CVE-2023-20269
published 2023-09-06CVE-2023-20269: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could…
PriorityP195critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-10-04
Exploited in the wild
EPSS
21.58%
97.3th percentile
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user.
This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following:
Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes:
Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.
Affected
493 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
command"C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "[REDACTED]\Company\[REDACTED]" [REDACTED]\Company\HR "[REDACTED]\Company\Human Resources Management - HR"↗
- →CVE-2023-20269 exploitation targets the web services interface (AAA functions) of Cisco ASA/FTD; detect by monitoring for high-volume authentication requests to the VPN web services interface with no rate-limiting or lockout, especially against the default connection profile/tunnel group. ↗
- →Exploitation requires SSL VPN enabled on at least one interface OR IKEv2 VPN enabled on at least one interface, combined with at least one LOCAL database user with a password or HTTPS management auth pointing to a valid AAA server — use these as detection pre-conditions. ↗
- →Attackers exploiting CVE-2023-20269 specify a default connection profile/tunnel group (DefaultADMINGroup or DefaultL2LGroup) during brute force or session establishment — monitor for VPN tunnel attempts using these default group names. ↗
- →Post-exploitation: monitor for creation of new administrative domain accounts named 'itadm' as a persistence indicator following Cisco VPN compromise. ↗
- →Post-exploitation: detect LSASS MiniDump creation via comsvcs.dll as a credential-harvesting follow-on after initial access through CVE-2023-20269. ↗
- →Post-exploitation: detect copying of NTDS.dit and SYSTEM registry hive from domain controllers as a follow-on credential-extraction technique after initial VPN access. ↗
- ·Brute-force exploitation of CVE-2023-20269 only works when the device has at least one LOCAL database user with a password configured, or HTTPS management authentication points to a valid AAA server — devices without these configurations are not vulnerable to the brute-force vector. ↗
- ·Clientless SSL VPN session establishment via CVE-2023-20269 is only possible on Cisco ASA Software Release 9.16 or earlier — later releases are not affected by this specific impact. ↗
- ·Establishing a client-based remote access VPN tunnel is NOT possible via this vulnerability, as default connection profiles/tunnel groups cannot have an IP address pool configured — scope detection to clientless SSL VPN and brute-force activity only. ↗
- ·MFA mitigates the risk of account takeover even if credentials are successfully brute-forced — CVE-2023-20269 does not allow bypassing MFA. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck5.0MEDIUM
cisa9.1CRITICAL
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
cisa·2023-09-13·CVSS 9.1
CVE-2023-20269 [CRITICAL] CWE-288 Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Vulnerability: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Affected: Cisco Adaptive Security Appliance and Firepower Threat Defense
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Required Action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC;
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
vendor_cisco·2023-09-06·CVSS 5.0
CVE-2023-20269 [MEDIUM] CWE-288 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user.
This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a de
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20269 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
CVE-2023-20269: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by s
GHSA
GHSA-v7pw-9cmm-88m6: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
ghsa_unreviewed·2023-09-06
CVE-2023-20269 [CRITICAL] CWE-288 GHSA-v7pw-9cmm-88m6: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user.
This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using v
VulnCheck
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
vulncheck·2023·CVSS 5.0
CVE-2023-20269 [MEDIUM] CWE-288 Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid
No detection rules found.
No public exploits indexed.
Unit42
Threat Assessment: Howling Scorpius (Akira Ransomware)
blogs_unit42·2024-12-02·CVSS 7.5
CVE-2020-3259 [HIGH] Threat Assessment: Howling Scorpius (Akira Ransomware)
## Threat Assessment: Howling Scorpius (Akira Ransomware)
Yoav Zemah
Published: December 2, 2024
Cybercrime
High Profile Threats
Ransomware
Akira ransomware
Bring Your Own Driver
CVE-2020-3259
CVE-2023-20269
Double extortion
ESXi
FTP
Howling Scorpius
Lazagne
Leak site
Linux
Megazord
Mimikatz
Remote desktop
Rust
Server Message Block
Torrenting
Windows
## Executive Summary
Emerging in early 2023, the Howling Scorpius ransomware group is the entity behind the Akira ransomware-as-a-service (RaaS), which has consistently ranked in recent months among the top five most active ransomware groups. Its double extortion strategy significantly amplifies the threat it poses. Unit 42 researchers have been monitoring the Howling Scorpius ransomware group over the past year.
