Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-36067 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds. NVD description · AI analysis pending | 10.0 | 48% | PoC ×2 |
| — | |
| CVE-2022-40684 | Admin-Interface Auth Bypass in Fortinet FortiOS, FortiProxy & FortiSwitchManager Fortinet's FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability (CWE-288) that lets an unauthenticated remote attacker gain access to the administrative interface. It is triggered by sending specially crafted HTTP or HTTPS requests directly to the admin interface, with no credentials or exploit code required. By bypassing authentication, an attacker can perform administrative operations on the device, such as modifying configuration or creating privileged accounts. Any organization running the affected products is exposed, particularly where the management interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 with known ransomware use, and EPSS assigns it roughly a 100% probability of exploitation within 30 days, although no public PoC is known. Do: Upgrade FortiOS, FortiProxy, and FortiSwitchManager to the fixed releases identified in Fortinet's advisory per the KEV required action. As mitigation, restrict access to the admin interface (e.g., disable WAN-facing management and use local-in policies or allow-lists for management IPs). Review admin logs and device configuration for signs of unauthorized access, such as unexpected admin accounts, added SSH keys, or config changes. | 9.8 | 100% | KEV ransomware PoC ×2 |
| massHundreds of thousands of internet-exposed Fortinet admin interfaces (~300k+ exposed FortiGate/FortiProxy management interfaces observed in public scans around… | |
| CVE-2022-41033 | Local Privilege Escalation in Microsoft Windows COM+ Event System Service CVE-2022-41033 is an elevation-of-privilege flaw in the Microsoft Windows COM+ Event System Service, classified under CWE-843 (access of a resource using an incompatible type). It is triggered locally: an attacker who can already execute code on a machine with limited (low-privilege) rights can exploit the vulnerable service with no user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker to the highest local privilege level, with high impact on the confidentiality, integrity, and availability of the system — a typical post-compromise privilege-escalation step for an attacker who already has a foothold. The flaw affects the Windows releases in the CISA CPE data — Windows 7, 8.1, RT 8.1, Windows 10 (1507, 1607, 1809, 20H2, 21H1, 21H2), Windows 11 (21H2, 22H2), and Windows Server 2008 — meaning effectively the broad Windows installed base. Microsoft patched it in the October 2022 Patch Tuesday release and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 as exploited in the wild; no public PoC is known, ransomware use is unknown, and EPSS currently estimates a 1.7% probability of exploitation in the next 30 days (75th percentile). Do: Apply the October 2022 Windows security updates (or any later cumulative update) on all affected Windows clients and servers, prioritizing hosts where low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI images — this also satisfies the CISA KEV required action. Until patched, treat any unprivileged compromise of a Windows host as potentially escalated to full local privilege, and restrict untrusted local code execution where possible. Verify remediation by confirming the October 2022 (or newer) cumulative update level on each host rather than relying on OS version alone. | 7.8 | 2% | KEV |
| masson the order of 1 billion Windows devices (essentially the entire supported Windows client and server installed base) | |
| CVE-2022-41352 | Path Traversal Arbitrary File Upload in Synacor Zimbra Collaboration Suite CVE-2022-41352 is an unauthenticated arbitrary file upload flaw in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0, rooted in a path traversal weakness (CWE-22) in how the amavis mail scanner hands archives to the cpio utility. An attacker sends a specially crafted archive via email; cpio follows traversal entries and extracts attacker-controlled files into the web root at /opt/zimbra/jetty/webapps/zimbra/public. Uploaded files in that web-accessible directory can lead to remote code execution and incorrect access to other users' accounts, giving network-level attackers high impact on confidentiality, integrity, and availability (CVSS 9.8). Any ZCS 8.8.15 or 9.0 deployment that processes mail with cpio is affected, particularly on Red Hat/CentOS 7 and later where the pax utility (which Zimbra recommends as the safe alternative) is not installed by default. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-10-20 with known ransomware use, carries a 95.5% EPSS score, and public reporting ties Zimbra exploitation to campaigns including Russia-linked Sandworm/Seashell Blizzard access operations. Do: Apply updates per vendor instructions, and as an immediate mitigation install the pax package on the Zimbra host (amavis automatically prefers pax over cpio once it is present; note pax is not in default Red Hat installations after RHEL/CentOS 6, while it is a prerequisite on Ubuntu). Also inspect /opt/zimbra/jetty/webapps/zimbra/public for unexpected uploaded files and review mail flow logs for suspicious archive attachments, given confirmed in-the-wild and ransomware-related exploitation. | 9.8 | 95% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Zimbra servers (public scan counts have shown roughly 40,000-60,000 exposed instances) |
Full article987 words · extracted from helpnetsecurity.com · click to collapse

Lack of transparency, systemic risks weaken national cybersecurity preparedness
Bob Kolasky, SVP for Critical Infrastructure at Exiger, previously served as Assistant Director for Cybersecurity and Infrastructure Security Agency (CISA), and in this Help Net Security interview talks about protecting critical infrastructure, the importance of information-sharing, national cybersecurity preparedness, and more.
Cybercriminals are having it easy with phishing-as-a-service
In this interview for Help Net Security, Immanuel Chavoya, Threat Detection Expert at SonicWall, talks about phishing-as-a-service (PaaS), the risks it can pose to organization, and what to do to tackle this threat.
