Ransomware is Being Used As a Precursor to Physical War: Ivanti
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-40539 | Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities. Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances. | 9.8 | 99% | KEV ransomware PoC |
| largetens of thousands of enterprise server installations (unknown precise count) | |
| CVE-2022-2613 | Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactio Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions. NVD description · AI analysis pending | 8.8 | <1% |
| — |
Full article385 words · extracted from infosecurity-magazine.com · click to collapse
Ransomware has grown by 466% since 2019 and is increasingly being used as a precursor to physical war.
The findings come from Ivanti's Ransomware Index Report Q2–Q3 2022, which the company shared with Infosecurity earlier today.
The data also shows ransomware groups continuing to grow in volume and sophistication, with 35 vulnerabilities becoming associated with ransomware in the first three quarters of 2022 and 159 trending active exploits.
Further, the Ivanti report highlighted 10 new ransomware families compared to the previous quarter: Black Basta, BianLian, BlueSky, Play, Hive, Deadbolt, H0lyGh0st, Lorenz, Maui and NamPoHyu. These bring the total to 170.
From a geographical perspective, Russia has been at the forefront of the malware families discovered, with 11 advanced persistent threat (APT) groups, followed closely by China with eight and Iran with four.
According to the Ivanti report, hostile governments increasingly use state-sponsored threat groups to infiltrate, destabilize and disrupt operations in their target countries. In many of these attacks, ransomware is being used as a precursor to physical warfare, as shown in the recent Russia–Ukraine war.
Regardless of geography, Ivanti has also said ransomware attackers increasingly rely on spear phishing techniques to lure unsuspecting victims into delivering their malicious payload, as in the case of the Pegasus spyware.
In terms of new ransomware vulnerabilities, the cybersecurity company spotted two: CVE-2021-40539 and CVE-2022-2613. Both have reportedly been exploited by ransomware families such as AvosLocker and Cerbe.
The report has also revealed that 47.4% of ransomware vulnerabilities affect healthcare systems, 31.6% energy systems and 21.1% critical manufacturing.
"IT and security teams must urgently adopt a risk-based approach to vulnerability management to better defend against ransomware and other threats," explained Srinivas Mukkamala, chief product officer at Ivanti.
The executive said this includes leveraging automation technologies that can correlate data from diverse sources but also measure risk, provide early warning of weaponization, predict attacks and prioritize remediation activities.
"Organizations that continue to rely on traditional vulnerability management practices, such as solely leveraging the [National Vulnerability Database] NVD and other public databases to prioritize and patch vulnerabilities, will remain at high risk of cyber-attack," Mukkamala concluded.
Case in point, it was recently revealed that a local government authority in London had been forced to spend over £12m ($11.7m) to help it recover from a devastating ransomware attack.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-precursor-to-physical/