• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
  • Home
  • Review
    Coinbase’s earnings fall short of expectations as crypto winter rages – TechCrunch

    Coinbase’s earnings fall short of expectations as crypto winter rages – TechCrunch

    China’s secretive space plane flies higher and longer than before

    China’s secretive space plane flies higher and longer than before

    Parallels Desktop 18 for Mac adds ProMotion support

    Parallels Desktop 18 for Mac adds ProMotion support

    Businesses including Stitch Fix are already experimenting with DALL-E 2 – TechCrunch

    Businesses including Stitch Fix are already experimenting with DALL-E 2 – TechCrunch

    Retention platform Clevertap bags 5 million in fresh funding – TechCrunch

    Retention platform Clevertap bags $105 million in fresh funding – TechCrunch

    Architectural bug in some Intel CPUs is more bad news for SGX users

    Architectural bug in some Intel CPUs is more bad news for SGX users

  • Gaming
    Prey is a different beast than most recent franchise blockbusters

    Prey is a different beast than most recent franchise blockbusters

    Simpsons Season 34 Will Feature An Anime Parody Of Death Note

    Simpsons Season 34 Will Feature An Anime Parody Of Death Note

    Shonen Jump Newcomer Akane-banashi Is A Brilliant New Manga

    Shonen Jump Newcomer Akane-banashi Is A Brilliant New Manga

    Pokémon: The Arceus Chronicles Premiers At The UK World Championships

    Pokémon: The Arceus Chronicles Premiers At The UK World Championships

    Throw the Wildest Milkshake Keg Party Today in Two Point Campus

    Throw the Wildest Milkshake Keg Party Today in Two Point Campus

    Gotham Knights: Designing Mr. Freeze, and Giving Him a Gang to Play With – IGN First

    Gotham Knights: Designing Mr. Freeze, and Giving Him a Gang to Play With – IGN First

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Beatport Announces Inaugural ReConnect Summit

    Beatport Announces Inaugural ReConnect Summit

    5 tips to improve your bird photography

    5 tips to improve your bird photography

    WhatsApp working on screenshot blocking for View Once messages

    WhatsApp working on screenshot blocking for View Once messages

    Jiggle Physics 138: Cultured Swine

    Jiggle Physics 138: Cultured Swine

    Beatport ReConnect Summit announces headline speakers Deadmau5, Eris Drew, Kerri Chandler, Richie Hawtin and more

    Beatport ReConnect Summit announces headline speakers Deadmau5, Eris Drew, Kerri Chandler, Richie Hawtin and more

    Google Nest Hub is currently selling for just

    Google Nest Hub is currently selling for just $55

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    NVIDIA’s Preliminary Earnings Are Not Pretty

    NVIDIA’s Preliminary Earnings Are Not Pretty

    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

  • Applications
    How The House of Da Vinci 3 is the Perfect Sequel

    How The House of Da Vinci 3 is the Perfect Sequel

    How to access Netflix games on iPhone and iPad

    How to access Netflix games on iPhone and iPad

    Best cases for MacBook Air with M2 in 2022

    Best cases for MacBook Air with M2 in 2022

    1Password 8 Arrives for iOS Devices With a Customizable Home Screen and More

    1Password 8 Arrives for iOS Devices With a Customizable Home Screen and More

    WhatsApp’s next update finally adds top-requested feature

    WhatsApp’s next update finally adds top-requested feature

    Snapchat launches family control portal, new features incoming

    Snapchat launches family control portal, new features incoming

  • Security
    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Cybrary Unveils Next-Generation Interactive, Hands-On Training Experience to Upskill Cybersecurity Professionals

    Cybrary Unveils Next-Generation Interactive, Hands-On Training Experience to Upskill Cybersecurity Professionals

    Researchers Debut Fresh RCE Vector for Common Google API Tool

    Researchers Debut Fresh RCE Vector for Common Google API Tool

    Abusing Kerberos for Local Privilege Escalation

    Abusing Kerberos for Local Privilege Escalation

    New Malicious Python Libraries Found on PyPI Repository

    New Malicious Python Libraries Found on PyPI Repository

No Result
View All Result
  • Home
  • Review
    Coinbase’s earnings fall short of expectations as crypto winter rages – TechCrunch

    Coinbase’s earnings fall short of expectations as crypto winter rages – TechCrunch

    China’s secretive space plane flies higher and longer than before

    China’s secretive space plane flies higher and longer than before

    Parallels Desktop 18 for Mac adds ProMotion support

    Parallels Desktop 18 for Mac adds ProMotion support

    Businesses including Stitch Fix are already experimenting with DALL-E 2 – TechCrunch

    Businesses including Stitch Fix are already experimenting with DALL-E 2 – TechCrunch

    Retention platform Clevertap bags 5 million in fresh funding – TechCrunch

    Retention platform Clevertap bags $105 million in fresh funding – TechCrunch

    Architectural bug in some Intel CPUs is more bad news for SGX users

    Architectural bug in some Intel CPUs is more bad news for SGX users

  • Gaming
    Prey is a different beast than most recent franchise blockbusters

    Prey is a different beast than most recent franchise blockbusters

    Simpsons Season 34 Will Feature An Anime Parody Of Death Note

    Simpsons Season 34 Will Feature An Anime Parody Of Death Note

    Shonen Jump Newcomer Akane-banashi Is A Brilliant New Manga

    Shonen Jump Newcomer Akane-banashi Is A Brilliant New Manga

    Pokémon: The Arceus Chronicles Premiers At The UK World Championships

    Pokémon: The Arceus Chronicles Premiers At The UK World Championships

    Throw the Wildest Milkshake Keg Party Today in Two Point Campus

    Throw the Wildest Milkshake Keg Party Today in Two Point Campus

    Gotham Knights: Designing Mr. Freeze, and Giving Him a Gang to Play With – IGN First

