Sunday, February 5, 2023
No Result
View All Result
  • Login
NEWSLETTER
Google Publishers
  • World
    • Africa
    • China
    • Asia
    • Australia
    • Europe
    • India
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • All
    • Diet and Weight Loss
    • Fashion
    • Health
    • Relationships
    fibromi x400 thumb

    Libro "Fibromialgia, del Dolor a la Libertad"

    mh 1 31 yellowstone 1675182540

    The Dutton Family Tree Reveals How ‘Yellowstone’ Is Going to End

    trumpbar x400 thumb

    2022-2025 President Trump Gold Bar

    falsefavs x400 thumb

    Horse racing system, betting systems, make money online, laying horses on betfair, proven laying system, lay betting, betfair, laying favourites, false favourites, online betting exchanges,betfair trading, punting on horses,racing tips, sports betting, weak favourites

    the best products to relieve tmj pain according t 3 6937 1675459989 12 dblbig

    The Best Products To Relieve TMJ Pain, According To Experts

    VYP2MOQ6BRFSRFPQRT44BXPWRA

    15-year-old girl arrested for murder for setting Bronx arson fire

    bestjoy x400 thumb

    LionSea DriverTuner™ – The Best Driver-Updating Program – DriverTuner ™

    5472

    Avoid flat lemonade and don’t starve the bug: what to do when gastro strikes

    feature image phone addiction memory

    Remember how it felt to remember things? Your phone camera might be wreaking havoc with your memory. How to combat ‘digital amnesia’

    mh 1 31 essay 2

    Testosterone Shots Made Me Feel Reborn

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • All
    • Gaming
    • Music
    • Sports
    donovan mitchell cleveland cavaliers usatsi

    Cavaliers vs. Pacers odds, line, spread: 2023 NBA picks, Feb. 5 predictions from proven computer model

    20 times abbott elementary made us laugh but were 3 2906 1675282655 0 dblbig

    20 Times “Abbott Elementary” Made Us Laugh, But Were Still Very Real Moments For Public Schools

    r1127045 1296x729 16 9

    Real Madrid stumble at Mallorca as Asensio misses penalty

    smokey robinson in concert 1280

    Smokey Robinson: Unstoppable

    4094658 loadout caliber site

    The Weird Ways Games Use Calibers – Loadout

    Skinamarink trailer

    What’s Popular On Streaming Now

    Lisa Marie Presley Felt Protected During COVID, Vulnerable Pre-Golden Globes

    carole feraci

    Carole Feraci, the singer who spoke her mind to Richard Nixon

    4590f170 38c8 471a a88a 0c6dc32ad9a6 Patatas Bravas

    Chef José Andrés shares his recipe for the potato dish

    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    gettyimages 1194601645

    This Common Daily Habit Is Wrecking Your Health

    236504 SmartThings Station JTuohy0004

    Samsung’s new SmartThings Station is a do-it-all smart home hub

    Best Cheap Phone Plans Update Gear GettyImages 1370101043

    The Best Budget Phone Plans to Ditch the Big Carriers

    63dd75cb0a08ae0018a6ba8b?width=1200&format=jpeg

    A Texas ‘Dreamer’ found out during an immigration meeting that his dad wasn’t his biological father. Now he could be trapped in Mexico for a decade.

    apple ipad pro 2022 review 11

    These 5 features turned my iPad into a shockingly good computer | Digital Trends

    The end of free rides: How Netflix is tackling account sharing

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities
  • World
    • Africa
    • China
    • Asia
    • Australia
    • Europe
    • India
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • All
    • Diet and Weight Loss
    • Fashion
    • Health
    • Relationships
    fibromi x400 thumb

