Tag: Cybersecurity and Infrastructure Security Agency

CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports
News

CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports

Citing evidence of active exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security hole affecting the open-source enterprise resource planning (ERP) system, Apache OFBiz, to its list of known exploited vulnerabilities (KEV) on Tuesday. The vulnerability, identified as CVE-2024-38856, has a critical severity CVSS score of 9.8. According to CISA, Apache OFBiz has an improper permission vulnerability that could enable remote code execution by an unauthorized attacker using a Groovy payload within the OFBiz user process. Earlier this month, SonicWall revealed details of the vulnerability, describing it as a patch bypass for another issue, CVE-2024-36104, that allows remote code execution through specially crafted request...
CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September
News

CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Versa Director security issue to its list of known exploited vulnerabilities (KEVs). A file upload problem affecting the "Change Favicon" feature is the source of the medium-severity vulnerability, identified as CVE-2024-39717 (CVSS score: 6.6). This exploit could enable a threat actor to submit a malicious file by disguising it as a seemingly innocent PNG image file. According to a CISA alert, administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin access can alter the user interface of the Versa Director GUI through an unlimited upload of files with a hazardous type vulnerability read more about CISA Urges Federal Agencies to Patch Versa D...
CISA Warns of Hackers Exploiting Legacy Cisco Smart Install Feature
News

CISA Warns of Hackers Exploiting Legacy Cisco Smart Install Feature

In an effort to obtain sensitive data, threat actors are misusing the outdated Cisco Smart Install (SMI) capability, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The organization claimed to have observed adversaries obtain system configuration files via taking advantage of software or protocols that are installed on devices, such as by misusing the outdated Cisco Smart Install function. Additionally, it stated that it still notices weak password types being used on Cisco network devices, leaving them vulnerable to password-cracking attempts. The terms "password types" and "system configuration file" relate to the algorithms used to protect a Cisco device's password read more about CISA Warns of Hackers Exploiting Legacy Cisco Smart Install Feature. ...
Oracle WebLogic Server OS Command Injection Flaw Under Active Attack
News

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security issue affecting the Oracle WebLogic Server to the Known Exploited Vulnerabilities (KEV) database on Thursday. The problem, identified as CVE-2017-3506 (CVSS score: 7.4), is related to an operating system (OS) command injection vulnerability that might be used to gain full control of vulnerable servers and gain unauthorized access. A product of the Fusion Middleware suite, Oracle WebLogic Server, has an OS command injection vulnerability, according to CISA, which enables an attacker to execute arbitrary code using a carefully constructed HTTP request that contains a malicious XML document. The China-based cryptojacking organization known as the 8220 Gang (aka W...
CISA Asks Manufacturers to Prioritize Cybersecurity in Product Design
News

CISA Asks Manufacturers to Prioritize Cybersecurity in Product Design

A new set of guidelines has been jointly released by several cybersecurity organizations from around the world to assist manufacturers in giving cybersecurity practices priority while building products. The Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), and the cybersecurity agencies of Australia, Canada, the UK, Germany, the Netherlands, and New Zealand all contributed to the creation of the document. Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default, the guidance's title, was released on Thursday and outlines key principles in addition to offering specific technical advice read more CISA Asks Manufacturers to Prioritize Cybersecurity i...
CISA Releases Recovery Tool for VMware Ransomware Victims
News

CISA Releases Recovery Tool for VMware Ransomware Victims

A new script has been released by the US Cybersecurity and Infrastructure Security Agency (CISA) to aid ransomware victims in recovering any VMware virtual machines (VMs) affected by a recent worldwide attack. Based on a Monday "internet-wide" scanning attempt, ransomware payment tracker Ransomwhere believed there were 3800 victims. It claimed that four payments totaling $88,000 had been paid, however this certainly understates the size of the effort. According to early reports from national CERTs, the threat actors responsible for it are using CVE-2021-21974 as a backdoor to execute remote code on VMware's ESXi hypervisors by causing a heap-overflow vulnerability in OpenSLP read the complete article CISA Releases Recovery Tool for VMware Ransomware Victims. With ReconBee.com St...