ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Massive Cyber Attack Knocks Down Ukrainian Government Websites

criticalVulnerabilityimportance 60CVE-2021-32648

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-32648
Authentication Bypass in October CMS Password Reset Enables Account Takeover

October CMS, a content management system built on the Laravel PHP framework, contains an improper authentication flaw (CWE-287) in its october/system package: an attacker can initiate a password reset for any account and then submit a specially crafted request that bypasses the reset-code check, gaining access to that account without knowing the current password. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.1, critical), and takeover of a back-end administrator account would grant the attacker full control of the CMS's content, users, and configuration. Any October CMS deployment running october/system versions prior to Build 472 or v1.1.5 is affected. Exploitation is confirmed in the wild: CISA added CVE-2021-32648 to its Known Exploited Vulnerabilities Catalog on 2022-01-18 as part of a batch of 17 added flaws, requiring patching per vendor instructions, and EPSS assigns a 90.4% probability of exploitation within 30 days (100th percentile). CISA lists ransomware use as unknown, and no public proof-of-concept exploit is known.

Do: Update October CMS to Build 472 or v1.1.5 (or later) following the vendor's update instructions; because the flaw is in CISA's KEV, patching is required for federal agencies. Organizations that cannot patch immediately should restrict network access to the CMS back end and audit recent password-reset requests, back-end logins, and account modifications for signs of takeover, rotating credentials for any accounts with unexpected resets.

9.190% KEV
  • October CMS (october/system package) All versions prior to Build 472 and prior to v1.1.5; fixed in Build 472 and v1.1.5
large~ tens of thousands of installations (roughly 10,000-50,000 sites per public CMS usage trackers; a subset are internet-exposed) - estimate
Full article436 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 15, 2022

No fewer than 70 websites operated by the Ukrainian government went offline on Friday for hours in what appears to be a coordinated cyber attack amid heightened tensions with Russia.

"As a result of a massive cyber attack, the websites of the Ministry of Foreign Affairs and a number of other government agencies are temporarily down," Oleg Nikolenko, MFA spokesperson, tweeted.

The Security Service of Ukraine, the country's law-enforcement authority, alluded to a possible Russian involvement, pointing fingers at the hacker groups associated with the Russian secret services while branding the intrusions as a supply chain attack that involved hacking the "infrastructure of a commercial company that had access to the rights to administer the web resources affected by the attack."

Prior to the update from the SSU, the Ukrainian CERT claimed that the attacks may have exploited a security vulnerability in Laravel-based October CMS (CVE-2021-32648), which could be abused by an adversary to gain access to an account using a specially crafted request.

The breach targeted a number of government websites, including those for Ukraine's Cabinet, education, agriculture, emergency, energy, veterans affairs, and environment ministries, among others, 10 websites of which were "subjected to unauthorized interference."

The security agency, however, stressed that content of the sites was not altered and that no sensitive personal data was stolen.

"Provocative messages were posted on the main page of the websites," the SSU said. "The content of the sites was not changed, and, according to preliminary information, no leakage of personal data occurred."

This is far from the first time Russia has set its sights on Ukraine. In December 2015, a nation-state adversary tracked as Sandworm targeted the power grid, resulting in unprecedented blackouts for roughly 230,000 consumers in the nation.

Two years later, Ukraine was also at the receiving end of the devastating NotPetya wiper malware campaign by the Sandworm military hackers that erased confidential data from the computers of banks and energy firms.

Then in November 2021, the SSU unmasked the real identities of five Russian intelligence officials allegedly involved in over 5,000 cyberattacks attributed to a cyber-espionage group named Gamaredon aimed at public authorities and critical infrastructure located in the country.

"The purpose of such attacks is to destabilize the internal situation in the country, as well as to sow chaos and disbelief in society," the Center for Strategic Communications and Information Security said, noting the hacks amount to "psychological pressure and intimidation."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/01/massive-cyber-attack-knocks-down.html