Cybersecurity News

Issue 03: Android and Linux Devices Exposed, ConnectWise ScreenConnect Flaws and Akira Strikes Again

Table of Contents

Welcome to Critical Chatter, CloudGuard’s weekly cyber news update. This week’s news flash has been curated by Martin Vondrous (SOC Analyst).

Top stories – 23 February 2024

New Wi-Fi Vulnerabilities Expose Android and Linux Devices to Hackers

Two authentication bypass flaws have been uncovered in open-source Wi-Fi software used across Android, Linux, and ChromeOS systems. These vulnerabilities, named CVE-2023-52160 and CVE-2023-52161, were detected in wpa_supplicant and Intel’s iNet Wireless Daemon (IWD) respectively.

These flaws enable attackers to deceive users into connecting to malicious networks or gaining entry to trusted networks without passwords. The research was conducted by Top10VPN in collaboration with Mathy Vanhoef, renowned for revealing Wi-Fi attacks like KRACK. CVE-2023-52161 permits unauthorised access to secured Wi-Fi networks, potentially resulting in malware infections and data breaches. However, CVE-2023-52160, which affects wpa_supplicant, is considered more severe as it is the default software for network logins in Android devices.

Exploiting CVE-2023-52160 necessitates prior knowledge of the SSID from a previous connection and physical proximity to the target. Several Linux distributions, including Debian, Red Hat, SUSE, and Ubuntu, have issued advisories with fixes available for ChromeOS but still pending for Android. As a precautionary measure, Android users are advised to manually configure CA certificates for saved enterprise networks.

Article Link: New Wi-Fi Vulnerabilities Expose Android and Linux Devices to Hackers (thehackernews.com)

Critical Flaws Found in ConnectWise ScreenConnect Software

ConnectWise has addressed two security vulnerabilities in its ScreenConnect remote desktop software, including a critical bug with potential remote code execution.

The vulnerabilities are:

· CVE-2024-1708: Path traversal flaw

· CVE-2024-1709: Authentication bypass

Deemed critical, these flaws impact ScreenConnect versions 23.9.7 and earlier, with fixes available in version 23.9.8, released after reports on February 13, 2024. While there’s no evidence of exploitation yet, users of self-hosted or on-premise versions are urged to update promptly. ConnectWise will also offer updates for versions 22.4 through 23.9.7.

HuntressLabs discovered over 8,800 vulnerable servers, with a proof-of-concept exploit demonstrated. ConnectWise revised its advisory after detecting attacks from specific IP addresses, suggesting active exploitation. Huntress warned of easy exploitation, facilitating the deployment of Cobalt Strike for post-exploitation activities. These flaws could allow the creation of rogue administrator accounts, granting full control over ScreenConnect, and access to other directories, enabling arbitrary code execution.

WatchTowr Labs and Horizon3 ai released proof-of-concept exploits for the authentication bypass, exploiting vulnerabilities in the SetupWizard component to create administrative users. These vulnerabilities follow a trend of recent flaws allowing attackers to reinitialise applications or create initial users post-setup.

Article Link: Critical Flaws Found in ConnectWise ScreenConnect Software – Patch Now (thehackernews.com)

CISA Warning: Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a now-patched security flaw, CVE-2020-3259, affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software, in its Known Exploited Vulnerabilities catalogue.

This vulnerability, with a CVSS score of 7.5, permits high-severity information disclosure, patched by Cisco in May 2020. Reports suggest the vulnerability has likely been exploited in Akira ransomware attacks. Although no public exploit code is available, Akira ransomware actors may have weaponised it to compromise Cisco Anyconnect SSL VPN appliances. Akira ransomware is linked to approximately 200 public victims, with connections to the Conti syndicate.

Federal Civilian Executive Branch agencies must address identified vulnerabilities by March 7, 2024, to fortify network security. CVE-2020-3259 is among flaws exploited for ransomware delivery. Recently, CVE-2023-22527 in Atlassian Confluence Data Center and Confluence Server was abused to distribute C3RB3R ransomware.

