ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-12271
SQL Injection RCE in Sophos SFOS Firewalls with WAN-Exposed Admin or User Portal

CVE-2020-12271 is a SQL injection flaw (CWE-89) in the Sophos firewall operating system (SFOS) firmware that runs Sophos's firewall appliances. It is triggered when the appliance's administration (HTTPS) service or its User Portal is exposed on the WAN (internet-facing) zone, which lets remote attackers inject SQL through those services and achieve code execution on the device. Successful exploitation gives attackers remote code execution that can be used to exfiltrate usernames and hashed passwords for local device administrators, portal administrators, and user accounts used for remote access; passwords stored in external Active Directory or LDAP directories are not exposed. Affected organizations are those running Sophos SFOS with the HTTPS admin interface or User Portal reachable from the internet; the source data does not specify affected version ranges, so defenders should consult Sophos's advisories for affected and fixed releases. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS estimates a 42.4% probability of exploitation in the next 30 days (99th percentile), and no public proof-of-concept is known.

Do: Immediately update SFOS to a current patched release per Sophos's upgrade instructions, which is CISA's required action for federal agencies. As an interim mitigation, remove the HTTPS administration service and User Portal from the WAN zone or restrict access to trusted source addresses. Because ransomware actors are known to exploit this flaw, review firewall logs for signs of intrusion and rotate local device-admin, portal-admin, and remote-access user credentials, as only those hashes could have been exfiltrated (external AD/LDAP passwords were not at risk).

9.842% KEV ransomware PoC
  • Sophos SFOS (Sophos firewall operating system)
largetens of thousands (order of magnitude 10,000-100,000) of internet-exposed Sophos firewall admin/portal services
CVE-2020-15069
Unauthenticated Buffer Overflow RCE in Sophos XG Firewall

CVE-2020-15069 is a critical buffer overflow (CWE-120) in the HTTP/S Bookmarks feature used for clientless access in Sophos XG Firewall, affecting firmware versions 17.x through v17.5 MR12. The flaw is reachable over the network without credentials or user interaction, so an unauthenticated attacker can trigger it by sending crafted requests to the exposed bookmarks functionality. Successful exploitation yields remote code execution on the firewall with high impact on confidentiality, integrity, and availability. Any organization running Sophos XG Firewall 17.x through v17.5 MR12 is affected, especially firewalls with the clientless-access feature enabled or management interfaces reachable from the internet. Sophos published hotfix HF062020.1 for all firewalls running v17.x, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, indicating confirmed in-the-wild exploitation (EPSS puts the 30-day exploitation probability at about 10.7%).

Do: Apply hotfix HF062020.1, which Sophos published for all firewalls running v17.x, or upgrade to a current supported release, prioritizing internet-exposed devices. Verify the hotfix is actually installed rather than assuming auto-update succeeded, and disable or restrict the clientless HTTP/S Bookmarks feature as interim mitigation. Review firewall logs for signs of unexpected access or compromise, since exploitation has been confirmed in the wild.

9.811% KEV
  • sophos XG Firewall firmware 17.x through v17.5 MR12
mass≈ hundreds of thousands of firewall deployments, with likely tens of thousands still running unpatched v17.x (internet-wide scans have historically shown…
CVE-2020-29574
Unauthenticated SQL Injection in Sophos CyberoamOS WebAdmin

CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.

Do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.

9.85% KEV ransomware
  • Sophos CyberoamOS (CROS) - WebAdmin all versions through 2020-12-04 (CISA date-based range); product is EoL/EoS
largetens of thousands of deployed appliances (installed-base estimate; internet-exposed WebAdmin consoles likely in the low thousands)
CVE-2022-1040
Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS)

CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw.

Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates.

9.8100% KEV PoC ×2
  • Sophos Firewall (SFOS) v18.5 MR3 and older
largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances
CVE-2022-3236
Unauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin)

CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure.

Do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied.

