UNAUTHENTICATED RCE THAT BYPASSES 2FA — Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networks Organizations using Ivanti Connect Secure should take action at once.
Dan Goodin – Jan 10, 2024 10:18 pm UTC EnlargeGetty Images reader comments 7
Unknown threat actors are actively targeting two critical zero-day vulnerabilities that allow them to bypass two-factor authentication and execute malicious code inside networks that use a widely used virtual private network appliance sold by Ivanti, researchers said Wednesday.
Further ReadingMore US agencies potentially hacked, this time with Pulse Secure exploitsIvanti reported bare-bones details concerning the zero-days in posts published on Wednesday that urged customers to follow mitigation guidance immediately. Tracked as CVE-2023-846805 and CVE-2024-21887, they reside in Ivanti Connect Secure, a VPN appliance often abbreviated as ICS. Formerly known as Pulse Secure, the widely used VPN has harbored previous zero-days in recent years that came under widespread exploitation, in some cases to devastating effect. Exploiters: Start your engines
When combined, these two vulnerabilities make it trivial for attackers to run commands on the system, researchers from security firm Volexity wrote in a post summarizing their investigative findings of an attack that hit a customer last month. In this particular incident, the attacker leveraged these exploits to steal configuration data, modify existing files, download remote files, and reverse tunnel from the ICS VPN appliance. Researchers Matthew Meltzer, Robert Jan Mora, Sean Koessel, Steven Adair, and Thomas Lancaster went on to write:
Volexity observed the attacker modifying legitimate ICS components and making changes to the system to evade the ICS Integrity Checker Tool. Notably, Volexity observed the attacker backdooring a legitimate CGI file (compcheck.cgi) on the ICS VPN appliance to allow command execution. Further, the attacker also modified a JavaScript file used by the Web SSL VPN component of the device in order to keylog and exfiltrate credentials for users logging into it. The information and credentials collected by the attacker allowed them to pivot to a handful of systems internally, and ultimately gain unfettered access to systems on the network.
The researchers attributed the hacks to a threat actor tracked under the alias UTA0178, which they suspect is a Chinese nation-state-level threat actor. Advertisement
Like other VPNs, the ICS sits at the edge of a protected network and acts as the gatekeeper thats supposed to allow only authorized devices to connect remotely. That position and its always-on status make the appliance ideal for targeting when code-execution vulnerabilities in them are identified. So far, the zero-days appear to have been exploited in low numbers and only in highly targeted attacks, Volexity CEO Steven Adair said in an email. He went on to write:
However, there is a very good chance that could change. There will now be a potential race to compromise devices before mitigations are applied. It is also possible that the threat actor could share the exploit or that additional attackers will otherwise figure out the exploit. If you know the detailsthe exploit is quite trivial to pull off and it requires absolutely no authentication and can be done over the Internet. The entire purposes of these devices are to provide VPN access, so by nature they sit on the Internet and are accessible.
Further ReadingCasualties keep growing in this months mass exploitation of MOVEit 0-dayThe threat landscape of 2023 was dominated by the active mass exploitation of a handful of high-impact vulnerabilities tracked under the names Citrix Bleed or designations including CVE-2022-47966, CVE-2023-34362 and CVE-2023-49103, which resided in the Citrix NetScaler Application Delivery Controller and NetScaler Gateway, the MOVEit file-transfer service, and 24 wares sold by Zoho-owned ManageEngine and ownCloud, respectively. Unless affected organizations move more quickly than they did last year to patch their networks, the latest vulnerabilities in the Ivanti appliances may receive the same treatment.
Researcher Kevin Beaumont, who proposed Connect Around as a moniker for tracking the zero-days, posted results from a scan that showed there were roughly 15,000 affected Ivanti appliances around the world exposed to the Internet. Beaumont said that hackers backed by a nation-state appeared to be behind the attacks on the Ivanti-sold device. Enlarge / Map showing geographic location of ICS deployments, led by the US, Japan, Germany, France, and Canada.Shodan Page: 1 2 Next → reader comments 7 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars
Palestinian President Mahmoud Abbas and 80 other officials have been blocked from attending September’s annual meeting of the United Nations General Assembly in New York.
