Showing posts with label patch management. Show all posts
Showing posts with label patch management. Show all posts

Monday, January 27, 2025

50,000 Fortinet Firewalls Vulnerable to Zero-day


Everybody agrees that the organizations have to have a vulnerability management system but is that enough? Well... NO! Having a vulnerability management system without a robust patch management means to sit back and wait for the attackers compromise your systems. It will only increase your headache and pain. (Remember: Ignorance is bliss 😜 )

A zero-day exploit for Fortinet firewalls was announced in mid-January this year (2025) but it seems that too many firewall administrators are still not aware of this threat. Approximately 50,000 Fortinet boxes on the world are still exposed to that zero-day exploit. (CVE-2024-55591) (According to the reports of Shadowserver: https://bit.ly/42wNjDI)


Nearly 50,000 Fortinet firewalls remain vulnerable to a zero-day exploit (CVE-2024-55591) discovered in mid-January 2025, according to Shadowserver (https://bit.ly/42wNjDI).


While vulnerability management is essential for identifying weaknesses, it's only half the battle. Without a patch management system to deploy timely fixes, these vulnerabilities become open invitations for attackers.


If you don't want to see your organization on the internet hacker news the next day then DO have a robust vulnerability AND patch management system.


https://bit.ly/42utKMl


"Data from the Shadowserver Foundation shows 48,457 Fortinet boxes are still publicly exposed and haven't had the patch for CVE-2024-55591 applied, despite stark warnings issued over the past seven days."


"Fortinet offered some relief, however, stating that if the usual security best practices have been followed since then, the risk of compromise is small. Devices purchased after December 2022 are all also unaffected."



Tuesday, December 10, 2024

A Decade-Old Cisco ASA WebVPN Vulnerability

If your systems are still susceptible to a decade-old vulnerability, it's clear that your vulnerability or patch management systems are not functioning effectively, or perhaps both.

This is not a hypothetical situation, but a real-world occurrence. Actually it's no surprise, as many organizations still lack a proper vulnerability management system. The worst part is, some of them are unaware of the risks involved with not having a vulnerability management system.


https://bit.ly/3Vxf5vr


"Cisco on Monday (2 Dec 2024) updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).


The vulnerability, tracked as CVE-2014-2120 (CVSS score: 4.3), concerns a case of insufficient input validation in ASA's WebVPN login page that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a targeted user of the appliance."


"The development comes shortly after cybersecurity firm CloudSEK revealed that the threat actors behind AndroxGh0st are leveraging an extensive list of security vulnerabilities in various internet-facing applications, including CVE-2014-2120, to propagate the malware."

Wednesday, April 3, 2024

About 17,000 Unpatched Microsoft Exchange Servers in Germany

If you are living in Germany and administering some Exchange Servers then you can begin to worry.

The German Fededal Office for Information Security (Bundesamt für Sicherheit in der Informationtechnik - BSI) has identified a critical security concern about the poor state of Microsoft Exchange server patching in the country.


Of these servers in Germany, 12% are running a version which is no longer supported (such as Exchange 2010 or 2013) and around 25% are running Exchange 2016 or 2019 without vital patches. This means that at least 37% of Microsoft Exchange Servers in Germany are vulnerable to cyber attacks.


And this case shows us how vital are vulnerability and patch management systems for a company.


https://bit.ly/3THFk0K


"The government regulator says there are 17,000 or more Exchange Server instances in Germany vulnerable to at least one critical vulnerability, out of around 45,000 public-facing servers in the Euro nation running the software."


"Of particular concern is fixing CVE-2024-21410, an elevation-of-privilege vulnerability that Microsoft patched last month. According to German investigators, it's not clear whether as much as 48 percent or so of the country's Exchange servers have fixed up this hole yet, and Microsoft did warn it's a trickier-than-normal update to apply."


"We're told BSI is now emailing network providers on a daily basis reminding them to shore up any vulnerable system it detects. It warns that criminals are already on the lookout to exploit these reported flaws and 'schools and universities, clinics, doctors' practices, nursing services and other medical facilities, lawyers and tax advisors, local governments and many medium-sized companies are particularly affected.'"


Wednesday, February 14, 2024

Chinese Hackers Infect Dutch Military Network


 

Why do you have to have to a solid vulnerability and patch management processes?

Well? The answer is quite easy: To avoid being hacked.


A part of Dutch military network was hacked by Chinese hackers using a FortiGate firewall vulnerability which was first detected in October 2022. (CVE-2022-42475 FortiOS SSL-VPN) The damage was limited due to the network segmantation in the network design.


https://bit.ly/3uwhqN7


"A Chinese cyber-espionage group breached the Dutch Ministry of Defence last year and deployed malware on compromised devices, according to the Military Intelligence and Security Service (MIVD) of the Netherlands."


"During the follow-up investigation, a previously unknown malware strain named Coathanger, a remote access trojan (RAT) designed to infect Fortigate network security appliances, was also discovered on the breached network."


"Even fully patched FortiGate devices may therefore be infected, if they were compromised before the latest patch was applied.


The malware operates stealthily and persistently, hiding itself by intercepting system calls to avoid revealing its presence. It also persists through system reboots and firmware upgrades."


"While the attacks weren't attributed to a specific threat group, MIVD linked this incident with high confidence to a Chinese state-sponsored hacking group and added that this malicious activity is part of a broader pattern of Chinese political espionage targeting the Netherlands and its allies."


"'For the first time, the MIVD has chosen to make public a technical report on the working methods of Chinese hackers. It is important to attribute such espionage activities by China,' said Defense Minister Kajsa Ollongren."