Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Ahead With Linux Security Features

Filter%20icon Refine features
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security features

We found -4 articles for you...
102

Cyberoam Security Alert: RCE Vulnerabilities Impacting 86,000 Networks

A new report published by vpnMentor examines two critical vulnerabilities in cybersecurity provider Cyberoam ’s firewall and VPN technology, which - both independently and combined - could be exploited by malicious actors to access the company’s email quarantine system without authentication and remotely execute arbitrary commands. . These flaws were discovered by different security researchers working independently, and have both been patched by Sophos . The first security bug, which existed in the FirewallOS of the Cyberoam SSL VPN and allowed unauthenticated root remote command execution (pre-auth RCE), was reported in late 2019. This vulnerability provided access to any Cyberoam device by exploiting its email quarantine release system - without requiring the username and password for the account linked to it. VpnMentor explains the serious implications of this flaw: “We found many banks and big corporations were using Cyberoam products as a gateway to their network from the outside, so this opened direct access to their intranet (local networks, often with more sensitive data). Exploiting the vulnerability also allowed relatively easy escalation to ‘root’ access on the device, which would grant a malicious hacker total control of the target device - and potentially the entire network into which that device was integrated. ” Sohos attempted to remedy this security issue by installing a regex-based patch into their code; however, the tech giant’s work was far from over. A second critical remote code execution (RCE) vulnerability, which was discovered in January of 2020, could have been exploited by threat actors to bypass the patch in Cyberoam’s regex filter and create a more versatile attack targeting the quarantine email functionality of Cyberoam’s devices - without even needing a username or password. And exploiting this security bug was fairly simple: it involved encoding the previous RCE command through Base64 and wrapping it in a Linux BashCommand. Luckily, both of these flaws - which left at least 86,000 networks exposed and susceptible to data theft and account takeovers - were successfully patched before they were discovered and exploited by criminal hackers. Read more about these vulnerabilities in a vpnMentor report: Critical Flaws in Cybersecurity Devices Exposed Entire Networks to Attack and Takeover . . Severe vulnerabilities in Cyberoam's firewall and VPN solutions left systems susceptible to security breaches and unauthorized access.. Cyberoam Firewall, Cybersecurity Flaws, Remote Code Execution, Network Security, VPN Vulnerabilities. . Brittany Day

Calendar%202 May 18, 2020 User Avatar Brittany Day
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here