UK cyber chief warns country is ‘widely underestimating’ risks from cyberattacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20198 | Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited) CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported. Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions. | 10.0 | 100% | KEV |
| large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions | |
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled |
Full article656 words · extracted from therecord.media · click to collapse
The cyber risks facing the United Kingdom are being “widely underestimated,” the country’s new cyber chief will warn on Tuesday as he launches the National Cyber Security Centre’s (NCSC) annual review. In his first major speech since joining the NCSC — part of the signals and cyber intelligence agency GCHQ — Richard Horne will drive a shift in tone in how the cybersecurity agency communicates these risks. Despite some evidence showing cyberattacks growing year-on-year for half a decade, the NCSC has not previously confirmed the trend nor expressed alarm about it. “What has struck me more forcefully than anything else since taking the helm at the NCSC is the clearly widening gap between the exposure and threat we face, and the defences that are in place to protect us,” Horne will say, according to an advance preview of his speech on Tuesday. Citing the intelligence that NCSC has access to as an agency within GCHQ, Horne will warn that “hostile activity in UK cyberspace has increased in frequency, sophistication and intensity,” adding that despite growing activity from Russian and Chinese threat actors, the agency believes British society as a whole is failing to appreciate the severity of the risk. The annual review reveals that the agency’s incident management team handled a record number of cyber incidents over the past 12 months — 430 compared to 371 last year — 89 of which were considered nationally significant incidents. NCSC did not break down how many of these were caused by state-sponsored cyber attackers versus financially-motivated criminals, but said 13 of the 89 incidents were ransomware attacks. Six of the nationally significant incidents were attributed to the exploitation of two zero-day vulnerabilities: CVE-2023-20198 in Cisco IOS XE, which was previously connected to cyberattacks in Norway; and CVE-2024-3400 in Palo Alto Networks PAN OS, a vulnerability that U.S. authorities said was being exploited by the Iranian government in concert with ransomware groups. Ransomware generally is described in the review as continuing “to pose the most immediate and disruptive threat to our critical national infrastructure, with some state-linked cyber groups now targeting the industrial control systems that infrastructure relies on.” “There is a widening gap between the increasingly complex threats and our collective defensive capabilities in the UK, particularly around our critical national infrastructure (CNI),” the report states. “That widening gap will only become more pronounced over time as the scale and capability of cyber actors proliferates, the relationship between state and non-state actors becomes more obfuscated, and states’ abilities to understand cyber activity becomes fraught. It is therefore vital we increase our cyber resilience across the whole of the UK, and that we do so with urgency.” The review dedicates the most space to China among foreign threats. Although unlike the United States the U.K. has not announced any targeting of its infrastructure by the Chinese hacking group tracked as Volt Typhoon, it has publicly accused Beijing of “carrying out malicious cyber activity targeting U.K. institutions and individuals important to our democracy.” The document repeats the government's praise for NCSC's certification scheme, Cyber Essentials, but acknowledges criticisms about the low levels of adoption. Out of more than five million eligible organizations in Britain, as of the end of this February only just over 31,000, or fewer than 1%, held a certification. “The reality is, not enough organisations are implementing our guidance, nor applying these frameworks,” the review finds. “There is no room for complacency about the severity of state-led threats or the volume of the threat posed by cyber criminals,” Horne will warn. “The defence and resilience of critical infrastructure, supply chains, the public sector and our wider economy must improve.”
No previous article
No new articles
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/uk-cyber-chief-warns-underestimate