Posts

Showing posts with the label Proof of Concept

Cybersecurity agencies reveal top exploited vulnerabilities of 2021

By Sergiu Gatlan, Bleeping Computer In partnership with the NSA and the FBI, cybersecurity authorities worldwide have released today a list of the top 15 vulnerabilities routinely exploited by threat actors during 2021. The cybersecurity authorities urged organizations in a joint advisory to promptly patch these security flaws and implement patch management systems to reduce their attack surface. Globally, malicious actors have been observed focusing their attacks on internet-facing systems, including email and virtual private network (VPN) servers, using exploits targeting newly disclosed vulnerabilities. "U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities assess, in 2021, malicious cyber actors aggressively targeted newly disclosed critical software vulnerabilities against broad target sets, including public and private sector organizations worldwide," the advisory reads. This might be due to malicious actors and security researchers releasing proof o...

Amazon Web Services fixes container escape in Log4Shell hotfix

Image
By Bill Toulas, Bleeping Computer Amazon Web Services (AWS) has fixed four security issues in its hot patch from December that addressed the critical Log4Shell vulnerability (CVE-2021-44228) affecting cloud or on-premise environments running Java applications with a vulnerable version of the Log4j logging library or containers. The hot patch packages from Amazon are not exclusive to AWS resources and allowed escaping a container in the environment and taking control of the host. The flaws could also be exploited through unprivileged processes to elevate privileges and execute code as with root permissions. The vulnerabilities are currently tracked as CVE-2021-3100, CVE-2021-3101, CVE-2022-0070, and CVE-2022-0071. All of them have been assessed as high-severity risks with a score of 8.8 out of 10. Hot patch trouble Security researchers at Palo Alto Network's Unit 42 discovered that Amazon's Log4Shell hot-fix solutions would keep searching for Java processes and patch them on the...

CISA warns of attackers now exploiting Windows Print Spooler bug

Image
By Sergiu Gatlan, Bleeping Computers The Cybersecurity and Infrastructure Security Agency (CISA) has added three new security flaws to its list of actively exploited bugs, including a local privilege escalation bug in the Windows Print Spooler. This high severity vulnerability (tracked as CVE-2022-22718) impacts all versions of Windows per Microsoft's advisory and it was patched during the February 2022 Patch Tuesday. The only information Microsoft shared about this security flaw is that threat actors can exploit it locally in low-complexity attacks without user interaction. Redmond patched several other Windows Print Spooler bugs in the last 12 months, including the critical PrintNightmare remote code execution vulnerability. After technical details and a proof-of-concept (POC) exploit for PrintNightmare were accidentally leaked, CISA warned admins to disable the Windows Print Spooler service on Domain Controllers and systems not used for printing to block potentially incoming a...