Today’s roundup
Fortinet Warns of New RCE Flaw in FortiNAC, Actively Exploited in the Wild
Over 100,000 Fortinet Devices Still Unpatched for Critical Flaw
Critical Vulnerability in SolarWinds Access Rights Manager (CVE-2023-33297) Allows RCE
New BlackCat (ALPHV) Ransomware Variant Targets VMware ESXi Servers
Cloudflare Suffers Major Outage Affecting Websites Globally
MOVEit Transfer Zero-Day Exploitation Leads to Mass Data Breaches
FIN7 Group Suspected in New Wave of Point-of-Sale (POS) Malware Attacks
Microsoft Patch Tuesday Addresses 98 Vulnerabilities, Including 6 Zero-Days
New Phishing Campaign Impersonates Microsoft 365 to Steal Credentials
Researchers Uncover Stealthy Backdoor in Open-Source Libraries
Summary
Fortinet issued an urgent alert for a critical RCE vulnerability (CVE-2023-33299, CVSS 9.6) in its FortiNAC solution. Actively exploited, this flaw allows unauthenticated attackers root access. Immediate patching is urged.
Over 100,000 Fortinet FortiGate and FortiProxy devices remain unpatched for the critical authentication bypass (CVE-2022-40684), disclosed and actively exploited last year. This ongoing vulnerability continues to expose organizations to compromise.
SolarWinds disclosed a critical RCE vulnerability (CVE-2023-33297, CVSS 9.8) in its Access Rights Manager (ARM). Unauthenticated attackers can execute arbitrary code with elevated privileges. Users must update to 2023.2 HF1 or 2023.4.
A new Linux-based BlackCat (ALPHV) ransomware variant has been identified, specifically designed to encrypt virtual machines on VMware ESXi servers, enhancing its capability against critical infrastructure. Organizations are advised to strengthen backups and network segmentation.
Cloudflare experienced a widespread global outage, impacting numerous websites for several hours due to a data center configuration error, not a cyberattack. The incident highlighted significant reliance on major internet infrastructure providers.
A zero-day vulnerability (CVE-2023-34362) in MOVEit Transfer is actively exploited by the Clop ransomware group, causing widespread data breaches. CISA added this critical SQL injection to its Known Exploited Vulnerabilities Catalog, mandating urgent patching for federal agencies.
The FIN7 cybercrime group is suspected of new point-of-sale (POS) malware attacks across retail and hospitality. New custom malware and TTPs, primarily via phishing and supply chain attacks, aim to steal credit card data.
Microsoft's latest Patch Tuesday addressed 98 vulnerabilities, including six actively exploited zero-days. Critical flaws in Windows MSMQ, SharePoint, and Kernel, with RCE and privilege escalation, require immediate patching.
A sophisticated phishing campaign impersonates Microsoft 365 login pages to steal user credentials. It uses convincing spoofed emails, bypasses filters, and leverages compromised accounts. MFA enforcement and employee training are advised.
Researchers uncovered a stealthy backdoor embedded in popular open-source libraries, enabling unauthorized access and command execution on systems. This supply chain attack underscores third-party code risks, urging dependency audits and updates.
Want to dig deeper?
Vulnerabilities
Cyber Groups
| FIN7 | GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest |
Malware Families