Tag: Tenable

Comment from Tenable: Apple patches zero-day flaws

Apple recently patched several vulnerabilities across its lineup of software and operating systems. Included in these patches were fixes for two zero-day vulnerabilities that have been exploited in the wild. Please find below a comment from Satnam Narang, Staff Research Engineer, Tenable.

“Apple patched CVE-2021-30661, a vulnerability in its WebKit Storage component used in its browser engine. The vulnerability exists across its desktop operating system (macOS Big Sur) as well as its mobile devices such as iPhone (iOS), iPad (iPadOS), Apple Watch (watchOS) and its operating system for Apple TV, tvOS. Apple says that an attacker could gain arbitrary code execution when processing maliciously crafted web content. Apple said they’re aware of reports this flaw has been actively exploited in the wild.

“In addition to CVE-2021-30661, Apple also patched CVE-2021-30657, a logic issue in its System Preferences. The vulnerability would allow an attacker to bypass Apple’s Gatekeeper, which is supposed to prevent untrusted software from running on macOS. As an example, Security researcher Patrick Wardle, who wrote about the flaw, created a proof-of-concept of a resume PDF file that, when opened, will launch the system’s Calculator application, a popular benign tactic used to show successful exploitation.

“Researchers at Jamf also documented the in-the-wild exploitation of CVE-2021-30657 by operators of the Shlayer macOS malware. The group has been known to spread their malware through poisoned search results that lead to fake downloads of Adobe Flash Player.

“Users of Apple devices, from laptops to mobile devices should regularly update to the latest version to protect themselves against threats like the ones patched recently.” – Satnam Narang, Staff Research Engineer, Tenable

Tenable Completes Acquisition Of Alsid And Launches Tenable.Ad To Secure Active Directory Environments

April 28, 2021, India — Tenable Holdings, Inc. (“Tenable”) (Nasdaq: TENB), the Cyber Exposure company, today announced that it completed the acquisition of Alsid SAS (“Alsid”), a leader in securing Active Directory, on April 26, 2021. The acquisition combines the complementary strengths of two cybersecurity innovators and marks an important milestone in Tenable’s vision to help organizations understand and reduce cyber risk across the entire attack surface. Today, Tenable also announced the availability of Tenable.ad, a new solution leveraging Alsid technology to secure Active Directory environments and disrupt one of the most common attack paths in both advanced persistent threats and common hacks.

Active Directory is used by 90 percent of Fortune 1000 organizations as their primary method for authentication and authorization, according to Frost & Sullivan. Its ubiquity makes Active Directory a favored attack vector for bad actors who use its misconfigurations to move laterally across systems and escalate privileges. This risk has never been more acute than it is today, with so many people working remotely and often using personal devices to connect to corporate systems. Active Directory plays a critical role in managed single sign-on and the level of access users are granted once authenticated.

“Active Directory is commonly targeted in attacks and is often the first thing bad actors go after when they gain access. Understanding your Active Directory security posture is a strategic and important complement to vulnerability management and is imperative to managing risk, especially in complex cloud and hybrid environments,” said Amit Yoran, chairman and CEO, Tenable. “We are delighted to welcome the Alsid team to Tenable and to offer Tenable.ad to our customers so we can help them focus on the security challenges that pose the greatest risk to their business.”

With Alsid’s deep expertise in securing Active Directory, Tenable is adding a new and innovative approach to disrupting cyberattacks. Tenable’s industry-leading risk-based vulnerability management solutions enable organizations to predict which vulnerabilities an attacker could leverage to gain an initial foothold. From there, Tenable.ad enables users to find and fix existing weaknesses and detects ongoing attacks in real time without the need to deploy agents or use privileged accounts. Tenable.ad, now generally available, is a Software as a Service (SaaS) solution with an on-premises deployment option. Existing Alsid SaaS customers have the option of upgrading to Tenable.ad immediately. Learn more about Tenable.ad.

“Today Alsid joins forces with Tenable. We share a singular vision to help our customers with a more holistic approach to foundational cybersecurity that includes powerfully effective solutions to prevent and detect Active Directory-focused attacks,” said Emmanuel Gras, CEO and co-founder, Alsid. “While this milestone is important validation, we’re even more excited about the opportunities ahead of us as we integrate capabilities and expand into new markets globally.”

