persistent Threat (APT) group, APT44.

This is due to the scale of the group’s cyber activities targeting Ukraine since Russia invaded the region in 2022.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/vulnerability-exploitation-rise/