Recent Security Issues


Title: Microsoft warns of “ProxyNotShell” vulnerabilities in Exchange Server

Description: Microsoft warned of two Exchange Server vulnerabilities collectively referred to as "ProxyNotShell” that had been actively exploited in the wild. One of these vulnerabilities could allow an attacker to execute remote code on the targeted server. CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, while CVE-2022-41082 enables Remote Code Execution (RCE) when PowerShell is accessible to the attackers. While no fixes or patches are available yet, Microsoft has provided mitigations for on-premises Microsoft Exchange users. Even organizations that use Exchange Online may still be affected if they run a hybrid server. Exchange vulnerabilities have become increasingly popular with threat actors, as they can provide initial access to network environments and are often used to facilitate more effective phishing and malspam campaigns.




Title: New malware builder used to deliver updated version of Agent Tesla

Description: Security researchers recently discovered a malware builder being sold on the dark web known as “Quantum Builder.” Attackers are using the new builder to deliver an updated version of the Agent Tesla trojan, which is known for stealing and spying on user interactions and keystrokes. Quantum Builder can create malicious shortcut files, and has previously been linked to the Lazarus Group APT. The attackers in this campaign send a spearphishing email to targets that contains a malicious GZIP attachment that holds a malicious shortcut to execute PowerShell code.


Security News

Researchers say that Microsoft's suggested mitigations for vulnerabilities in Exchange Server can be easily bypassed.

A hacking group with ties to North Korea has been using Trojanized open source apps to compromise media, defense and aerospace, and IT industry organizations.

A new IoT malware called “Chaos” is compromising Windows and Linux devices to build up a group of infected devices to launch distributed denial-of-service attacks.

The Witchetty espionage group is using a backdoor that leverages steganography.

Hackers have leaked more than 500 GB of data stolen during a recent ransomware attack on the Los Angeles Unified School District (LAUSD).

Attackers are using the browser-in-a-browser attack method to target users of the video game storefront Steam, aimed at stealing their login credentials using fake pop-up windows and tabs.

Vulnerabilities with Exploits


ID: CVE-2022-41040 and CVE-2022-41082

Title: Microsoft Exchange Server multiple vulnerabilities

Description: The first flaw (CVE-2022-41040) is a Server-Side Request Forgery (SSRF) vulnerability. The second flaw (CVE-2022-41082) allows remote code execution (RCE) when PowerShell is accessible to the attacker. The customers should know that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities.

CVSS v3.1 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

ID: CVE-2022-41429

Title: Heap-based overflow vulnerability in AP4_Atom::TypeFromString

Description: This issue affects the function AP4_Atom::TypeFromString of the component mp4tag. Manipulation with an unknown input may lead to a memory corruption vulnerability.

CVSS v3.1 Base Score: 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

ID: CVE-2022-41430

Title: Heap-based overflow vulnerability in Axiomatic Bento4 mp4mux ReadBit function

Description: The flaw affects the function AP4_BitReader::ReadBit of the component mp4mux. Manipulation with an unknown input may lead to a memory corruption vulnerability.

CVSS v3.1 Base Score: 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

