Subj : Networks breached after ransomware slips past Qlik Sense security To : All From : TechnologyDaily Date : Fri Dec 01 2023 17:45:04 Networks breached after ransomware slips past Qlik Sense security flaws Date: Fri, 01 Dec 2023 17:30:53 +0000 Description: Three separate flaws, patched last summer, are being abused by a group called Cactus. FULL STORY ====================================================================== Hackers were observed exploiting multiple critical vulnerabilities in the Qlik Sense data analytics solution to deploy ransomware and steal sensitive company data. This is according to a new report from cybersecurity researchers Arctic Wolf, which claims that Cactus abused three flaws discovered, and patched, in late August and late September. As per the report, Qlik first found two flaws - CVE-2023-41265 and CVE-2023-41266, in late August this year. A month later, the company discovered that one of the patches did not work as intended, leading to a separate vulnerability tracked as CVE-2023-48365. All three flaws were subsequently addressed and patches were issued. Reader Offer: $50 Amazon gift card with demo Perimeter 81's Malware Protection intercepts threats at the delivery stage to prevent known malware, polymorphic attacks, zero-day exploits, and more. Let your people use the web freely without risking data and network security. Preferred partner ( What does this mean? ) Mitigating the threat These three flaws allowed attackers to generate anonymous sessions and run HTTP requests to unauthorized endpoints, or elevate privileges and run HTTP requests on backend servers hosting the application. Cactus was using the flaws as a means of initial access to corporate networks with unpatched Qlik Sense instances. The group forced the Qlik Sense Scheduler service to initiate new processes, and then used PowerShell and the Background Intelligent Transfer Service (BITS) to download remote access software such as AnyDesk. It also used different infostealing software to grab sensitive corporate data, but at the end of the day, it was the Cactus encryptor that was the most disruptive. To protect against such attacks, Qlik recommended its users upgrade to the following versions of Sense Enterprise for Windows: August 2023 Patch 2 May 2023 Patch 6 February 2023 Patch 10 November 2022 Patch 12 August 2022 Patch 14 May 2022 Patch 16 February 2022 Patch 15 November 2021 Patch 17 Cactus is a relatively new entrant in the ransomware game, first being spotted in March this year. It has the usual modus operandi, stealing sensitive data and encrypting systems, to later demand payment in cryptocurrency in exchange for the decryption key and for keeping the data private. Via BleepingComputer More from TechRadar Pro Ransomware, AI, and social engineering all set to be 2024's biggest security threats Here's a list of the best malware removal software around today These are the best endpoint protection tools right now ====================================================================== Link to news story: https://www.techradar.com/pro/security/networks-breached-after-ransomware-slip s-past-qlik-sense-security-flaws --- Mystic BBS v1.12 A47 (Linux/64) * Origin: tqwNet Technology News (1337:1/100) .