Security Vulnerability Weekly 22/08/22 - Apple Vulnerability, Android Bugdrop Vulnerability, Wordpress, CISA, and recent Hacks to Mailchimp and Twilio

Security Vulnerability Weekly 22/08/22 - Apple Vulnerability, Android Bugdrop Vulnerability, Wordpress, CISA, and recent Hacks to Mailchimp and Twilio

Article Extract of: https://appsecphoenix.com/security-vulnerability-weekly-22-08-22/


Previous Issues of vulnerability Weekly

This week we deep dive into Apple Vulnerability,?CISA new vulnerability for September, Bugdrop new android vulnerabilities, recent hacks to twilio exposing digital ocaean clients and Mailchimp hack

Appsec

WordPress Hacked by fake Cloudflare


No alt text provided for this image

WordPress sites are being hacked to display fake Cloudflare DDoS protection pages to distribute NetSupport RAT and the RaccoonStealer password-stealing Trojan.

DDoS is a distributed denial of service, a technique used to bring down a website utilizing a sheer amount of traffic.

A report by Sucuri, details the actors are hacking poorly protected WordPress sites to add a heavily obfuscated JavaScript payload that displays a fake Cloudflare protection DDoS screen.

No alt text provided for this image


Fake DDoS protection screen (Sucuri)

No alt text provided for this image


Clicking on the link results in a download of files?

When a user opens the security_install.iso, they will see a file called security_install.exe, which is a Windows shortcut that runs a PowerShell command from the debug.txt file.

How to protect

Admins should check the theme files of their WordPress sites, as according to Sucuri, this is the most common infection point in this campaign.

Malicious code found in jquery.min.js (Sucuri)

Additionally, it is advisable to employ file integrity monitoring systems to catch those JS injections as they happen and prevent your site from being a RAT distribution point.

CISA adds 7 vulnerabilities to the list of threats actively exploited by hackers?

No alt text provided for this image


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its list of bugs actively exploited by hackers, with the new flaws disclosed by Apple. Microsoft, SAP, and Google.

The seven vulnerabilities added on the 18 August, with CISA requiring all of them to be patched by September 8th, 2022.

Apple released macOS and iOS/iPadOS security updates on Wednesday for the CVE-2022-32893 and CVE-2022-32894 vulnerabilities, explaining that they could be exploited to perform code execution on vulnerable devices (see below for details)?

INFRA/Network

Apple Zero Day Vulnerability takes internet by storm

No alt text provided for this image


Apple is again in the eye of the storm, with two zero-day now patched. Apple has released security updates for iOS, iPadOS, and macOS platforms to remediate two zero-day vulnerabilities.

The two zero day enables remote exploitation and access to the camera, microphone and executes code with the highest privileges.

The vulnerability might be actively exploited as Apple said in the recent release. We covered the other set of vulnerabilities in the previous version of Security Vulnerability of the Week 08/08/22?

The list of issues is below -

  • CVE-2022-32893 - An out-of-bounds issue in WebKit which could lead to the execution of arbitrary code by processing a specially crafted web content
  • CVE-2022-32894 - An out-of-bounds issue in the operating system's Kernel that could be abused by a malicious application to execute arbitrary code with the highest privileges

Those are added to the existing:

  • CVE-2022-22587 (IOMobileFrameBuffer) – A malicious application may be able to execute arbitrary code with kernel privileges
  • CVE-2022-22620 (WebKit) – Processing maliciously crafted web content may lead to arbitrary code execution
  • CVE-2022-22674 (Intel Graphics Driver) – An application may be able to read kernel memory
  • CVE-2022-22675 (AppleAVD) – An application may be able to execute arbitrary code with kernel privileges

Both the vulnerabilities have been fixed in iOS 15.6.1, iPadOS 15.6.1, and macOS Monterey 12.5.1

Apple on Thursday released a security update for Safari web browser (version 15.6.1) for macOS Big Sur and Catalina to patch the WebKit vulnerability fixed in macOS Monterey.

Rest of the article:

https://appsecphoenix.com/security-vulnerability-weekly-22-08-22/

Ravi Teja T.

M.Sc | Security Engineer

2 年

Thank you for insight ?? Francesco ?? Cipollone, you are killing it ??

要查看或添加评论,请登录

?? Francesco ?? Cipollone的更多文章

社区洞察

其他会员也浏览了