    Gotham Knights: Designing Mr. Freeze, and Giving Him a Gang to Play With – IGN First

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Beatport Announces Inaugural ReConnect Summit

    Beatport Announces Inaugural ReConnect Summit

    5 tips to improve your bird photography

    5 tips to improve your bird photography

    WhatsApp working on screenshot blocking for View Once messages

    WhatsApp working on screenshot blocking for View Once messages

    Jiggle Physics 138: Cultured Swine

    Jiggle Physics 138: Cultured Swine

    Beatport ReConnect Summit announces headline speakers Deadmau5, Eris Drew, Kerri Chandler, Richie Hawtin and more

    Beatport ReConnect Summit announces headline speakers Deadmau5, Eris Drew, Kerri Chandler, Richie Hawtin and more

    Google Nest Hub is currently selling for just

    Google Nest Hub is currently selling for just $55

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    AORUS Z690i Ultra Plus, Now With Less WHEA Errors

    NVIDIA’s Preliminary Earnings Are Not Pretty

    NVIDIA’s Preliminary Earnings Are Not Pretty

    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

  • Applications
    How The House of Da Vinci 3 is the Perfect Sequel

    How The House of Da Vinci 3 is the Perfect Sequel

    How to access Netflix games on iPhone and iPad

    How to access Netflix games on iPhone and iPad

    Best cases for MacBook Air with M2 in 2022

    Best cases for MacBook Air with M2 in 2022

    1Password 8 Arrives for iOS Devices With a Customizable Home Screen and More

    1Password 8 Arrives for iOS Devices With a Customizable Home Screen and More

    WhatsApp’s next update finally adds top-requested feature

    WhatsApp’s next update finally adds top-requested feature

    Snapchat launches family control portal, new features incoming

    Snapchat launches family control portal, new features incoming

  • Security
    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Microsoft Patches Zero-Day Actively Exploited in the Wild

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Halo Security Emerges From Stealth With Full Attack Surface Management Platform

    Cybrary Unveils Next-Generation Interactive, Hands-On Training Experience to Upskill Cybersecurity Professionals

    Cybrary Unveils Next-Generation Interactive, Hands-On Training Experience to Upskill Cybersecurity Professionals

    Researchers Debut Fresh RCE Vector for Common Google API Tool

    Researchers Debut Fresh RCE Vector for Common Google API Tool

    Abusing Kerberos for Local Privilege Escalation

    Abusing Kerberos for Local Privilege Escalation

    New Malicious Python Libraries Found on PyPI Repository

    New Malicious Python Libraries Found on PyPI Repository

No Result
View All Result
No Result
View All Result
Home Applications

Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

RealHacker Staff by RealHacker Staff
June 24, 2022
Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack
Share on FacebookShare on Twitter


A suspected ransomware intrusion against an unnamed target leveraged a Mitel VoIP appliance as an entry point to achieve remote code execution and gain initial access to the environment.

The findings come from cybersecurity firm CrowdStrike, which traced the source of the attack to a Linux-based Mitel VoIP device sitting on the network perimeter, while also identifying a previously unknown exploit as well as a couple of anti-forensic measures adopted by the actor on the device to erase traces of their actions.

The exploit in question is tracked as CVE-2022-29499 and was fixed by Mitel in April 2022. It’s rated 9.8 out of 10 for severity on the CVSS vulnerability scoring system, making it a critical shortcoming.

“A vulnerability has been identified in the Mitel Service Appliance component of MiVoice Connect (Mitel Service Appliances – SA 100, SA 400, and Virtual SA) which could allow a malicious actor to perform remote code execution (CVE-2022-29499) within the context of the Service Appliance,” the company noted in an advisory.

The exploit entailed two HTTP GET requests — which are used to retrieve a specific resource from a server — to trigger remote code execution by fetching rogue commands from the attacker-controlled infrastructure.

In the incident investigated by CrowdStrike, the attacker is said to have used the exploit to create a reverse shell, utilizing it to launch a web shell (“pdf_import.php”) on the VoIP appliance and download the open source Chisel proxy tool.

The binary was then executed, but only after renaming it to “memdump” in an attempt to fly under the radar and use the utility as a “reverse proxy to allow the threat actor to pivot further into the environment via the VOIP device.” But subsequent detection of the activity halted their progress and prevented them from moving laterally across the network.

CyberSecurity

The disclosure arrives less than two weeks after German penetration testing firm SySS revealed two flaws in Mitel 6800/6900 desk phones (CVE-2022-29854 and CVE-2022-29855) that, if successfully exploited, could allow an attacker to gain root privileges on the devices.

“Timely patching is critical to protect perimeter devices. However, when threat actors exploit an undocumented vulnerability, timely patching becomes irrelevant,” CrowdStrike researcher Patrick Bennett said.

“Critical assets should be isolated from perimeter devices to the extent possible. Ideally, if a threat actor compromises a perimeter device, it should not be possible to access critical assets via ‘one hop’ from the compromised device.”





Source link

Related

Continue Reading
Tags: AttackExploitHackersMitelRansomwareVoIPZeroDay
RealHacker Staff

RealHacker Staff

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

How The House of Da Vinci 3 is the Perfect Sequel

How The House of Da Vinci 3 is the Perfect Sequel

August 9, 2022
Prey is a different beast than most recent franchise blockbusters

Prey is a different beast than most recent franchise blockbusters

August 9, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Gaming
  • Gear
  • Computers
  • Applications
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!