Connect with us

Published

on

UNAUTHENTICATED RCE THAT BYPASSES 2FA — Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networks Organizations using Ivanti Connect Secure should take action at once.

Dan Goodin – Jan 10, 2024 10:18 pm UTC EnlargeGetty Images reader comments 7

Unknown threat actors are actively targeting two critical zero-day vulnerabilities that allow them to bypass two-factor authentication and execute malicious code inside networks that use a widely used virtual private network appliance sold by Ivanti, researchers said Wednesday.

Further ReadingMore US agencies potentially hacked, this time with Pulse Secure exploitsIvanti reported bare-bones details concerning the zero-days in posts published on Wednesday that urged customers to follow mitigation guidance immediately. Tracked as CVE-2023-846805 and CVE-2024-21887, they reside in Ivanti Connect Secure, a VPN appliance often abbreviated as ICS. Formerly known as Pulse Secure, the widely used VPN has harbored previous zero-days in recent years that came under widespread exploitation, in some cases to devastating effect. Exploiters: Start your engines

When combined, these two vulnerabilities make it trivial for attackers to run commands on the system, researchers from security firm Volexity wrote in a post summarizing their investigative findings of an attack that hit a customer last month. In this particular incident, the attacker leveraged these exploits to steal configuration data, modify existing files, download remote files, and reverse tunnel from the ICS VPN appliance. Researchers Matthew Meltzer, Robert Jan Mora, Sean Koessel, Steven Adair, and Thomas Lancaster went on to write:

Volexity observed the attacker modifying legitimate ICS components and making changes to the system to evade the ICS Integrity Checker Tool. Notably, Volexity observed the attacker backdooring a legitimate CGI file (compcheck.cgi) on the ICS VPN appliance to allow command execution. Further, the attacker also modified a JavaScript file used by the Web SSL VPN component of the device in order to keylog and exfiltrate credentials for users logging into it. The information and credentials collected by the attacker allowed them to pivot to a handful of systems internally, and ultimately gain unfettered access to systems on the network.

The researchers attributed the hacks to a threat actor tracked under the alias UTA0178, which they suspect is a Chinese nation-state-level threat actor. Advertisement

Like other VPNs, the ICS sits at the edge of a protected network and acts as the gatekeeper thats supposed to allow only authorized devices to connect remotely. That position and its always-on status make the appliance ideal for targeting when code-execution vulnerabilities in them are identified. So far, the zero-days appear to have been exploited in low numbers and only in highly targeted attacks, Volexity CEO Steven Adair said in an email. He went on to write:

However, there is a very good chance that could change. There will now be a potential race to compromise devices before mitigations are applied. It is also possible that the threat actor could share the exploit or that additional attackers will otherwise figure out the exploit. If you know the detailsthe exploit is quite trivial to pull off and it requires absolutely no authentication and can be done over the Internet. The entire purposes of these devices are to provide VPN access, so by nature they sit on the Internet and are accessible.

Further ReadingCasualties keep growing in this months mass exploitation of MOVEit 0-dayThe threat landscape of 2023 was dominated by the active mass exploitation of a handful of high-impact vulnerabilities tracked under the names Citrix Bleed or designations including CVE-2022-47966, CVE-2023-34362 and CVE-2023-49103, which resided in the Citrix NetScaler Application Delivery Controller and NetScaler Gateway, the MOVEit file-transfer service, and 24 wares sold by Zoho-owned ManageEngine and ownCloud, respectively. Unless affected organizations move more quickly than they did last year to patch their networks, the latest vulnerabilities in the Ivanti appliances may receive the same treatment.

Researcher Kevin Beaumont, who proposed Connect Around as a moniker for tracking the zero-days, posted results from a scan that showed there were roughly 15,000 affected Ivanti appliances around the world exposed to the Internet. Beaumont said that hackers backed by a nation-state appeared to be behind the attacks on the Ivanti-sold device. Enlarge / Map showing geographic location of ICS deployments, led by the US, Japan, Germany, France, and Canada.Shodan Page: 1 2 Next → reader comments 7 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

UK

Fourteen children arrested on suspicion of manslaughter over Gateshead fire released on bail

Published

on

By

Fourteen children arrested on suspicion of manslaughter over Gateshead fire released on bail

All 14 children arrested on suspicion of manslaughter after a boy died in a fire have been released on police bail, officers said.

Layton Carr, 14, was found dead near the site of a fire at Fairfield industrial park in the Bill Quay area of Gateshead on Friday.

Northumbria Police said on Saturday that they had arrested 11 boys and three girls in connection with the incident.

In an update on Sunday, a Northumbria Police spokesman said: “All those arrested have since been released on police bail pending further inquiries.”

Please use Chrome browser for a more accessible video player

Teenager dies in industrial estate fire

Firefighters raced to the industrial site shortly after 8pm on Friday, putting out the blaze a short time later.

Police then issued an appeal for Carr, who was believed to be in the area at that time.

In a statement on Saturday, the force said that “sadly, following searches, a body believed to be that of 14-year-old Layton Carr was located deceased inside the building”.

More on Northumbria

David Thompson, headteacher of Hebburn Comprehensive School, where Layton was a pupil, said the school community was “heartbroken”.

Mr Thompson described him as a “valued and much-loved member of Year 9” and said he would be “greatly missed by everyone”.

He added that the school’s “sincere condolences” were with Layton’s family and that the community would “rally together to support one another through this tragedy”.

A fundraising page on GoFundMe has been set up to help Layton’s mother pay for funeral costs.