H
Unit42
Threat Assessment: Howling Scorpius (Akira Ransomware)
blogs_unit42·2024-12-02
Threat Assessment: Howling Scorpius (Akira Ransomware)
## Executive Summary
Emerging in early 2023, the Howling Scorpius ransomware group is the entity behind the Akira ransomware-as-a-service (RaaS), which has consistently ranked in recent months among the top five most active ransomware groups. Its double extortion strategy significantly amplifies the threat it poses. Unit 42 researchers have been monitoring the Howling Scorpius ransomware group over the past year.
Howling Scorpius targets small to medium-sized businesses in North America, Europe and Australia, across various sectors. Affected industries include education, consulting, government, manufacturing, telecommunications, technology and pharmaceuticals.
Our research reveals that Howling Scorpius maintains and operates encryptors for Windows and Linux operating systems. We identif
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
## Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to mo
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to moderate confidence that this shift was due
Qualys
Akira Ransomware Analysis Origins Tactics and Detection Strategies
blogs_qualys·2024-10-02·CVSS 6.5
[MEDIUM] Akira Ransomware Analysis Origins Tactics and Detection Strategies
## Table of Contents
What is Akira Ransomware? An Overview
Tactics, Techniques, and Procedures (TTPs) Used by Akira
Analyzing Akira Ransomware Samples
How to Detect Akira: Threat Hunting Approaches
Wrapping Up: Key Takeaways on Akira Ransomware
Akira Ransomware in the MITRE ATT&CK Framework
Indicators of Compromise (IoCs) for Akira
## What is Akira Ransomware? An Overview
Akira is a prolific ransomware that has been operating since March 2023 and has targeted multiple industries, primarily in North America, the UK, and Australia. It functions as a Ransomware as a Service (RaaS) and exfiltrates data prior to encryption, achieving double extortion. According to the group’s leak site, they have infected over 196 organizations.
When looking at the history of Akira, one must go back t
Bleepingcomputer
Ransomware payments drop to record low of 28% in Q1 2024
blogs_bleepingcomputer·2024-04-21·CVSS 5.0
[MEDIUM] Ransomware payments drop to record low of 28% in Q1 2024
## Ransomware payments drop to record low of 28% in Q1 2024
## Bill Toulas
Ransomware actors have had a rough start this year, as stats from cybersecurity firm Coveware show companies are increasingly refusing to pay extortion demands, leading to a record low of 28% of companies paying ransom in the first quarter of 2024.
This figure was 29% in Q4 2023 , and Coveware's stats show that diminishing payments have remained steady since early 2019.
This decrease is due to organizations implementing more advanced protective measures, mounting legal pressure not to meet the crooks' financial demands, and cybercriminals repeatedly breaching promises not to publish or resale stolen data if a ransom is paid.
However, it is essential to note that despite the drop in the payment rate, the amount
Tenable
Cybersecurity Snapshot: LockBit Gang Gets Knocked Down, as CISA Stresses Security of Water Plants
blogs_tenable·2024-02-23
Cybersecurity Snapshot: LockBit Gang Gets Knocked Down, as CISA Stresses Security of Water Plants
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Finland warns of Akira ransomware wiping NAS and tape backup devices
blogs_bleepingcomputer·2024-01-11·CVSS 5.0
[MEDIUM] Finland warns of Akira ransomware wiping NAS and tape backup devices
## Finland warns of Akira ransomware wiping NAS and tape backup devices
## Bill Toulas
The Finish National Cybersecurity Center (NCSC-FI) is informing of increased Akira ransomware activity in December, targeting companies in the country and wiping backups.
The agency says that the threat actor's attacks accounted for six out of the seven cases of ransomware incidents reported last month.
