Security News > 2023 > December > Week in review: Apache Struts vulnerability exploit attempt, EOL Sophos firewalls get hotfix
EOL Sophos firewalls get hotfix for old but still exploited vulnerabilityOver a year has passed since Sophos delivered patches for a vulnerability affecting Sophos Firewalls that was being actively exploited by attackers, and now they have pushed additional ones to protect vulnerable EOL devices.
Attackers are trying to exploit Apache Struts vulnerabilityAttackers are trying to leverage public proof-of-exploit exploit code for CVE-2023-50164, the recently patched path traversal vulnerability in Apache Struts 2.
eIDAS: EU's internet reforms will undermine a decade of advances in online securityThe European Union's attempt to reform its electronic identification and trust services - a package of laws better known as eIDAS 2.0 - contains legislation that poses a grave threat to online privacy and security.
Security automation gains traction, prompting a "Shift everywhere" philosophyThe use of automated security technology is growing rapidly, which in turn is propagating the "Shift everywhere" philosophy - performing security tests throughout the entire software development life cycle - across more organizations, according to Synopsys.
WhatsApp, Slack, Teams, and other messaging platforms face constant security risks42% of businesses report employees with BYOD devices in business settings that use tools like WhatsApp have led to new security incidents, according to SafeGuard Cyber.
Photos: CyberMarketingCon 2023Help Net Security sponsored and attended Cybersecurity Marketing Society's CyberMarketingCon 2023 in Austin, TX. New infosec products of the week: December 15, 2023Here's a look at the most interesting products from the past week, featuring releases from Censys, Confirm, Drata, Safe Security, and SpecterOps.
News URL
Related news
- Palo Alto Networks warns of firewall hijack bugs with public exploit (source)
- Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials (source)
- Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices (source)
- Custom "Pygmy Goat" malware used in Sophos Firewall hack on govt network (source)
- Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit (source)
- PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs and Patch Released (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-07 | CVE-2023-50164 | Files or Directories Accessible to External Parties vulnerability in Apache Struts An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue. | 9.8 |