9.899% KEV
  • Sophos Firewall (User Portal and Webadmin) v19.0 MR1 and older
masshundreds of thousands of deployed Sophos Firewall appliances; tens of thousands of User Portal/Webadmin instances internet-exposed per public scans
CVE-2024-10443
Unauthenticated OS Command Injection RCE in Synology Photos and BeePhotos

CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation.

Do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction.

9.828%
  • Synology Photos all versions before 1.6.2-0720 (1.6.x line) and before 1.7.0-0795 (1.7.x line)
  • Synology BeePhotos all versions before 1.0.2-10026 (1.0.x line) and before 1.1.0-10053 (1.1.x line)
massmillions of NAS devices (press reports cite millions of vulnerable Synology DiskStation and BeePhotos units)
CVE-2024-20418
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Poi

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.

NVD description · AI analysis pending
10.03%
CVE-2024-33661
Portainer before 2.20.0 allows redirects when the target is not index.yaml.

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

NVD description · AI analysis pending
9.1<1%
  • portainer portainer
CVE-2024-33662
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

NVD description · AI analysis pending
7.5<1%
  • portainer portainer
CVE-2024-39720
+3 in the same advisory: …39719 …39722 …39721
An issue was discovered in Ollama before 0.1.46.

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).

NVD description · AI analysis pending
8.2
group max
2% PoC
  • ollama ollama
CVE-2024-42509
+1 in the same advisory: …47460
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

NVD description · AI analysis pending
9.8
group max
2%
CVE-2024-43093
Local Privilege Escalation via Unicode Path Filter Bypass in Android Framework

CVE-2024-43093 is a privilege escalation flaw in the Android Framework's ExternalStorageProvider (the component behind the system document/file picker), where the shouldHideDocument function mishandles Unicode normalization, allowing crafted file paths to bypass the filter that hides sensitive directories such as app-private storage (CWE-176). It is triggered locally: an app with no additional execution privileges can exploit it with user interaction, for example when a user selects a file or location through the documents UI. A successful bypass grants unauthorized access to otherwise protected directories and can lead to local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.3, vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Any device running the Android Framework is in scope, meaning effectively the entire Android installed base, although the local access and user-interaction requirements limit practical exploitability to targeted scenarios. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07 and Google has indicated it may be under limited, targeted exploitation; no public proof-of-concept is known, and EPSS currently rates the 30-day exploitation probability at a modest 0.7%, though the KEV listing is the authoritative in-the-wild signal.

Do: Apply Google's Android security updates immediately — the fix is included in the November 2024 Android Security Bulletin (security patch level 2024-11-01) or later — and verify the device's security patch level in Settings; OEM devices (e.g., Samsung) may receive the fix through vendor updates on a lag. Per the CISA KEV required action, treat patching as urgent or apply vendor mitigations, and as an interim measure restrict sideloaded/untrusted app installs and caution users when picking files through the document picker. Ransomware linkage is unknown, and the user-interaction requirement means exploitation is targeted rather than wormable.

7.3<1% KEV
  • Google Android (Android Framework component)
massbillions of Android devices worldwide (Android runs on roughly 70% of global smartphones)
CVE-2024-50387
A SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later

NVD description · AI analysis pending
10.010%
  • qnap smb service
CVE-2024-50388
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

NVD description · AI analysis pending
9.52%
  • qnap hybrid backup sync
CVE-2024-50389
A SQL injection vulnerability has been reported to affect QuRouter.

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

NVD description · AI analysis pending
9.5<1%
  • qnap qurouter
CVE-2024-5910
Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition

CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465).

Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool.

9.392% KEV PoC
  • Palo Alto Networks Expedition
nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances
CVE-2024-8355
Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability.

Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DeviceManager. When parsing the iAP Serial number, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20112.

NVD description · AI analysis pending
6.8<1%
  • visteon infotainment firmware
CVE-2024-8360
Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability.

Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability. The specific flaw exists within the REFLASH_DDU_ExtractFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23421.