US secretary of state Marco Rubio has revoked the US visas of delegates from the Palestinian Authority (PA) and Palestine Liberation Organisation (PLO), and denied others from applying for one.
It is the latest step by Donald Trump’s administration to target Palestinians with visa restrictions, and follows the suspension of a programme to allow injured children from Gaza to receive treatment in the US.
Image: Mahmoud Abbas addressed the general assembly in 2024, but is barred from next month’s meeting. Pic: Reuters
“It is in our national security interests to hold the PLO and PA accountable for not complying with their commitments, and for undermining the prospects for peace,” a statement from the US State Department said.
It added that, to be considered partners for peace, both groups “must consistently repudiate terrorism, and end incitement to terrorism in education, as required by US law and as promised by the PLO”.
Israel declared Gaza’s largest city a dangerous combat zone on Friday.
The army launched a planned offensive that has drawn international condemnation.
Please use Chrome browser for a more accessible video player
0:44
Thick smoke rises from Gaza City after Israeli strikes
Foreign ministers from Iceland, Ireland, Luxembourg, Norway, Slovenia and Spain released a joint statement saying the military operations in Gaza City will cause “intolerable deaths of innocent Palestinian civilians”.
Hundreds of thousands of Palestinians are sheltering in Gaza City while enduring famine.
Image: An Israeli armoured vehicle in northern Gaza on Friday. Pic: AP
Image: Palestinians ride a truck carrying humanitarian aid in Gaza City. Pic: AP
The Palestinian ambassador to the United Nations (UN), Riyad Mansour, said Mr Abbas had planned to lead the delegation to the UN meetings and was expected to address the general assembly at the general debate, which begins on 23 September.
He was also expected to attend a high-level meeting co-chaired by France and Saudi Arabia on 22 September about a two-state solution, a broad idea involving Israel coexisting with an independent Palestinian state.
The State of Palestine is an observer member of the UN, meaning it can speak at meetings but not vote on resolutions.
Image: The State of Palestine cannot vote on UN resolutions. Pic: AP
US decision ‘contravenes international law’
The Palestinian Authority “expressed its deep regret and astonishment” at the visa decision, calling it “a violation of US commitments” as the host of the UN, and claiming it “contravenes international law”.
UN spokesman Stephane Dujarric said the world body would be seeking clarification in the “hope that this will be resolved”.
Image: Hundreds of diplomats left when Israeli leader Benjamin Netanyahu began speaking at the general assembly in 2024. Pic: Reuters
The State Department said that the Palestinian Authority’s mission to the UN, comprising officials who are permanently based there, would not be included in the restrictions.
Under a 1947 UN agreement, the US is generally required to allow access for foreign diplomats to the UN in New York.
But Washington has said it can deny visas for security, extremism and foreign policy reasons.
The death toll in Gaza has now risen to 63,025, according to the Hamas-run health ministry, which does not differentiate between civilians and combatants.
It also reported five more malnutrition-related deaths in the last 24 hours, bringing the total number during the war to 322, with 121 of them children.
Palestinian President Mahmoud Abbas and 80 other officials have been blocked from attending September’s annual meeting of the United Nations General Assembly in New York.
US secretary of state Marco Rubio has revoked the US visas of delegates from the Palestinian Authority (PA) and Palestine Liberation Organisation (PLO), and denied others from applying for one.
It is the latest step by Donald Trump’s administration to target Palestinians with visa restrictions, and follows the suspension of a programme to allow injured children from Gaza to receive treatment in the US.
Image: Mahmoud Abbas addressed the general assembly in 2024, but is barred from next month’s meeting. Pic: Reuters
“It is in our national security interests to hold the PLO and PA accountable for not complying with their commitments, and for undermining the prospects for peace,” a statement from the US State Department said.
It added that, to be considered partners for peace, both groups “must consistently repudiate terrorism, and end incitement to terrorism in education, as required by US law and as promised by the PLO”.