Wiping the backups amplifies the damage of the attack and allows the threat actor to put more pressure on the victim as they eliminate the option of restoring the data without paying a ransom.
Smaller organizations often use network-attached storage (NAS) devices for this purpose, but the Finnish agency highlights that these systems were not spared in Akira ransomware attacks.
The attackers also tar
Securelist
PC malware statistics, Q3 2023
blogs_securelist·2023-12-01
PC malware statistics, Q3 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2023
- IT threat evolution in Q3 2023. Non-mobile statistics
- IT threat evolution in Q3 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2023:
- Kaspersky solutions blocked 694,400,301 attacks from online resources across the globe.
- A total of 169,194,807 unique links were recognized as malicious by Web Anti-Virus
Securelist
IT threat evolution in Q3 2023. Non-mobile statistics
blogs_securelist·2023-12-01
IT threat evolution in Q3 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Vulnerability exploitation
More attacks on healthcare
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT honeypots
Attacks via web resources
Countries and territories that serve as sourc
Trendmicro
Akira Ransomware unter der Lupe
blogs_trendmicro·2023-11-14·CVSS 5.0
[MEDIUM] Akira Ransomware unter der Lupe
Ransomware
## Akira Ransomware unter der Lupe
Akira, eine neuartige Ransomware, tauchte erst im Frühling auf, wird aber von sehr erfahrenen und geschickten Betreibern eingesetzt. Wir haben die Hintergründe, Techniken und Taktiken dieser sehr zielgerichteten erfolgreichen Gruppe analysiert.
By: Trend Micro Nov 14, 2023 Read time: ( words)
Save to Folio
Akira entwickelt sich zusehends zu einer der am schnellsten wachsenden Ransomware-Familien, da sie eine doppelte Erpressungstaktik, ein Ransomware-as-a-Service (RaaS)-Vertriebsmodell und einzigartige Zahlungsoptionen einsetzt.
Einem Bericht zufolge, der Blockchain- und Quellcodedaten analysiert hat, scheint die Akira-Gruppe mit der inzwischen aufgelösten Conti-Ransomware -Gang verbunden zu sein. Conti, eine der berüchtigtsten Ransomware
Tenable
Cybersecurity Snapshot: GenAI Drives Broader Use of Artificial Intelligence Tech for Cyber
blogs_tenable·2023-10-27
Cybersecurity Snapshot: GenAI Drives Broader Use of Artificial Intelligence Tech for Cyber
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cybersecurity Snapshot: SANS Offers Tips for Maximizing Smaller OT Security Budgets
blogs_tenable·2023-10-06
Cybersecurity Snapshot: SANS Offers Tips for Maximizing Smaller OT Security Budgets
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Cisco fixes hard-coded root credentials in Emergency Responder
blogs_bleepingcomputer·2023-10-04·CVSS 9.8
CVE-2023-20101 [CRITICAL] Cisco fixes hard-coded root credentials in Emergency Responder
## Cisco fixes hard-coded root credentials in Emergency Responder
## Sergiu Gatlan
Cisco released security updates to fix a Cisco Emergency Responder (CER) vulnerability that let attackers log into unpatched systems using hard-coded credentials.
CER helps organizations respond effectively to emergencies by enabling accurate location tracking of IP phones, allowing emergency calls to be routed to the appropriate Public Safety Answering Point (PSAP).
Tracked as CVE-2023-20101, the security flaw allows unauthenticated attackers to access a targeted device using the root account, which had default, static credentials that could not be modified or removed.
