Today’s roundup
ConnectWise ScreenConnect RCE Vulnerability Under Active Exploitation
CISA and FBI Release Advisory on Akira Ransomware
CISA Releases Twelve Industrial Control Systems Advisories
Thousands of Fortinet FortiGate VPNs Found Vulnerable to New Exploit
Cisco Patches Critical Vulnerabilities in IOS XE and Nexus Products
New Phishing Kit Targets Microsoft 365 Users with Sophisticated Lures
New Malvertising Campaign Uses Google Ads to Distribute Remote Access Trojans
Over 2 Million Devices Compromised by Infostealer Malware in Q3 2023
European Commission announces launch of Joint Cyber Unit
US Sanctions Russian Individuals and Entities for Cyber Activities
Summary
Cybersecurity researchers report active exploitation of two critical vulnerabilities in ConnectWise ScreenConnect (CVE-2024-46805, CVE-2024-46806), an authentication bypass and a path traversal leading to unauthenticated remote code execution. Patches for versions 23.9.7 and earlier are available in 23.9.8. CISA has added these to its Known Exploited Vulnerabilities Catalog.
CISA and the FBI issued an advisory (AA23-322A) on November 18, 2023, detailing Akira ransomware, targeting Windows/Linux by exploiting VPN vulnerabilities (e.g., Cisco ASA/FTD zero-day CVE-2023-20269) for data exfiltration and encryption. Over 250 organizations, including critical infrastructure, have been impacted with multi-million dollar ransom demands.
On November 7, 2023, CISA released twelve Industrial Control Systems (ICS) advisories for vulnerabilities in products from Siemens, Rockwell Automation, AVEVA, Delta Electronics, and Hitachi Energy. Some flaws have CVSS scores up to 9.8, posing significant risks to critical infrastructure; organizations are urged to apply updates promptly.
A new exploit (CVE-2023-36551) affects Fortinet FortiGate VPN devices, allowing unauthenticated attackers to retrieve sensitive information like hashed passwords. Thousands of devices are vulnerable. Fortinet has released patches, and users are advised to update immediately to prevent data exposure.
Cisco released security updates addressing multiple critical vulnerabilities in its IOS XE operating system and Nexus products. The most severe flaws permit unauthenticated remote attackers to execute arbitrary code or cause denial-of-service conditions. Customers are advised to apply patches without delay.
A sophisticated new phishing kit, actively targeting Microsoft 365 users globally, is designed to bypass multi-factor authentication (MFA). It uses convincing login pages and real-time proxying of credentials/session cookies to compromise accounts despite MFA, prompting calls for enhanced user training and detection.
A new malvertising campaign uses Google Ads to distribute remote access Trojans (RATs) like DarkGate and IcedID. Attackers impersonate legitimate software (e.g., Zoom) in sponsored search results, leading users to malicious download sites. The campaign employs evasion techniques and rapid domain rotation.
A Q3 2023 report reveals over 2 million devices were compromised by infostealer malware, leading to the theft of credentials, financial data, and personal information. This significant increase in attacks, often spread via malvertising and phishing, highlights the pervasive threat of data exfiltration.
The European Commission officially launched its Joint Cyber Unit on November 7, 2023, to strengthen EU cybersecurity. It acts as an operational cooperation platform for EU institutions, member states, and private entities, focusing on enhancing cyber crisis management, intelligence sharing, and collective response.
On November 9, 2023, the U.S. Treasury Department sanctioned Russian individuals and entities for malicious cyber activities, including ransomware attacks and critical infrastructure targeting. This action aims to disrupt operations and hold perpetrators accountable.
Want to dig deeper?
Cyber Groups
| Akira | GOLD SAHARA, PUNK SPIDER, Howling Scorpius |
Malware Families