Weakness in Microsoft Office 365 Message Encryption could expose email contents
WithSecure researchers are warning organizations of a security weakness in Microsoft Office 365 Message Encryption (OME) that could be exploited by attackers to obtain sensitive information.
Microsoft patches Windows flaw exploited in the wild (CVE-2022-41033)
October 2022 Patch Tuesday is here, with fixes for 85 CVE-numbered vulnerabilities, including CVE-2022-41033, a vulnerability in Windows COM+ Event System Service that has been found being exploited in the wild.
2FA is over. Long live 3FA!
In the past few months, we’ve seen an unprecedented number of identity theft attacks targeting accounts protected by two-factor authentication (2FA), challenging the perception that existing 2FA solutions provide adequate protection against identity theft attacks.
Researchers release PoC for Fortinet firewall flaw, exploitation attempts mount
Horizon3.ai researchers have released a PoC exploit for CVE-2022-40684, the authentication bypass vulnerability affecting Fortinet‘s firewalls and secure web gateways, and soon after exploitation attempts started rising.
Critical vm2 sandbox escape flaw uncovered, patch ASAP! (CVE-2022-36067)
Oxeye researchers discovered a severe vm2 vulnerability (CVE-2022-36067) that has received the maximum CVSS score of 10.0. Called SandBreak, this new vulnerability requires R&D leaders, AppSec engineers, and security professionals to ensure they immediately patch the vm2 sandbox if they use it in their applications.
Purpose-based access control: Putting data access requests into context
Access control is the heart of data protection. Striking the right balance between easy access and tight security isn’t easy, but getting it right is how you maintain business agility while still meeting regulatory and fiduciary data protection responsibilities.
Here’s 5 of the world’s riskiest connected devices
Forescout’s research team analyzed 19 million connected devices deployed across five different industries, to find the riskiest device groups: smart buildings, medical devices, networking equipment, and IP cameras, VoIP, and video conferencing systems.
EDR is not a silver bullet
Endpoint Detection and Response (EDR) tools have become Standard Operating Procedures for cybersecurity regimes. In a recent study by Cymulate of over one million tests conducted by our customers in 2021, the most popular testing vector was EDR.
Board members should make CISOs their strategic partners
Proofpoint released their Cybersecurity: The 2022 Board Perspective report, which explores board of directors’ perceptions about their key challenges and risks.
Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)
A still unpatched vulnerability (CVE-2022-41352) in Zimbra Collaboration is being exploited by attackers to achieve remote code execution on vulnerable servers.
Don’t lose control of your smart thermostat this winter
Winter is coming and the energy crisis is upon us. With rocketing prices and dwindling supply, much of the western world is bracing for three cold months beset by restrictions.
Microsoft Teams: A channel for sensitive business information sharing that needs better backup
Hornetsecurity has found an urgent need for greater backup for Microsoft Teams with 45% of users sending confidential and critical information frequently via the platform.
Are your cybersecurity investments making you less resilient?
In the past decade, digital transformation has become a buzzword in nearly every industry. Organizations have scaled down workforces in favor of automation, moved their servers and networks off-premises, and transferred their data to the cloud, but mostly kept to their old ways when thinking about cybersecurity.
What you should look for in an MDR relationship
The managed IT services market is growing both in size and importance, as more organizations decide it makes fiscal and operational sense to outsource key functions.
Increasing network visibility is critical to improving security posture
In this Help Net Security video, Anthony James, VP of Product Marketing at Infoblox, discusses why visibility is synonymous with improving efficiency and performance for networking and security professionals.
How government organizations can stay steps ahead of attackers
In this Help Net Security video, David Masson, Director of Enterprise Security at Darktrace, illustrates how the attack surface is getting bigger by the day.
Constellation: Open-source, runtime-encrypted Kubernetes
In this Help Net Security video, Felix Schuster, CEO at Edgeless Systems, talks about the open-source release of Constellation.
How to improve employees’ cybersecurity behavior
In this Help Net Security video interview, Inka Karppinen, Lead Behavioral Scientist at CybSafe, talks about cybersecurity behaviors within organizations.
New RSA Conference CEO talks about delivering value
In this Help Net Security video, Kylie Wright-Ford talks about her new role, the biggest challenges within the cybersecurity industry, and RSA Conference opportunities for growth.
Cost-effective steps healthcare CISOs can take to mitigate damaging attacks
In this Help Net Security video, Maureen Kaplan, Chief Revenue Officer at SilverSky, discusses how attackers are now narrowing their focus from larger healthcare systems to smaller hospitals and specialty clinics to more easily retrieve patient data and use it for launching fraud and identity theft.
The dangers of orphaned data and what companies can do about it
In this Help Net Security video, Carl D’Halluin, CTO at Datadobi, talks about how companies can eliminate the cost and risk associated with this data type.
Educational institutions must reverse their backward approach to cyber defense
In this Help Net Security video, Raj Dodhiawala, CEO at Remediant, talks about how this situation is due to longer cycles for IT budgetary and staffing processes, a higher turnover rate, and lower continuity in IT security projects and skills.
New infosec products of the week: October 14, 2022
Here’s a look at the most interesting products from the past week, featuring releases from ABBYY, Digi International, Portnox, Stytch, and Thales.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/16/week-in-review-3fa-fortinet-firewalls-under-attack-and-the-riskiest-connected-devices/