- Cisco has disclosed a high-severity flaw (CVE-2023-20185) in its data center switching gear that could allow threat actors to read and modify encrypted traffic.
- The vulnerability affects the Application Centric Infrastructure (ACI) Multisite CloudSec encryption on Cisco Nexus 9000 series fabric switches.
- There are no patches available yet for this vulnerability. Cisco advises customers using the affected switches to disable the CloudSec encryption feature.
- An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption.
The vulnerability, tracked as CVE-2023-20185, affects the Application Centric Infrastructure (ACI) Multisite CloudSec encryption on Cisco Nexus 9000 series fabric switches.
This flaw allows threat actors to read and modify encrypted traffic, posing a significant risk to data confidentiality and integrity. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption.
What makes this situation more concerning is that there are currently no patches available for this vulnerability. Cisco has advised customers using the affected switches to disable the CloudSec encryption feature and to contact their support organization to evaluate alternative options.
- Cybersecurity agencies warn of new TrueBot malware variants targeting companies in the US and Canada, exploiting a critical vulnerability (CVE-2022-31199) in the Netwrix Auditor server.
- TrueBot malware, linked with cybercriminal collectives Silence and FIN11, is deployed to extract data and disseminate ransomware, jeopardizing numerous infiltrated networks.
- The malware gains initial access by exploiting the cited vulnerability, then installs TrueBot and the FlawedGrace remote access trojan (RAT) to escalate privileges and establish persistence.
- The shift to exploiting the CVE-2022-31199 vulnerability for initial access allows cyber threat actors to carry out attacks on a broader scale within infiltrated environments.
The TrueBot malware, linked with cybercriminal collectives Silence and FIN11, has evolved to pose a significant threat to cybersecurity. The malware targets companies in the US and Canada, exploiting a critical vulnerability (CVE-2022-31199) in the widely used Netwrix Auditor server. Once the vulnerability is exploited, TrueBot and the FlawedGrace remote access trojan (RAT) are installed to escalate privileges, establish persistence, and conduct additional operations.
The shift in delivery vector, from primarily malicious email attachments to exploiting the CVE-2022-31199 vulnerability, allows cyber threat actors to carry out attacks on a broader scale within infiltrated environments. This strategic shift underscores the evolving nature of cyber threats and the need for continuous vigilance and robust security measures.
The US government and other cybersecurity agencies have issued advisories and recommended mitigations, including applying patches to the Netwrix Auditor remote code execution flaw. Organizations are urged to implement these measures to reduce the likelihood and impact of TrueBot activity and other ransomware-related incidents.
- France's parliament has approved a new clause in the justice reform bill that allows police to remotely activate cameras and microphones in internet-connected devices to surveil suspects.
- The law applies to suspects involved in crimes punishable by a minimum of five years in jail.
- Critics argue that this law transforms digital tools into police auxiliaries, posing a serious problem in societies.
- The law comes amidst ongoing protests in France, raising concerns about its timing and potential misuse.
The newly passed French law marks a significant shift in the landscape of digital surveillance. It allows police to remotely access cameras, microphones, and GPS on suspects' devices, including phones, laptops, and cars. This law applies to suspects involved in crimes punishable by a minimum of five years in jail, and it requires judge approval for any surveillance, limiting the duration to six months.
However, critics argue that this law effectively transforms personal digital tools into police auxiliaries, raising serious privacy concerns. The law comes amidst ongoing protests in France, further fueling concerns about its potential misuse.
Sign up for Mandos Way
Join Mandos Way for tips and strategies to make security your business accelerator. Receive weekly cybersecurity briefs for you and your team.
No spam. Unsubscribe anytime.