Ukrainian hacktivists deleted 2 petabytes of data from Russian research center
Ukrainian hacktivists deleted 2 petabytes of data from Russian research center#### Welcome to Security Sunday, your weekly round-up of cybersecurity news.

Ukrainian hacktivists deleted 2 petabytes of data from Russian research center
Pro-Ukrainian hacktivists infiltrated a Russian space hydrometeorology center called Planeta and deleted 2 petabytes of data, according to the Main Intelligence Directorate of the Ukrainian Defense Ministry.
Planeta is a state-run research center that uses data from space satellites and ground-based sources such as radars and stations to provide information and accurate forecasts on weather, climate, natural disasters, extreme events and volcano monitoring.
The agency is affiliated with Russia’s space agency, Roscosmos, and supports sectors such as the military, civil aviation, agriculture, and maritime transport.
While the Ukrainian government has not said whether it was involved in the attack, it says hackers destroyed 280 servers used by the research center, which contained 2 petabytes (2,000 terabytes) of data.
The Ukrainian intelligence service says the damage caused by the loss of data is estimated at $10,000,000, affecting the operation of the supercomputer clusters as well as years of research.
Critical Jenkins vulnerability exposes servers to RCE attacks
The maintainers of the open source Jenkins automation software have patched nine security vulnerabilities, including a critical bug that could lead to remote code execution (RCE) if successfully exploited.
The bug, tracked as CVE-2024–23897, has been described as an arbitrary file reading vulnerability via the built-in command-line interface (CLI).
“Jenkins uses the args4j library to parse arguments and command options on the Jenkins controller when processing CLI commands,” administrators said in a document released Wednesday.
“This command parser has a feature that replaces the @ character followed by the file path in the argument with the contents of the file (expandAtFiles). This feature is enabled by default and is not disabled in Jenkins 2.441 and earlier, LTS 2.426.2 and earlier.”
An attacker could exploit this vulnerability to read arbitrary files in the file system.
SonarSource security researcher Yaniv Nizry was instrumental in discovering and reporting the vulnerability on November 13, 2023, and the bug was fixed in Jenkins 2.442, LTS 2.426.3 by disabling the command parser feature.
Disabling CLI access is recommended as a short-term workaround until the fix can be applied.
Apache ActiveMQ vulnerability exploited in new Godzilla Web Shell attacks
Cybersecurity researchers are warning of a “notable increase” in activity by attackers who are actively exploiting a now-patched vulnerability in Apache ActiveMQ to deliver the Godzilla web shell to compromised hosts.
“The web shells are hidden in an unknown binary format and are designed to evade security and signature-based scanners,” Trustwave said. “Remarkably, despite the unknown binary format, the JSP ActiveMQ engine continues to compile and run the web shell.”
The web shell, dubbed Godzilla, is a feature-rich backdoor capable of parsing incoming HTTP POST requests, executing their contents, and returning the results in the form of an HTTP response.
A closer examination of the attack chain reveals that the web shell code is converted to Java code before being executed by the Jetty servlet engine.
Apache ActiveMQ users are strongly advised to upgrade to the latest version as soon as possible to mitigate potential threats.
40,000 attacks in 3 days: Critical Confluence RCE vulnerability actively exploited by attackers
The CVE-2023–22527 vulnerability, which we reported on in a previous Security Sunday episode, allows unauthenticated attackers to achieve remote code execution.
The vulnerability affects versions of Confluence Data Center and Server 8 released before December 5, 2023, as well as version 8.4.5.
According to the Shadowserver Foundation, just days after the vulnerability was made public, nearly 40,000 exploit attempts were logged on January 19, targeting more than 600 unique IP addresses.
Most of the attackers’ IP addresses were from Russia (22,674), followed by Singapore, Hong Kong, the US, China, India, Brazil, Taiwan, Japan and Ecuador.
As of January 21, 2024, more than 11,000 instances were found to be accessible over the Internet.
More than 5 300 GITLAB servers vulnerable to ZERO-CLICK ACCOUNT TAKEOVER attack
GitLab has recently released security updates that address two critical vulnerabilities affecting both the Community and Enterprise versions.
The most critical vulnerability, tracked as CVE-2023–7028 (CVSS rating 10), is an account takeover via password reset. This vulnerability can be exploited to take over an account without any user interaction.
GitLab has fixed this issue in versions 16.7.2, 16.5.6 and 16.6.4.
Tesla Hacked, 24 Zero-Days Exploited at Pwn2Own Tokyo
During the Pwn2Own Automotive 2024 hacking competition, security researchers hacked Tesla’s infotainment system and introduced 24 zero-day vulnerabilities.
The Synacktiv team took home $100,000 after linking two zero-day vulnerabilities from sandbox leaks and hacking Tesla’s infotainment system.
Synacktiv also won an additional $295,000 after gaining root on a Tesla modem and using three strings to hack into Ubiquiti Connect EV and JuiceBox 40 smart charging stations, exploiting a total of seven zero-day vulnerabilities.
The Pwn2Own Automotive 2024 hacking competition will take place during the Automotive World conference in Tokyo, Japan, January 24–26, focusing on automotive technology.
Following the Pwn2Own competition, vendors have 90 days to release security patches before TrendMicro’s Zero Day Initiative makes the vulnerabilities public.
Apple issues patch for critical zero-day vulnerability in iPhones and Macs
Apple on Monday released security updates for iOS, iPadOS, macOS, tvOS and the Safari web browser that address a zero-day vulnerability that is being actively exploited.
The issue, tracked as CVE-2024–23222, is a type modification vulnerability in the browser’s WebKit kernel that an attacker could exploit to execute arbitrary code. The tech giant said the issue has been fixed with enhanced controls.
This is the first actively exploited vulnerability that Apple has patched this year. Last year, the iPhone maker addressed 20 zero-day vulnerabilities that were being used in real-world attacks.
Critical Cisco Vulnerability Allows Hackers to Remotely Control Unified Communications Systems
Cisco has released updates to address a critical vulnerability in its Unified Communications and Contact Center Solutions products that could allow an unauthenticated remote attacker to execute arbitrary code.
The issue, tracked as CVE-2024–20253 (CVSS rating: 9.9), stems from improper handling of user-provided data that an attacker could exploit to send a specially crafted message to a listening port on the device.
“Successful exploitation could allow an attacker to execute arbitrary commands in the underlying operating system with the privileges of a Web services user,” Cisco said in an advisory. “With access to the underlying operating system, an attacker could also gain root access on the compromised device.”
Interested in cyber security? Check out the next episodes of Security Sunday.
https://medium.com/@zakpatrikcz/list/security-sunday-en-c438ddf5f168