Under the terms of the agreement, Tenable acquired Alsid for a total purchase price of approximately $98 million in cash, subject to customary purchase price adjustments.

For more information about the announcement, visit the Investor FAQ page. Tenable also shares news and updates on its Investor Relations website at investors.tenable.com, which may be of interest or material to Tenable investors.

About Tenable
Tenable® is the Cyber Exposure company. Over 30,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. As the creator of Nessus®, Tenable extended its expertise in vulnerabilities to deliver the world’s first platform to see and secure any digital asset on any computing platform. Tenable customers include more than 50 percent of the Fortune 500, more than 30 percent of the Global 2000 and large government agencies. Learn more at www.tenable.com.

Comment from Tenable: Zero-Day Vuln in Pulse Connect Secure Exploited in the Wild

Threat actors are leveraging a zero-day vulnerability in Pulse Connect Secure (PCS), for which there is no immediate patch scheduled for release. Attackers also appear to be leveraging three previously known and patched vulnerabilities in PCS from 2019 and 2020. Please find below a comment from Scott Caveza, Research Engineering Manager, Tenable and a full analysis from Tenable here.

“CVE-2021-22893 is a critical authentication bypass zero-day vulnerability that gives attackers an entry point into Pulse Connect Secure (PCS) SSL VPN appliances. In addition to CVE-2021-22893, attackers also appear to be leveraging three previously known and patched vulnerabilities in PCS from 2019 and 2020: CVE-2019-11510, CVE-2020-8243 and CVE-2020-8260. CVE-2019-11510, which has been exploited in the wild since details became public in August 2019, was one of the Top 5 vulnerabilities in Tenable’s 2020 Threat Landscape Retrospective report because of its ease of exploitation and widespread exploitation.

“Because it is a zero-day and the timetable for the release of a patch is not yet known, CVE-2021-22893 gives attackers a valuable tool to gain entry into a key resource used by many organizations, especially in the wake of the shift to the remote workforce over the last year. Attackers can utilize this flaw to further compromise the PCS device, implant backdoors and compromise credentials. While Pulse Secure has noted that the zero-day has seen limited use in targeted attacks, it’s just a matter of time before a proof-of-concept becomes publicly available, which we anticipate will lead to widespread exploitation, as we observed with CVE-2019-11510.” — Scott Caveza, Research Engineering Manager, Tenable

Comment from Tenable – CERT-IN cautions Whatsapp users of vulnerabilities detected in the app

Earlier this week, CERT-IN – India’s cyber security agency cautioned WhatsApp users about certain vulnerabilities detected in the instant messaging app that could lead to breach of sensitive information. The vulnerability was discovered in software that has ‘WhatsApp and WhatsApp Business for Android prior to v2.21.4.18 and WhatsApp and WhatsApp Business for iOS prior to v2.21.32.’ Please find below a comment from Satnam Narang, Staff Research Engineer, Tenable.

“With over two billion users, WhatsApp is one of the most popular messaging platforms around the world. Therefore, the discovery of vulnerabilities within the WhatsApp application for Android and iOS devices could be significant. Earlier this month, two flaws were patched in WhatsApp for Android and iOS. To exploit these flaws in apps like WhatsApp, more often than not, an attacker would need to socially engineer the victim into clicking on a link to visit a website.

“Whenever WhatsApp releases new versions of its software, it is important for end-users to ensure updates are applied, either automatically or by checking for updates. This can help address any known vulnerabilities within the application.

“With respect to the supposed WhatsApp Pink release, it appears that cybercriminals are circulating a fake copy of WhatsApp for Android that apparently changes the colour of the app logo and the app iconography and theme to pink. Installing apps from outside the Google Play Store is a risky proposition, so we strongly encourage users to be cautious and not install apps from outside the official Google Play Store.” — Satnam Narang, Staff Research Engineer, Tenable

Comment from Tenable: Second zero-day in Google Chrome

For the second time in a week, a researcher has published a proof-of-concept (PoC) exploit for a zero-day vulnerability in Google Chrome. Earlier this week, a researcher published a PoC for a 1-day vulnerability in the V8 JavaScript engine used by Google Chrome and Microsoft Edge (Chromium). Please find below, a comment from Satnam Narang, Staff Research Engineer, Tenable.