NVD description · AI analysis pending
6.8<1%
  • visteon infotainment
Full article2,187 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 11, 2024Cybersecurity / Hacking News

⚠️ Imagine this: the very tools you trust to protect you online—your two-factor authentication, your car’s tech system, even your security software—turned into silent allies for hackers. Sounds like a scene from a thriller, right? Yet, in 2024, this isn’t fiction; it’s the new cyber reality. Today’s attackers have become so sophisticated that they’re using our trusted tools as secret pathways, slipping past defenses without a 🔍 trace.

For banks 🏦, this is especially alarming. Today’s malware doesn’t just steal codes; it targets the very trust that digital banking relies on. These threats are more advanced and smarter than ever, often staying a step ahead of defenses.

And it doesn’t stop there. Critical systems that power our cities are at risk too. Hackers are hiding within the very tools that run these essential services, making them harder to detect and harder to stop. It’s a high-stakes game of hide-and-seek, where each move raises the risk.

As these threats grow, let’s dive into the most urgent security issues, vulnerabilities, and cyber trends this week.

⚡ Threat of the Week

FBI Probes China-Linked Global Hacks: The FBI is urgently calling for public assistance in a global investigation into sophisticated cyber attacks targeting companies and government agencies. Chinese state-sponsored hacking groups—identified as APT31, APT41, and Volt Typhoon—have breached edge devices and computer networks worldwide.

Exploiting zero-day vulnerabilities in edge infrastructure appliances from vendors like Sophos, these threat actors have deployed custom malware to maintain persistent remote access and repurpose compromised devices as stealthy proxies. This tactic allows them to conduct surveillance, espionage, and potentially sabotage operations while remaining undetected.

Tips for Organizations:

  • Update and Patch Systems: Immediately apply the latest security updates to all edge devices and firewalls, particularly those from Sophos, to mitigate known vulnerabilities like CVE-2020-12271, CVE-2020-15069, CVE-2020-29574, CVE-2022-1040, and CVE-2022-3236.
  • Monitor for Known Malware: Implement advanced security solutions capable of detecting malware such as Asnarök, Gh0st RAT, and Pygmy Goat. Regularly scan your network for signs of these threats.
  • Enhance Network Security: Deploy intrusion detection and prevention systems to monitor for unusual network activity, including unexpected ICMP traffic that could indicate backdoor communications.

SANS Cyber Defense Initiative 2024 SANS Cyber Defense Initiative 2024

Microsoft 365 Cyber Resilience: 3 Keys to Success

Protecting Microsoft 365 data is essential to any modern cybersecurity strategy, since the suite’s applications are so commonly used in businesses of all sizes and industries. Watch this webinar for key steps you can take to build a more proactive approach to securing your organization’s Microsoft 365 data from cyberattacks and ensuring resilience.

WATCH NOW

🔔 Top News

  • Android Banking Trojan ToxicPanda Targets Europe: A new Android banking trojan dubbed ToxicPanda has been observed targeting over a dozen banks in Europe and Latin America. It's so named for its Chinese roots and its similarities with another Android-focused malware named TgToxic. ToxicPanda comes with remote access trojan (RAT) capabilities, enabling the attackers to conduct account takeover attacks and conduct on-device fraud (ODF). Besides obtaining access to sensitive permissions, it can intercept one-time passwords received by the device via SMS or those generated by authenticator apps, which enables the cybercriminals to bypass multi-factor authentication. The threat actors behind ToxicPanda are likely Chinese speakers.
  • VEILDrive Attack Exploits Microsoft Services: An ongoing threat campaign dubbed VEILDrive has been observed taking advantage of legitimate services from Microsoft, including Teams, SharePoint, Quick Assist, and OneDrive, as part of its modus operandi. In doing so, it allows the threat actors to evade detection. The attack has been so far spotted targeting an unnamed critical infrastructure entity in the U.S. It's currently not known who is behind the campaign.
  • Crypto Firms Targeted with New macOS backdoor: The North Korean threat actor known as BlueNoroff has targeted cryptocurrency-related businesses with a multi-stage malware capable of infecting Apple macOS devices. Unlike other recent campaigns linked to North Korea, the latest effort uses emails propagating fake news about cryptocurrency trends to infect targets with a backdoor that can execute attacker-issued commands. The development comes as the APT37 North Korean state-backed group has been linked to a new spear-phishing campaign distributing the RokRAT malware.
  • Windows Hosts Targeted by QEMU Linux Instance: A new malware campaign codenamed CRON#TRAP is infecting Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the compromised hosts. This allows the unidentified threat actors to maintain a stealthy presence on the victim's machine.
  • AndroxGh0st Malware Integrates Mozi Botnet: The threat actors behind the AndroxGh0st malware are now exploiting a broader set of security flaws impacting various internet-facing applications, alongside deploying the Mozi botnet malware. While Mozi suffered from a steep decline in activity last year, the new integration has raised the possibility of a possible operational alliance, thereby allowing it to propagate to more devices than ever before.