The U.S. State Department offers rewards for information on BlackCat ransomware gang members, highlighting the lucrative ransomware market. New players like Alpha, potentially linked to NetWalker, have emerged, prompting calls for enhanced oversight into ransomware mitigation practices across critical sectors.

Article Link: CISA Warning: Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability (thehackernews.com)

If you like what you’ve read, subscribe on LinkedIn so you don’t miss next week’s roundup!

Author: Jen Begue
Share:
Author: Jen Begue
Share:

Related Resources

Critical Chatter Issue 77
Issue 77: Critical Exchange Flaw, SonicWall VPN Exploits, UK CNI Threat Warning
critical chatter banner
Issue 39: Are your credentials safe? Massive exploits threaten key systems
Issue 04: ConnectWise Mass Exploitation, 8,000+ Trusted Brand Domains Hijacked, LockBit Ransomware & Midnight Blizzard
Welcome to Critical Chatter, CloudGuard’s weekly cyber news update. This week’s news flash has been curated by Vaughan Carey (SOC Leader). Top stories – 01 March 2024 ConnectWise ScreenConnect Mass Exploitation Delivers Ransomware 8,000+ Domains of Trusted Brands Hijacked for Massive Spam Operation LockBit Reemerges, a Week After ‘Complete Compromise’...
Critical Chatter Issue 2: Microsoft Bugs, Deepfakes and Facebook Marketplace Leak
Welcome to another week of Critical Chatter, CloudGuard’s weekly roundup of security articles curated by Guardians. This week’s news flash has been curated by Dafydd Davies (SOC Automation Engineer). Top stories – 16 February 2024 New critical Microsoft Outlook RCE bug is trivial to exploit Hackers used new Windows Defender...
Critical Chatter Issue 1: AnyDesk, CloudFlare and Microsoft breaches
Welcome to another week of Critical Chatter, CloudGuard’s weekly roundup of security articles curated by Guardians. This week’s news flash has been curated by Joe Appleby (SOC Analyst). Top stories – 09 February 2024 AnyDesk says hackers breached its production servers, reset passwords Cloudflare Breach: Nation-State Hackers Access Source Code...
image of british library with text "6 crucial lessons to learn from the british library cyber attack"
6 Crucial Lessons to Learn from the British Library Cyber Attack
You’ve probably read about the British Library cyber attack in the news. But imagine waking up to the news that your organisation’s data has been compromised, and cybercriminals are auctioning off sensitive information on the dark web. Unfortunately, this nightmare became a reality for security professional working the the British...
critical chatter by cloudguard
Critical Chatter: Apple, Cisco, Android, and Mircosoft vulnerabilities
Welcome to another week of Critical Chatter, CloudGuard’s weekly roundup of security articles curated by Guardians. This week’s news flash has been curated by Joe Appleby (SOC Analyst). Top stories – 8 September 2023 Apple zero-click iMessage exploit used to infect iPhones with spyware Cisco BroadWorks impacted by critical authentication...
critical chatter by cloudguard
Critical Chatter: Exploited CISCO VPNs, WinRAR zero-day, malicious Google ads and more
Welcome to another week of Critical Chatter, CloudGuard’s weekly roundup of security articles curated by Guardians. This week’s news flash has been curated by Joe Appleby (SOC Analyst). Top stories – 25 August 2023 New Akira ransomware targets businesses via exploited CISCO VPNs New stealthy techniques let hackers gain Windows...
critical chatter by cloudguard
Critical Chatter: Lolek Hosted dismantled, multiple Citrix exploits, LinkedIn account hacks and website phishing
Welcome to another week of Critical Chatter, CloudGuard’s weekly roundup of security articles curated by Guardians. This week’s news flash has been curated by Vaughan Carey (Senior SOC Analyst). Top stories – 18 August 2023 Lolek bulletproof hosting servers seized CISA adds Citrix ShareFile flaw to KEV catalogue 400,000 proxy...
Get In Touch

Our Cybersecurity Services Can Instantly Improve Your Business’ Security Posture

Complete the form to find out more about any of our one-off or managed cybersecurity services. Not seeing what you’re looking for? Our cybersecurity consultants and MXDR experts are always on-hand to provide the guidance and support you need.