    Libro "Fibromialgia, del Dolor a la Libertad"

    mh 1 31 yellowstone 1675182540

    The Dutton Family Tree Reveals How ‘Yellowstone’ Is Going to End

    trumpbar x400 thumb

    2022-2025 President Trump Gold Bar

    falsefavs x400 thumb

    Horse racing system, betting systems, make money online, laying horses on betfair, proven laying system, lay betting, betfair, laying favourites, false favourites, online betting exchanges,betfair trading, punting on horses,racing tips, sports betting, weak favourites

    the best products to relieve tmj pain according t 3 6937 1675459989 12 dblbig

    The Best Products To Relieve TMJ Pain, According To Experts

    VYP2MOQ6BRFSRFPQRT44BXPWRA

    15-year-old girl arrested for murder for setting Bronx arson fire

    bestjoy x400 thumb

    LionSea DriverTuner™ – The Best Driver-Updating Program – DriverTuner ™

    5472

    Avoid flat lemonade and don’t starve the bug: what to do when gastro strikes

    feature image phone addiction memory

    Remember how it felt to remember things? Your phone camera might be wreaking havoc with your memory. How to combat ‘digital amnesia’

    mh 1 31 essay 2

    Testosterone Shots Made Me Feel Reborn

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • All
    • Gaming
    • Music
    • Sports
    donovan mitchell cleveland cavaliers usatsi

    Cavaliers vs. Pacers odds, line, spread: 2023 NBA picks, Feb. 5 predictions from proven computer model

    20 times abbott elementary made us laugh but were 3 2906 1675282655 0 dblbig

    20 Times “Abbott Elementary” Made Us Laugh, But Were Still Very Real Moments For Public Schools

    r1127045 1296x729 16 9

    Real Madrid stumble at Mallorca as Asensio misses penalty

    smokey robinson in concert 1280

    Smokey Robinson: Unstoppable

    4094658 loadout caliber site

    The Weird Ways Games Use Calibers – Loadout

    Skinamarink trailer

    What’s Popular On Streaming Now

    Lisa Marie Presley Felt Protected During COVID, Vulnerable Pre-Golden Globes

    carole feraci

    Carole Feraci, the singer who spoke her mind to Richard Nixon

    4590f170 38c8 471a a88a 0c6dc32ad9a6 Patatas Bravas

    Chef José Andrés shares his recipe for the potato dish

    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    gettyimages 1194601645

    This Common Daily Habit Is Wrecking Your Health

    236504 SmartThings Station JTuohy0004

    Samsung’s new SmartThings Station is a do-it-all smart home hub

    Best Cheap Phone Plans Update Gear GettyImages 1370101043

    The Best Budget Phone Plans to Ditch the Big Carriers

    63dd75cb0a08ae0018a6ba8b?width=1200&format=jpeg

    A Texas ‘Dreamer’ found out during an immigration meeting that his dad wasn’t his biological father. Now he could be trapped in Mexico for a decade.

    apple ipad pro 2022 review 11

    These 5 features turned my iPad into a shockingly good computer | Digital Trends

    The end of free rides: How Netflix is tackling account sharing

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities
No Result
View All Result
Google Publishers
No Result
View All Result
Home Tech

SSRF attacks hit 100,000 businesses globally since November | Computer Weekly

by Google Publishers
January 24, 2023
in Tech
0
cyber security attack virus malware Skorzewiak adobe
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Tumblr

Security teams are warned to be on the lookout for a growing wave of opportunistic and largely untargeted cyber attacks exploiting two related exploit chains to target Microsoft Exchange servers.

This is according to Bitdefender Labs, which noted an uptick in attack volumes beginning at the end of November 2022. The attacks are technically known as server-side request forgeries (SSRF), and are rapidly becoming widely popular and routinely exploited by the cyber criminal underground – mainly because Microsoft Exchange is so widely used.

In an SSRF attack, a threat actor sends a specially crafted request from a vulnerable server to another server on the vulnerable server’s behalf, and thus becomes able to access resources or information not directly accessible to them, and perform actions on the vulnerable server’s behalf.

There are two exploit chains currently under active exploitation. The first is ProxyNotShell, a combination of two disclosed vulnerabilities, CVE-2022-41080 and CVE-2022-41082 that requires the threat actor to authenticate to the vulnerable server, and was patched by Microsoft in November 2022.

The second is known as OWASSRF. This is a slightly different exploit chain that uses the same two vulnerabilities, albeit slightly differently in such a way that it can bypass the ProxyNotShell mitigations. OWASSRF was used in the December 2022 Rackspace attack.

The research team claims that more than 100,000 organisations globally have fallen victim to SSRF attacks in the past couple of months, with the majority of victims in the US and Europe. Victims were found in multiple sectors including arts and entertainment, consultancy, legal, manufacturing, real estate and wholesale.

