Casualties keep growing in this month’s mass exploitation of MOVEit 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0669 | Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%. Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use. | 7.2 | 100% | KEV ransomware PoC ×3 |
| moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface) |
Full article327 words · extracted from arstechnica.com · click to collapse
Driver license data for millions of Oregon and Louisiana citizens have also been stolen in the attacks. CNN has reported that the Department of Agriculture may also be affected.
Shoes keep dropping
On Tuesday, the Clop site named Siemens Electric as another victim, and shortly after that, it was widely reported, company officials confirmed its systems had been breached in the Clop campaign.
“Based on the current analysis, no critical data has been compromised and our operations have not been affected,” a Siemens Electric representative told news outlets, including Cyberscoop. “We took immediate action when we learned about the incident.” Attempts by Ars to reach Siemens Electric weren’t successful.
Clop named Schneider Electric as another victim. In an email, a Schneider Electric official wrote: “On May 30th, 2023, Schneider Electric became aware of vulnerabilities impacting Progress MOVEit Transfer software. We promptly deployed available mitigations to secure data and infrastructure and have continued to monitor the situation closely.”
On Saturday evening, the head of New York City’s Department of Education came forward to say that it, too, had been hit in the Clop campaign.
“Review of the impacted files is ongoing, but preliminary results indicate that approximately 45,000 students, in addition to DOE staff and related service providers, were affected,” Emma Vadehra, chief operating officer for the department, wrote. “Roughly 19,000 documents were accessed without authorization. The types of data impacted include Social Security Numbers and employee ID numbers (not necessarily for all impacted individuals; for example, approximately 9,000 Social Security Numbers were included).”
Clop is a Russian-speaking group that’s among the most prolific and active ransomware actors. The threat actor recently mass-exploited CVE-2023-0669, a critical vulnerability in a different file-transfer service known as GoAnywhere. That hacking spree also claimed more than 100 organizations, including data security company Rubrik, and Community Health Systems of Franklin, Tennessee. The hack of Community Health Systems, one of the biggest hospital chains, allowed Clop to obtain health information for 1 million patients.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/06/casualties-keep-growing-in-this-months-mass-exploitation-of-moveit-0-day/