Security Affairs newsletter Round 463 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-1403 | In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypas In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2024-21412 | CVE-2024-21412: Security Feature Bypass in Microsoft Windows Internet Shortcut Files CVE-2024-21412 is a security feature bypass (CWE-693) in how Microsoft Windows handles Internet Shortcut files: a crafted shortcut can make Windows skip the security warning prompt that normally appears before untrusted internet content is opened or downloaded. Triggering it requires user interaction — an attacker must deliver a malicious shortcut file, typically via email or a malicious website, and convince the user to open it, which is reflected in the CVSS vector's UI:R component. An attacker who succeeds gains a bypass of those prompts, making it easier to retrieve and execute malicious remote content with fewer warnings; the DarkGate malware operators used exactly this technique in zero-day campaigns to distribute their loader. Anyone running the affected Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2019, or Windows Server 2022 (including 23H2) builds was exposed. The flaw was patched in Microsoft's February 2024 Patch Tuesday release (2024-02-13), the same day CISA added it to the KEV catalog, and it is under active exploitation with known ransomware association and a 95.4% EPSS score. Do: Apply the February 2024 Windows cumulative security update (released 2024-02-13) or any later monthly cumulative update to every affected Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022 build, and verify patch levels through your endpoint inventory. Because exploitation requires user interaction, as an interim control flag or block .url/Internet Shortcut attachments at email gateways and remind users not to open shortcuts from untrusted sources. Prioritize internet-facing and shared endpoints given the KEV listing and known ransomware use. | 8.1 | 95% | KEV ransomware |
| mass≈1 billion Windows 10/11/Server installations potentially affected worldwide (pre-patch installed base) |
Full article636 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
March 17, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
Cybercrime
Data breaches caused by insiders can cost you over $15 million
Stanford says data from 27,000 people leaked in September ransomware attack
A Close Up Look at the Consumer Data Broker Radaris
Binance’s Top Crypto Crime Investigator Is Being Detained in Nigeria
FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga.
CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms
Pennsylvania’s Scranton School District dealing with ransomware attack
Cybercriminals Evolve Tooling For Remote Access Compromise
France Travail: the CNIL investigates the data leak and gives advice on how to protect yourself
Malware
MAGNET GOBLIN TARGETS PUBLICLY FACING SERVERS USING 1-DAY VULNERABILITIES
New Malware Campaign Found Exploiting Stored XSS in Popup Builder < 4.2.3
BianLian GOs for PowerShell After TeamCity Exploitation
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Hacking
AUTOATTACKER: A Large Language Model Guided System to Implement Automatic Cyber-attacks
CVE-2024-1403: Progress OpenEdge Authentication Bypass Deep-Dive
French state services hit by ‘intense’ cyberattack, PM’s office says
Intelligence and Information Warfare
China intensifies intelligence activities against Lithuania from its territory
First-ever South Korean citizen arrested for espionage in Russia
Russia’s spy service accuses US of trying to meddle in presidential election
THE MARCH 2024 SECURITY UPDATE REVIEW
Rubio warns Chinese cyberattack ‘will be 100 times worse’ than AT&T outage: ‘Your power, your water’
North Korean Hackers Return to Tornado Cash Despite Sanctions
Safeguarding EU elections amidst cybersecurity challenges
Nation-state threat actors using LLMs to boost cyber operations
Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack
China could use TikTok to influence US elections, spy chief says
Stealing Part of a Production Language Model
US Senator Urges Microsoft to Pull Bing Out of China
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/160586/breaking-news/security-affairs-newsletter-round-463-by-pierluigi-paganini-international-edition.html