Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » CISA urges agencies to fix critical weaknesses in array networks amid active attacks
Global Security

CISA urges agencies to fix critical weaknesses in array networks amid active attacks

AdminBy AdminNovember 26, 2024No Comments2 Mins Read
Active Attacks
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 26, 2024Ravi LakshmananVulnerability / Network Security

Active attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added A critical security flaw affecting Array Networks AG and vxAG Secure Access Gateways is now fixed for known vulnerabilities (KEV) catalog after reports of active exploitation in the wild.

Vulnerability, tracked as CVE-2023-28461 (CVSS Score: 9.8) deals with a case of no authentication that can be used to execute arbitrary code remotely. The fixes for the security flaw (version 9.4.0.484) were released by the networking equipment vendor in March 2023.

Cyber ​​security

“The Array AG/vxAG remote code execution vulnerability is a web security vulnerability that could allow an attacker to browse the file system or execute remote code on an SSL VPN gateway by using the flags attribute in an unauthenticated HTTP header,” Array Networks said. “The product can be exploited via a vulnerable URL.”

KEV’s listing came shortly after Trend Micro’s cybersecurity campaign revealed that a China-linked cyberespionage group called Earth Kasha (aka MirrorFace) is exploiting security flaws in publicly available enterprise products such as Array AG (CVE-2023-28461), Proself (CVE-2023-45727), and Fortinet FortiOS/FortiProxy (CVE -2023-27997), for initial access.

Earth Kasha is known for its extensive targeting of Japanese organizations, although recent years have also seen attacks on Taiwan, India and Europe.

Earlier this month also ESET opened by Earth Kasha, which targeted an unnamed diplomatic entity in the European Union to create a backdoor known as ANEL, using it as bait for the upcoming World Expo 2025 to be held in Osaka, Japan from April 2025.

Due to active exploitation, the Federal Civil Enforcement Agency (FCEB) is advised to apply patches by December 16, 2024 to protect their networks.

Cyber ​​security

The disclosure comes after 15 different Chinese hacker groups out of a total of 60 named threat actors were linked to the abuse of at least one of top 15 commonly used vulnerabilities in 2023according to VulnCheck.

The cybersecurity company said it has identified more than 440,000 hosts that may be vulnerable to attacks.

“Organizations must assess the impact of these technologies, improve visibility of potential risks, use robust threat intelligence, maintain robust patch management practices, and implement controls such as minimizing the exposure of these devices to the Internet where possible,” Patrick Garrity of VulnCheck. said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.