Israel declared Gaza’s largest city a dangerous combat zone on Friday.
The army launched a planned offensive that has drawn international condemnation.
Please use Chrome browser for a more accessible video player
0:44
Thick smoke rises from Gaza City after Israeli strikes
Foreign ministers from Iceland, Ireland, Luxembourg, Norway, Slovenia and Spain released a joint statement saying the military operations in Gaza City will cause “intolerable deaths of innocent Palestinian civilians”.
Hundreds of thousands of Palestinians are sheltering in Gaza City while enduring famine.
Image: An Israeli armoured vehicle in northern Gaza on Friday. Pic: AP
Image: Palestinians ride a truck carrying humanitarian aid in Gaza City. Pic: AP
The Palestinian ambassador to the United Nations (UN), Riyad Mansour, said Mr Abbas had planned to lead the delegation to the UN meetings and was expected to address the general assembly at the general debate, which begins on 23 September.
He was also expected to attend a high-level meeting co-chaired by France and Saudi Arabia on 22 September about a two-state solution, a broad idea involving Israel coexisting with an independent Palestinian state.
The State of Palestine is an observer member of the UN, meaning it can speak at meetings but not vote on resolutions.
Image: The State of Palestine cannot vote on UN resolutions. Pic: AP
US decision ‘contravenes international law’
The Palestinian Authority “expressed its deep regret and astonishment” at the visa decision, calling it “a violation of US commitments” as the host of the UN, and claiming it “contravenes international law”.
UN spokesman Stephane Dujarric said the world body would be seeking clarification in the “hope that this will be resolved”.
Image: Hundreds of diplomats left when Israeli leader Benjamin Netanyahu began speaking at the general assembly in 2024. Pic: Reuters
The State Department said that the Palestinian Authority’s mission to the UN, comprising officials who are permanently based there, would not be included in the restrictions.
Under a 1947 UN agreement, the US is generally required to allow access for foreign diplomats to the UN in New York.
But Washington has said it can deny visas for security, extremism and foreign policy reasons.
The death toll in Gaza has now risen to 63,025, according to the Hamas-run health ministry, which does not differentiate between civilians and combatants.
It also reported five more malnutrition-related deaths in the last 24 hours, bringing the total number during the war to 322, with 121 of them children.
China’s Dongfang Electric has installed a 26-megawatt offshore wind turbine, snatching the title of world’s most powerful from Siemens Gamesa’s 21.5 turbine in Denmark.
Photo: Dongfang Electric Corporation
The Chinese state-owned manufacturer announced today that it has installed the world’s most powerful wind turbine prototype at a testing and certification base. This turbine, the world’s largest for capacity and size, boasts a blade wheel diameter of more than 310 meters (1,107 feet) and a hub height of 185 meters (607 feet). Dongfang shipped the turbine’s nacelle earlier this month – the world’s heaviest – along with three blades.
This offshore wind turbine is designed for areas with wind speeds of 8 meters per second and above. With average winds of 10 meters per second, just one of these giants can generate 100 GWh of power annually, which is enough to power 55,000 homes. That’s enough to cut standard coal consumption by 30,000 tons and reduce CO2 emissions by 80,000 tons. Dongfang says it’s wind resistant up to 17 (200 km/h) on the extended Beaufort scale.
In May, Dongfang said it had completed static load testing on the turbine’s blades, and the turbine is now undergoing fatigue testing, which could take up to a year before the turbine is fully certified.
The 30% federal solar tax credit is ending this year. If you’ve ever considered going solar, now’s the time to act. To make sure you find a trusted, reliable solar installer near you that offers competitive pricing, check out EnergySage, a free service that makes it easy for you to go solar. It has hundreds of pre-vetted solar installers competing for your business, ensuring you get high-quality solutions and save 20-30% compared to going it alone. Plus, it’s free to use, and you won’t get sales calls until you select an installer and share your phone number with them.
Your personalized solar quotes are easy to compare online and you’ll get access to unbiased Energy Advisors to help you every step of the way. Get started here.
FTC: We use income earning auto affiliate links.More.