Security Leftovers
-
Microsoft Patch Tuesday, October 2022 Edition
Microsoft today released updates to fix at least 85 security holes in its Windows operating systems and related software, including a new zero-day vulnerability in all supported versions of Windows that is being actively exploited. However, noticeably absent from this month’s Patch Tuesday are any updates to address a pair of zero-day flaws being exploited this past month in Microsoft Exchange Server.
-
iTWire - Fortinet authentication bypass flaw being exploited in the wild
An authentication bypass flaw in security firm Fortinet's products, which was patched on 6 October, is being exploited in the wild, the company has confirmed.
It said CVE-2022-40684 was an authentication bypass on the administrative interface that enables remote threat actors to log into FortiGate firewalls, FortiProxy Web proxies, and FortiSwitch Manager on-premise management instances.
The advisory issued by Fortinet said an attacker who exploited the flaw would be able to execute unauthorised code or commands.
-
iTWire - Telstra chair refuses to criticise Optus over data breach
Telstra chairman John Mullen has defended Optus over the recent major data breach, saying it was easy to be critical of another company's performance when one was not in the firing line.
Mullen told the company's AGM on Tuesday: "...may I just say that it is easy for third parties to be critical of companies who have suffered devastating cyber-attacks such as happened recently to Optus.
"Let me be blunt, however, and say that it is easy to be critical when it isn’t you in the firing line, and we should all avoid hubris because no-one can be complacent and no organisation can ever be 100% sure that it is completely protected and safe.
"The threat and sophistication of the attackers grows every day, and to address the threat business needs to put aside competitive rivalry, and work constructively across industries, with government, and with the community to protect Australia from this modern scourge."
-
Microsoft Patch Tuesday: 84 new vulnerabilities | ZDNET
This release comes on top of 12 patches for CVEs in Microsoft Edge (Chromium-based) released earlier this month.
-
Microsoft Exchange servers hacked to deploy LockBit ransomware
Microsoft is investigating reports of a new zero-day bug abused to hack Exchange servers which were later used to launch Lockbit ransomware attacks.
In at least one such incident from July 2022, the attackers used a previously deployed web shell on a compromised Exchange server to escalate privileges to Active Directory admin, steal roughly 1.3 TB of data, and encrypt network systems.
As described by South Korean cybersecurity firm AhnLab, whose forensic analysis experts were hired to help with the investigation, it took the threat actors only a week to hijack the AD admin account from when the web shell was uploaded.