“What makes both of these publicly disclosed vulnerabilities similar is that they are of limited value by themselves. In this case, it takes two to tango, which means they require a separate vulnerability to break out of the Chrome sandbox. Once again, this latest vulnerability is also mitigated by the fact that it is not paired with a flaw to escape the sandbox.

“Therefore, an attacker cannot compromise the underlying operating system or access confidential information without combining this vulnerability with a second vulnerability to escape the sandbox.

“Zero-days may garner most of the attention, but known yet unpatched vulnerabilities enable most breaches and have become favoured by advanced attackers. Yesterday, the National Security Agency (NSA) released a joint cybersecurity advisory with the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), highlighting a series of known vulnerabilities allegedly used by Russian Foreign Intelligence Services.

“Despite the limited impact from the public disclosure of another Google Chrome vulnerability, we continue to encourage users and organisations alike to ensure they are patching their browsers like Chrome and Edge as soon as possible.”– Satnam Narang, Staff Research Engineer, Tenable

Comment from Tenable: Proof-of-Concept for Google Chrome/Microsoft Edge 1-Day

A 1-day vulnerability in the V8 JavaScript engine used by Google Chrome and Microsoft Edge (Chromium) has come to light on social media. It appears to be the same flaw that was reported during the Pwn2Own contest held earlier this month. The known vulnerability has been patched in the V8 engine, but yet to be patched in both Chrome and Edge. Please find below a comment from Satnam Narang, Staff Research Engineer, Tenable.

“There are reports of a 1-day vulnerability in the V8 JavaScript engine used by Google Chrome and Microsoft Edge (Chromium). This vulnerability was disclosed on social media on April 12, but appears to be the same flaw that was reported during the Pwn2Own contest held earlier this month. The known vulnerability has been patched in the V8 engine, but yet to be patched in both Chrome and Edge.

“While it is concerning that details about a vulnerability in popular web browsers has been publicly disclosed, the cause for concern dissipates when you consider that the vulnerability by itself cannot escape Google’s sandbox. This means that an attacker could not compromise the underlying operating system or access confidential information. It’s sort of like clapping your hands; you can’t truly clap with just one hand, you need both. Similarly, in this instance, an attacker would need to chain this V8 vulnerability with a second vulnerability to escape the sandbox.

“Despite that, we strongly encourage users and organizations alike to ensure they are patching their browsers like Chrome and Edge as soon as possible, as unpatched browsers and systems are ripe targets for cybercriminals and advanced persistent threat groups.”– Satnam Narang, Staff Research Engineer, Tenable

Patch Wednesday- Four Critical Microsoft Exchange Server Vulnerabilities Patched in April

This month’s Patch Wednesday release addressed 108 CVEs, 19 of which are rated critical. This is the first time in 2021 that Microsoft patched over 100 CVEs. They’ve addressed 329 CVEs so far in 2021. Following last month’s out-of-band update addressing four critical zero-days in Microsoft Exchange Server that were exploited in the wild, including ProxyLogon, Microsoft patched four more critical Exchange Server vulnerabilities this month: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483. All four are credited to the National Security Agency, with two also being discovered by Microsoft internally. Here’s a comment from Satnam Narang, Staff Research Engineer, Tenable.

“These vulnerabilities have been rated “Exploitation More Likely” using Microsoft’s Exploitability Index. Two of the four vulnerabilities (CVE-2021-28480, CVE-2021-28481) are pre-authentication, meaning an attacker does not need to authenticate to the vulnerable Exchange server to exploit the flaw. With the intense interest in Exchange Server since last month, it is crucial that organisations apply these Exchange Server patches immediately. Microsoft also patched CVE-2021-28310, a Win32k Elevation of Privilege vulnerability that was exploited in the wild as a zero-day.

“Exploitation of this vulnerability would give the attacker elevated privileges on the vulnerable system. This would allow an attacker to execute arbitrary code, create new accounts with full privileges, access and/or delete data and install programs. Elevation of Privilege vulnerabilities are leveraged by attackers post-compromise, once they’ve managed to gain access to a system in order to execute code on their target systems with elevated privileges.” — Satnam Narang, Staff Research Engineer, Tenable

Comment on vulnerabilities in VMware’s vRealize Operations

“The most severe flaw, CVE-2021-21975, is a server-side request forgery (SSRF) vulnerability in the vROPs Manager API. An unauthenticated, remote attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable vROPs Manager API endpoint. Successful exploitation would result in the attacker obtaining administrative credentials.