Pic: Gofundme
Image:
Pic: Gofundme

Organiser Stephanie Simpson said: “The last thing Georgia needs to stress trying to pay for a funeral for her Boy Any donations will help thank you.”

One tribute in a Facebook post read: “Can’t believe I’m writing this my nephew RIP Layton 💔 forever 14 you’ll be a massive miss, thinking of my sister and 2 beautiful nieces right now.”

Detective Chief Inspector Louise Jenkins, of Northumbria Police, also said: “This is an extremely tragic incident where a boy has sadly lost his life.”

She added that the force’s “thoughts are with Layton’s family as they begin to attempt to process the loss of their loved one”.

They are working to establish “the full circumstances surrounding the incident” and officers will be in the area to “offer reassurance to the public”, she added.

A cordon remains in place at the site while police carry out enquiries.

Continue Reading

UK

Football bodies could be forced to pay towards brain injury care costs of ex-players

Published

on

By

Football bodies could be forced to pay towards brain injury care costs of ex-players

Football bodies could be forced to pay towards the care costs of ex-players who have been diagnosed with brain conditions, under proposals set to be considered by MPs.

Campaigners are drafting amendments to the Football Governance Bill, which would treat conditions caused by heading balls as an “industrial injuries issue”.

The proposals seek to require the football industry to provide the necessary financial support.

Campaigners say existing support is not fit for purpose, including the Brain Health Fund which was set up with an initial £1m by the Professional Footballers’ Association (PFA), supported by the Premier League.

But the Premier League said the fund has supported 121 families with at-home adaptations and care home fees.

From England‘s 1966 World Cup-winning team, both Jack and Bobby Charlton died with dementia, as did Martin Peters, Ray Wilson and Nobby Stiles.

Neil Ruddock speaks to Sky's Rob Harris outside parliament
Image:
Neil Ruddock speaks to Sky’s Rob Harris outside parliament

Ex-players, including former Liverpool defender Neil Ruddock, went to parliament last week to lobby MPs.

More on Dementia

Ruddock told Sky News he had joined campaigners “for the families who’ve gone through hell”.

“A professional footballer, greatest job in the world, but no one knew the dangers, and that’s scary,” he said.

“Every time someone heads a ball it’s got to be dangerous to you. You know, I used to head 100 balls a day in training. I didn’t realise that might affect my future.”

A study co-funded by the PFA and the Football Association (FA) in 2019 found footballers were three and a half times more likely to die of a neurodegenerative disease than members of the public of the same age.

‘In denial’

Among those calling on football authorities to contribute towards the care costs of ex-players who have gone on to develop conditions such as Alzheimer’s and dementia is Labour MP Chris Evans.

Mr Evans, who represents Caerphilly in South Wales, hopes to amend the Bill to establish a care and financial support scheme for ex-footballers and told a recent event in parliament that affected ex-players “deserve to be compensated”.

Greater Manchester Mayor Andy Burnham, who helped to draft the amendment, said the game was “in denial about the whole thing”.

Mr Burnham called for it to be seen as “an industrial injuries issue in the same way with mining”.

In January, David Beckham lent his support to calls for greater support for footballers affected by dementia.

One of the amendments says that “the industry rather than the public should bear the financial burden”.

Read more from Sky News:
Woman missing for more than 60 years found ‘alive and well’
Meghan posts new photo of Prince Harry amid backlash

A spokesperson for the FA said it was taking a “leading role in reviewing and improving the safety of our game” and that it had “already taken many proactive steps to review and address potential risk factors”.

An English Football League spokesperson said it was “working closely with other football bodies” to ensure both professional and grassroots football are “as safe as it can be”.

The PFA and Premier League declined to comment.

Continue Reading

UK

Terror arrests came in context of raised warnings about Iran, with ongoing chaos in its own backyard

Published

on

By

Terror arrests came in context of raised warnings about Iran, with ongoing chaos in its own backyard

These are two separate and unrelated investigations by counter-terror officers.

But the common thread is nationality – seven out of the eight people arrested are Iranian.

And that comes in the context of increased warnings from government and the security services about Iranian activity on British soil.

Please use Chrome browser for a more accessible video player

Counter terror officers raid property

Last year, the director general of MI5, Ken McCallum, said his organisation and police had responded to 20 Iran-backed plots presenting potentially lethal threats to British citizens and UK residents since January 2022.

He linked that increase to the ongoing situation in Iran’s own backyard.

“As events unfold in the Middle East, we will give our fullest attention to the risk of an increase in – or a broadening of – Iranian state aggression in the UK,” he said.

The implication is that even as Iran grapples with a rapidly changing situation in its own region, having seen its proxies, Hezbollah in Lebanon and Hamas in Gaza, decimated and itself coming under Israeli attack, it may seek avenues further abroad.

More on Iran

The government reiterated this warning only a few weeks ago, with security minister Dan Jarvis addressing parliament.

“The threat from Iran sits in a wider context of the growing, diversifying and evolving threat that the UK faces from malign activity by a number of states,” Jarvis said.

“The threat from states has become increasingly interconnected in nature, blurring the lines between: domestic and international; online and offline; and states and their proxies.

“Turning specifically to Iran, the regime has become increasingly emboldened, asserting itself more aggressively to advance their objectives and undermine ours.”

Read more:
Anybody working for Iran in UK must register or face jail, government announces

As part of that address, Jarvis highlighted the National Security Act 2023, which “criminalises assisting a foreign intelligence service”, among other things.

So it was notable that this was the act used in one of this weekend’s investigations.

The suspects were detained under section 27 of the same act, which allows police to arrest those suspected of being “involved in foreign power threat activity”.

Those powers are apparently being put to use.

Continue Reading

Trending