In this week's Security Advisory:
Trend Micro disclosed a zero-day in their Apex One (on-premise and SaaS) and Worry-Free Business Security products. The zero-day, CVE-2023-41179, is due to a vulnerability in the 3rd party AV uninstaller module and could allow an attacker to execute arbitrary code on the affected device. To exploit this vulnerability, an attacker must first obtain access to the administrative console on the affected system. There are reports of this vulnerability being actively exploited in the wild. CVE-2023-41179 has not received a CVSS score.
The following versions are affected:
More Reading/Information
A new information stealing malware dubbed 'MetaStealer' is targeting macOS business users. The threat actors are posing as fake clients and tricking users into downloading a malicious disk image (.dmg) file containing the MetaStealer malware. Once downloaded, MetaStealer can evade Apple security mechanisms and proceed to exfiltrate the keychain, harvest passwords and steal files. Threat actors are always going to evolve and find new techniques to deliver malware which is why it is always important to use caution when clicking on any attachments, even if it is coming from a trusted source.
More Reading/Information
Microsoft AI research division accidentally leaked 38T of private data via a misconfigured Shared Access Signature (SAS) token, a URL that provides a secure way to delegate access to data within a storage account. The Microsoft AI research division published this misconfigured SAS token in a public GitHub repository, ultimately giving users full read/write permissions to an internal storage account. While Microsoft states that there was no exposure to consumer data, it highlights the importance of securing access to storage accounts. If your organization must share data from a private cloud storage account, it is best practice to create a separate storage account that is used only for public sharing. Microsoft also recommends following best practices when working with SAS tokens such as applying the principle of least privilege, using short-lived SAS tokens, and having a revocation plan.
More Reading/Information
Please review your environment to ensure the above-mentioned issues are patched in a timely manner. It is security best practice to regularly update and/or patch software to the latest versions. The vulnerabilities above highlight the security benefits of limiting deployed software to "vendor-supported versions" only. This dramatically increases the likelihood that new vulnerabilities have a patch issued for them. Likewise, Cybersafe Solutions strongly encourages maintaining an inventory of current software in your environment, which helps ensure and inform your patch and vulnerability management program.