ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 488 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2024-32896CVE-2024-30078CVE-2024-36401

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-30078
Windows Wi-Fi Driver Remote Code Execution Vulnerability

Windows Wi-Fi Driver Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.85%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-32896
Local Privilege Escalation in Google Android Pixel Kernel

CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates.

Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk.

7.83% KEV
  • google Android (Pixel)
masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown)
CVE-2024-36401
Unauthenticated RCE in OSGeo GeoServer via GeoTools XPath Injection

OSGeo GeoServer ships the GeoTools library, which evaluates feature property names directly as XPath expressions without proper neutralization (CWE-95), so attacker-supplied input is executed as code rather than treated as data. A remote, unauthenticated attacker triggers the flaw by sending specially crafted requests to a GeoServer service, causing the injected expression to be evaluated in the server's context. Successful exploitation results in remote code execution on the host running GeoServer, giving the attacker control over the mapping server and any data or credentials it can reach. Any organization running GeoServer is affected, and the underlying GeoTools flaw also extends to dependent applications such as GeoNetwork, which shipped its own fix for an unauthenticated RCE chain affecting government geoportal backends. The flaw is being actively exploited: it was added to CISA KEV on 2024-07-15, and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Upgrade GeoServer to the fixed releases identified in the OSGeo advisory (2.23.6, 2.24.4 or 2.25.2, or later); where upgrading is not immediately possible, restrict access to GeoServer's public endpoints per vendor mitigations or discontinue use of the product per the KEV required action. Organizations running GeoNetwork or other GeoTools-based applications should apply those vendors' fixes as well. Given active exploitation, hunt for signs of compromise such as unexpected child processes spawned by the GeoServer Java process, new files or services on the host, and unusual map/feature service request patterns.

9.8100% KEV PoC ×3
  • OSGeo GeoServer Multiple releases prior to the vendor-patched builds (fixed in the 2.23.x, 2.24.x and 2.25.x maintenance lines; exact fixed releases per the OSGeo advisory: 2.2
  • OSGeo GeoNetwork (bundles the vulnerable GeoTools library)
largeTens of thousands of internet-exposed instances (roughly 20,000-40,000 GeoServer endpoints visible in public internet scans), with substantially more internal…
Full article724 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 08, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

U.S. CISA adds Draytek VigorConnect and Kingsoft WPS Office bugs to its Known Exploited Vulnerabilities catalog
A flaw in WordPress LiteSpeed Cache Plugin allows account takeover
Car rental company Avis discloses a data breach
SonicWall warns that SonicOS bug exploited in attacks
Apache fixed a new remote code execution flaw in Apache OFBiz
Russia-linked GRU Unit 29155 targeted critical infrastructure globally
Veeam fixed a critical flaw in Veeam Backup & Replication software
Earth Lusca adds multiplatform malware KTLVdoor to its arsenal
Is Russian group APT28 behind the cyber attack on the German air traffic control agency (DFS)?
Quishing, an insidious threat to electric car owners
Google fixed actively exploited Android flaw CVE-2024-32896
Discontinued D-Link DIR-846 routers are affected by code execution flaws. Replace them!
Head Mare hacktivist group targets Russia and Belarus
Zyxel fixed critical OS command injection flaw in multiple routers
VMware fixed a code execution flaw in Fusion hypervisor
U.S. oil giant Halliburton disclosed a data breach
Vulnerabilities in Microsoft apps for macOS allow stealing permissions
Three men plead guilty to running MFA bypass service OTP.Agency
Transport for London (TfL) is dealing with an ongoing cyberattack
Lockbit gang claims the attack on the Toronto District School Board (TDSB)
A new variant of Cicada ransomware targets VMware ESXi systems
An air transport security system flaw allowed to bypass airport security screenings

International Press – Newsletter

Cybercrime  

Cambodian scam giant handled $49 billion in crypto transactions since 2021, researchers say

Toronto school board confirms students’ info stolen as LockBit claims breach      

Owners of 1-Time Passcode Theft Service Plead Guilty  

Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant  

Exclusive: LockBit 3.0 appears to be duplicating old listings as Design Intoto named a second time  

Malla: Demystifying Real-world Large Language Model Integrated Malicious Services  

EXPOSED: OnlyFans Hack Gone Wrong – How Cyber Criminals Turn into Victims Overnight

Planned Parenthood confirms cyberattack as RansomHub claims breach

Russian authorities able to identify train saboteur from anonymous Telegram account  

Malware

BlackSuit Ransomware

Year-Long Campaign of Malicious npm Packages Targeting Roblox Users  

Rocinante: The trojan horse that wanted to fly   

Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion     

FBI: Play ransomware gang has attacked 300 orgs since 2022  

New Android SpyAgent Campaign Steals Crypto Credentials via Image Recognition  

Hacking

Bypassing airport security via SQL injection

Dragon Hactivists on Prowl      

Hiding in plain sight: Techniques and defenses against `/proc` filesystem manipulation in Linux

How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions

Learning Rust for fun and backdoo-rs    

Head Mare: adventures of a unicorn in Russia and Belarus       

Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion  

Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078 

Advanced forensic techniques for recovering hidden data in wearable devices  

Recent SonicWall Firewall Vulnerability Potentially Exploited in the Wild

Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401   

Intelligence and Information Warfare 

The Geopolitics of Cyber Espionage Goes Far Beyond Sensitive Information Theft  

Social Media as an Intelligence Tool for Information Warfare

NATO Wants to Boost Its Undersea Defenses     

German air traffic control was attacked by pro-Russian hackers  

Russian Military Cyber Actors Target US and Global Critical Infrastructure

NSA’s China-focused ‘innovation pipeline’ targets economic imbalances

US cracks down on Russian disinformation before 2024 election      

BlindEagle Targets Colombian Insurance Sector with BlotchyQuasar

Chinese APT Abuses VSCode to Target Government in Asia  

With charges and sanctions, US takes aim at Russian disinformation ahead of November election

North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks      

Cybersecurity

A concrete example of ES|QL and SOC detection rules  

TfL faces ‘ongoing cyber security incident’  

What is the future of cross-border data flows?  

Managing Cybersecurity in the Age of Artificial Intelligence  

Clearview AI Faces €30.5M Fine for Building Illegal Facial Recognition Database

X is hiring staff for security and safety after two years of layoffs  

Critical Account Takeover Vulnerability Patched in LiteSpeed Cache Plugin  

A scientific approach to eavesdropping via HDMI  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168159/breaking-news/security-affairs-newsletter-round-488-by-pierluigi-paganini-international-edition.html