“VMware also patched CVE-2021-21983, an arbitrary file write vulnerability in the VROPs Manager API, which can be used to write files to the underlying operating system. This vulnerability is post-authentication, meaning an attacker needs to be authenticated with administrative credentials in order to exploit this flaw.

“While on their own, these vulnerabilities may not seem as severe as CVE-2021-21972, a remote code execution vulnerability in VMware’s vCenter Server that was patched in February. However, if attackers chain both CVE-2021-21975 and CVE-2021-21983 together, they could also gain remote code execution privileges.

“VMware has provided patches for both flaws across vROPs Manager versions 7.5.0 through 8.3.0. They’ve also provided a temporary workaround to prevent attackers from exploiting these flaws. The workaround should only be used as a temporary stop-gap until organizations are able to plan for applying the patches.” — Satnam Narang, Staff Research Engineer, Tenable

Comment on Clubhouse App: Tenable

Clubhouse, an invite-only app available on iOS is seemingly the next big thing in social media for casual, drop-in audio conversations with anyone or sometimes even celebrities. As of Feb 2021, the app had 8 million downloads. Just as apps offer opportunities to learn and connect with others, they can also be breeding grounds for scammers. Satnam Narang, Staff Research Engineer at Tenable who has done extensive research into scams on social media platforms such as TikTok, Instagram and Cash App, offers his comments on the challenges and opportunities Clubhouse might present to scammers.

“In February 2021, Clubhouse topped 8 million global downloads for its invite-only voice-based social media app that is currently only available on iOS devices. Historically, I’ve found that when an app surges in popularity with users, scammers quickly take notice and find their own niche around them, whether it’s Facebook, Twitter, Instagram, Snapchat, Tinder or TikTok. There are a few challenges that Clubhouse presents to scammers as well as opportunities.

“For instance, because the app is voice-driven, there is no way to chat with users in order to peddle links to scams, which is often a scammer’s preferred method. Clubhouse does allow users to promote social profiles for Instagram and Twitter, which is the most likely way users will be driven to scams. I saw this in my TikTok research a few years ago, when scammers were promoting adult dating scams, they would ask the users to add them on Snapchat in order to take them off the platform.

“There have been reports that Clubhouse rooms have been created to promote get-rich quick schemes or fake coaching offers. They drive users off Clubhouse to social profiles created to promote these so-called opportunities. These benign profiles aren’t likely to get removed until after users have parted ways with their money, making this type of scam extremely lucrative.

“There is also an impersonation problem that faces other platforms and has already started to emerge on Clubhouse. After Elon Musk joined Clubhouse, a few fake Elon Musk profiles appeared on the platform. There are reports of other notable figures who aren’t actually on Clubhouse, but have been told by their fans that they were in a room with them. I expect this to continue until Clubhouse starts incorporating some sort of verification mechanism within the platform for these notable figures.

“The Clubhouse app itself is undoubtedly being examined by security researchers for flaws. We’ve already seen reports that users have been able to snoop on audio from Clubhouse rooms and create unofficial Android versions of the app until an official one is released.

“Unofficial versions of Clubhouse for Android is another area that is ripe for abuse. With the ability to sideload applications on Android devices, cybercriminals can create fake versions of Clubhouse that perform malicious actions on the users’ devices and potentially lead to financial harm.”—Satnam Narang, Staff Research Engineer, Tenable

Comment on Vulnerabilities in F5 BIG-IP and BIG-IQ from Tenable

“F5 recently addressed several vulnerabilities in its BIG-IP and BIG-IQ, of which four were rated critical. The most severe of these critical vulnerabilities is CVE-2021-22986, an unauthenticated remote command execution flaw in the iControl REST interface. It received a CVSSv3 score of 9.8 out of 10, making it one of the most severe flaws patched today. Successful exploitation of this flaw could lead to full system compromise.

As we saw last summer when F5 patched CVE-2020-5902, another critical vulnerability in BIG-IP, attackers quickly latch onto such flaws and begin scanning for and targeting vulnerable F5 devices that are publicly accessible. We expect history to repeat itself for CVE-2021-22986 in the coming days and weeks, especially once a proof-of-concept becomes publicly available. It’s imperative for organizations to update to a patched version immediately.” – Satnam Narang, Staff Research Engineer, Tenable.