‎️‍🔥 Trending CVEs

Recently trending CVEs include: CVE-2024-39719, CVE-2024-39720, CVE-2024-39721, CVE-2024-39722, CVE-2024-43093, CVE-2024-10443, CVE-2024-50387, CVE-2024-50388, CVE-2024-50389, CVE-2024-20418, CVE-2024-5910, CVE-2024-42509, CVE-2024-47460, CVE-2024-33661, CVE-2024-33662. Each of these vulnerabilities represents a significant security risk, emphasizing the importance of regular updates and monitoring to protect data and systems.

📰 Around the Cyber World

  • Unpatched Flaws Allow Hacking of Mazda Cars: Multiple security vulnerabilities identified in the Mazda Connect Connectivity Master Unit (CMU) infotainment unit (from CVE-2024-8355 through CVE-2024-8360), which is used in several models between 2014 and 2021, could allow for execution of arbitrary code with elevated permissions. Even more troublingly, they could be abused to obtain persistent compromise by installing a malicious firmware version and gain direct access to the connected controller area networks (CAN buses) of the vehicle. The flaws remain unpatched, likely because they all require an attacker to physically insert a malicious USB into the center console. "A physically present attacker could exploit these vulnerabilities by connecting a specially crafted USB device – such as an iPod or mass storage device – to the target system," security researcher Dmitry Janushkevich said. "Successful exploitation of some of these vulnerabilities results in arbitrary code execution with root privileges."
  • Germany Drafts Law to Protect Researchers Reporting Flaws: The Federal Ministry of Justice in Germany has drafted a law to provide legal protection to researchers who discover and responsibly report security vulnerabilities to vendors. "Those who want to close IT security gaps deserve recognition—not a letter from the prosecutor," the ministry said. "With this draft law, we will eliminate the risk of criminal liability for people who take on this important task." The draft law also proposes a penalty of three months to five years in prison for severe cases of malicious data spying and data interception that include acts motivated by profit, those that result in substantial financial damage, or compromise critical infrastructure.
  • Over 30 Vulnerabilities Found in IBM Security Verify Access: Nearly a three dozen vulnerabilities have been disclosed in IBM Security Verify Access (ISVA) that, if successfully exploited, could allow attackers to escalate privileges, access sensitive information, and compromise the entire authentication infrastructure. The vulnerabilities were found in October 2022 and were communicated to IBM at the beginning of 2023 by security researcher Pierre Barre. A majority of the issues were eventually patched at the end of June 2024.
  • Silent Skimmer Actor Makes a Comeback: Organizations that host or create payment infrastructure and gateways are being targeted as part of a new campaign mounted by the same threat actors behind the Silent Skimmer credit card skimming campaign. Dubbed CL-CRI-0941, the activity is characterized by the compromise of web servers to gain access to victim environments and gather payment information. "The threat actor gained an initial foothold on the servers by exploiting a couple of one-day Telerik user interface (UI) vulnerabilities," Palo Alto Networks Unit 42 said. The flaws include CVE-2017-11317 and CVE-2019-18935. Some of the other tools used in the attacks are reverse shells for remote access, tunneling and proxy utilities such as Fuso and FRP, GodPotato for privilege escalation, and RingQ to retrieve and launch the Python script responsible for harvesting the payment information to a .CSV file.
  • Seoul Accuses Pro-Kremlin Hacktivists of Targeting South Korea: As North Korea joins hands with Russia in the ongoing Russo-Ukrainian War, DDoS attacks on South Korea have ramped up, the President's Office said. "Their attacks are mainly private-targeted hacks and distributed denial-of-service (DDoS) attacks targeting government agency home pages," according to a statement. "Access to some organizations' websites has been temporarily delayed or disconnected, but aside from that, there has been no significant damage."
  • Canada Predicts Indian State-Sponsored Attacks amid Diplomatic Feud: Canada has identified India as an emerging cyber threat in the wake of growing geopolitical tensions between the two countries over the assassination of a Sikh separatist on Canadian soil. "India very likely uses its cyber program to advance its national security imperatives, including espionage, counterterrorism, and the country's efforts to promote its global status and counter narratives against India and the Indian government," the Canadian Centre for Cyber Security said. "We assess that India's cyber program likely leverages commercial cyber vendors to enhance its operations."
  • Apple's New iOS Feature Reboots iPhones after 3 Days of Inactivity: Apple has reportedly introduced a new security feature in iOS 18.1 that automatically reboots iPhones that haven't been unlocked for a period of three days, according to 404 Media. The newly added code, called "inactivity reboot," triggers the restart so as to revert the phone to a more secure state called "Before First Unlock" (aka BFU) that forces users to enter the passcode or PIN in order to access the device. The new feature has apparently frustrated law enforcement efforts to break into the devices as part of criminal investigations. Apple has yet to formally comment on the feature.