"This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during d
Tenable
Cybersecurity Snapshot: DHS Tracks New Ransomware Trends, as Attacks Drive Up Cyber Insurance Claims and Snatch Variant Triggers Alert
blogs_tenable·2023-09-22
Cybersecurity Snapshot: DHS Tracks New Ransomware Trends, as Attacks Drive Up Cyber Insurance Claims and Snatch Variant Triggers Alert
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2023-20269: Zero-Day Vulnerability in Cisco Adaptive Security Appliance and Firepower Threat Defense Reportedly Exploited by Ransomware Groups
blogs_tenable·2023-09-11·CVSS 5.0
[MEDIUM] CVE-2023-20269: Zero-Day Vulnerability in Cisco Adaptive Security Appliance and Firepower Threat Defense Reportedly Exploited by Ransomware Groups
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
11th September – Threat Intelligence Report
blogs_checkpoint·2023-09-11·CVSS 9.8
CVE-2022-47966 [CRITICAL] 11th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th September, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Check Point warns of a recent Email phishing campaign abusing the data visualization tool – Google Looker Studio. Attackers use the tool to send slideshow emails to victims from official Google accounts, instructing them to visit 3 rd party websites to collect cryptocurrency. The websites will then prompt the victims
Bleepingcomputer
The Week in Ransomware - September 8th 2023 - Conti Indictments
blogs_bleepingcomputer·2023-09-08
The Week in Ransomware - September 8th 2023 - Conti Indictments
## The Week in Ransomware - September 8th 2023 - Conti Indictments
## Lawrence Abrams
It started as a slow ransomware news week but slowly picked up pace with the Department of Justice announcing indictments on TrickBot and Conti operations members.
On Thursday, the US announced sanctions and three indictments against nine Russian nationals who are alleged members of the TrickBot and Conti ransomware operations for attacks on more than 900 victims worldwide.
"The defendants charged in these three indictments across three different jurisdictions allegedly used their cyber knowledge and capabilities to victimize people and businesses around the world without regard for the damage they caused," said Acting Assistant Attorney General Nicole M. Argentieri of the Justice Department's Crimina
Bleepingcomputer
Cisco warns of VPN zero-day exploited by ransomware gangs
blogs_bleepingcomputer·2023-09-08·CVSS 5.0
CVE-2023-20269 [MEDIUM] Cisco warns of VPN zero-day exploited by ransomware gangs
## Cisco warns of VPN zero-day exploited by ransomware gangs
## Bill Toulas
Cisco is warning of a CVE-2023-20269 zero-day vulnerability in its Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) that is actively exploited by ransomware operations to gain initial access to corporate networks.
The medium severity zero-day vulnerability impacts the VPN feature of Cisco ASA and Cisco FTD, allowing unauthorized remote attackers to conduct brute force attacks against existing accounts.
By accessing those accounts, the attackers can establish a clientless SSL VPN session in the breached organization's network, which can have varying repercussions depending on the victim's network configuration.
Last month, BleepingComputer reported that the Akira ransomware gang
Huntress
CVE-2023-20269 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 9.1
CVE-2023-20269 [CRITICAL] CVE-2023-20269 Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2023-20269 Vulnerability
Published: 2/20/2025
Written by: Lizzie Danielson
## What is CVE-2023-20269 vulnerability?
CVE-2023-20269 is a critical vulnerability impacting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. It leverages a flaw in the Remote Access Virtual Private Network (RAVPN) authentication mechanism, potentially allowing unauthenticated attackers to execute arbitrary code on targeted devices. The vulnerability is notable for its high threat level due to its ability to bypass authentication, making affected systems susceptible to unauthorized access and exploitation.
## When was it discovered?
This vulnerability was disclosed on August 23, 2023, by Cisco, following internal identification and extensive analysis. Cisco promptly iss
arXiv
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
arxiv_fulltext·2026-03
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Akhil Gupta Chigullapally^1, Sharvan Vittala^1, Razin Farhan Hussian^2, Mohsen Amini Salehi^3
^1Department of Computer Science and Engineering, University of North Texas (UNT)
\akhilguptachigullapally, [email protected]\@my.unt.edu
^2Versaterm Public Safety Inc., Canada
[email protected]
^3High Performance Cloud Computing (HPCC) Lab, Department of Computer Science and Engineering, University of North Texas (UNT)
[email protected]
## Abstract
The fast pace of modern AI is rapidly transforming traditional industrial systems into vast,
intelligent—and potentially unmanned—autonomous operational environments driven by AI-based solutions. These solutions leverage various forms of machine lea
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeChttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeChttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20269
2023-09-06
Published
2023-09-13
Added to CISA KEV
Exploited in the wild