Tag Archive for: belatedly

Mikrotik Belatedly Patches RouterOS Flaw Exploited at Pwn2Own


Latvian network equipment manufacturer MikroTik has shipped a patch for a major security defect in its RouterOS product and confirmed the vulnerability was exploited five months ago at the Pwn2Own Toronto hacking contest.

In a barebones advisory documenting the CVE-2023-32154 flaw, Mikrotik confirmed the issue affects devices running MikroTik RouterOS versions v6.xx and v7.xx with enabled IPv6 advertisement receiver functionality. 

According to ZDI, organizers of the Pwn2Own software exploitation event, the vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. 

“Authentication is not required to exploit this vulnerability,” ZDI warned in an advisory.

“The specific flaw exists within the Router Advertisement Daemon. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root,” the company said.

The Pwn2Own organizers decided to go public with an advisory prior to the availability of patches after waiting five months for MikroTik to acknowledge and fix the already-exploited security flaw.

ZDI said it reported the issue to MikroTik during the event last December and asked again for an update in May this year, five months later. On May 10, ZDI said it “re-disclosed the report at the vendor’s request” and gave the company an extra week to provide fixes.

Advertisement. Scroll to continue reading.

In its response, MikroTik said it cannot find a record of the December disclosure from ZDI and that it was not present at the Toronto event in December to discuss the exploit.

Security defects in MikroTik routers have featured in the CISA must-patch list and have been used in the past to build malicious botnets.

Related: Microsoft Releases Open Source Tool for Securing MikroTik Routers

Related: CISA Adds Exploited Mikrotik Flaws to ‘Must-Patch’ List

Related: MikroTik Confirms Mēris Botnet Targets Routers

Related: Tesla Hacked Twice at Pwn2Own Exploit Contest

Source…

Japan is belatedly recognising the risks of cyber war


Two days before Prime Minister Yoshihide Suga announced his resignation, Japan finally set about launching his flagship, the Digital Agency.

Due to the need to create such an organization and give it political capital that may disappear by the time a new leader is elected, the world’s third-largest economy left the project embarrassingly late.

Japan will pay the price of reputation for decades of foot drag. The more successful government agencies are in the country’s digitally hesitant bureaucracy and economic modernization, the more surprising the shortcomings it uncovers and the later its efforts will appear.

However, people near the Cabinet Office say that the urgency of the birth of a digital agency masks the fear of being passed on to Kan’s successor. Japan knows that both the private and public sectors are not ready for cyberwarfare, and strongly suspects that potential enemies, especially China, are ready for cyberwarfare.

It’s interesting that Ciaran Martin, the founder and former head of the UK’s National Cyber ​​Security Center (NCSC), joins the board of directors of a small Japan-based cyber defense consultant with the highest level of Japanese ears. To the moment. government. Other advisors of the company, Japan Cyber ​​DefenseIncludes former top officers in Japan and former Chief of Staff in Taiwan.

Martin’s addition as an adviser is in line with the government’s efforts to put together a complete cyber defense strategy by December and a changing perception of the risks facing the country, according to his new colleague. NS Ransomware attack The closure of America’s largest oil pipeline in May was only the latest in a global attack on critical infrastructure, said a Japanese cyber defense executive. But it was a particularly timely illustration of what the vulnerabilities of today’s nation would look like to the people around Suga, many of whom are likely to remain in the next administration.

These real-life shocks say that those who have seen the slow progress of Japan’s public and private sectors are now essential in building a coherent cyber defense strategy.

At some level, Japan appears to have moved to a new stage of heightened…

Source…