🔥 Resources, Guides & Insights

🎥 Expert Webinar

🔧 Cybersecurity Tools

P0 Labs recently announced the release of new open-source tools designed to enhance detection capabilities for security teams facing diverse attack vectors.

  • YetiHunter - Detects indicators of compromise in Snowflake environments.
  • CloudGrappler - Queries high-fidelity, single-event detections related to well-known threat actors in cloud environments like AWS and Azure.
  • DetentionDodger - Identifies identities with leaked credentials and assesses potential impact based on privileges.
  • BucketShield - A monitoring and alerting system for AWS S3 buckets and CloudTrail logs, ensuring consistent log flow and audit-readiness.
  • CAPICHE Detection Framework (Cloud API Conversion Helper Express) - Simplifies cloud API detection rule creation, supporting defenders in creating multiple detection rules from grouped APIs.

🔒 Tip of the Week

Strengthen Security with Smarter Application Whitelisting — Lock down your Windows system like a pro by using built-in tools as your first line of defense. Start with Microsoft Defender Application Control and AppLocker to control which apps can run - think of it as a bouncer that only lets trusted apps into your club. Keep an eye on what's happening with Sysinternals Process Explorer (it's like CCTV for your running programs) and use Windows Security Center to guard your browsers and folders. For older Windows versions, Software Restriction Policies (SRP) will do the job. Remember to set up alerts so you know when something suspicious happens.

Don't trust any app until it proves itself - check for digital signatures (like an app's ID card) and use PowerShell safely by requiring signed scripts only. Keep risky apps in a sandbox (like Windows Sandbox or VMware) - it's like a quarantine zone where apps can't hurt your main system. Watch your network with Windows Firewall and GlassWire to spot any apps making suspicious connections. When it's time for updates, test them in a safe space first using Windows Update management tools. Keep logs of everything using Windows Event Forwarding and Sysmon, and review them regularly to spot any trouble. The key is layering these tools - if one fails, the others will catch the threat.

Conclusion

As we face this new wave of cyber threats, it’s clear that the line between safety and risk is getting harder to see. In our connected world, every system, device, and tool can either protect us or be used against us. Staying safe now means more than just better defenses; it means staying aware of new tactics that change every day. From banking to the systems that keep our cities running, no area is immune to these risks.

Moving forward, the best way to protect ourselves is to stay alert, keep learning, and always be ready for the next threat. Don’t forget to subscribe for our next edition. 👋

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_11.html