“While the initial infection vector keeps evolving and threat actors are quick to exploit any new opportunity, their post-exploitation activities are familiar. The best protection against modern cyber attacks is a defence-in-depth architecture,” the Bitdefender team wrote.

“Start with reducing your attack surface, focusing on patch management – not only for Windows but for all applications and internet-exposed services), and detection of misconfigurations.

“The next security layer should be reliable world-class protection controls that can eliminate most security incidents, using multiple layers of security, including IP/URL reputation for all endpoints, and protection against fileless attacks. 

“Implementing IP, domain, and URL reputation…is one of the most effective methods to stop automated vulnerability exploits. According to analysis in the Data breach investigations report 2022, only 0.4% of the IPs that attempted RCEs were not seen in one of the previous attacks. Block bad IPs, domains or URLs on all devices, including endpoints, and prevent a security breach in your business environment. 

“Finally, for the few incidents that get through your defenses, lean on security operations, either in-house or through a managed service, and leverage strong detection and response tools. Modern threat actors often spend weeks or months doing active reconnaissance on networks, generating alerts and relying on the absence of detection and response capabilities,” they said.

The Bitdefender team found evidence of multiple different types of cyber attacks taking advantage of the two exploit chains.

Among them were the deployment of remote access and administration tools, the use of web shells, likely by initial access brokers (IABs), the deployment of the Cuba ransomware, and the theft of credentials.

Google Publishers

Google Publishers

Related Posts

gettyimages 1194601645
Tech

This Common Daily Habit Is Wrecking Your Health

by Google Publishers
February 5, 2023

Most people care about staying healthy -- it's getting motivated that's the problem. When you're dreading exercise, it can be hard to...

236504 SmartThings Station JTuohy0004
Tech

Samsung’s new SmartThings Station is a do-it-all smart home hub

by Google Publishers
February 5, 2023

I am a fan of multipurpose smart home hubs. No one has the space or patience for yet another plastic...

Best Cheap Phone Plans Update Gear GettyImages 1370101043

The Best Budget Phone Plans to Ditch the Big Carriers

February 5, 2023
Next Post
3e2bd884c18b01d9f72c4ee2de9c2f47

NTNA S. 7 Challenge 7: Broadway Show Nail Art (Ally)

Recommended

fd6d82b2823a5b067379928929338127

5 takeaways from Phoenix Suns avenging ugly loss with road stunner over Boston Celtics

1 day ago
VYP2MOQ6BRFSRFPQRT44BXPWRA

15-year-old girl arrested for murder for setting Bronx arson fire

3 hours ago

Popular News

  • Trey Songz – One Love ( New Song 2009 ) Lyrics

    0 shares
    Share 0 Tweet 0
  • Maine Tera Naam Dil Rakh Diya – Slowed And Reverb – Galliyan Returns – Lofi Songs | Indian Lofi Song

    0 shares
    Share 0 Tweet 0
  • PashtoMP3.com Pashto Music, Get the Best and latest Pashto songs2

    0 shares
    Share 0 Tweet 0
  • Reza Darmawangsa & Salma SING-OFF MEDLEY EVERY HIT SONGS ON TIKTOK

    0 shares
    Share 0 Tweet 0
  • Boss – Jass Manak ft Avvy Dhaliwal (Official Song) Latest Punjabi Songs GK.DIGITAL Geet

    0 shares
    Share 0 Tweet 0

Connect with us

Facebook Twitter Youtube RSS

About Us

GOOGLE PUBLISHERS NETWORK is the largest local-to-national digital media organization in the country. Our national flagship brand, sits at the center of the NETWORK, surrounded by hundreds of local media properties reporting on the stories and cultural moments happening across America and in our communities.

Recent News

fibromi x400 thumb

Libro "Fibromialgia, del Dolor a la Libertad"

February 5, 2023
1672672655 5472

Five injured in rocket attacks on 2nd-largest city in Ukraine: Officials

February 5, 2023
20230202120256 a5880d6f514a14880a66d778b026476f8d8b37140a35c9f302c1f59ec82915f2 1

Liberals ‘didn’t quite get it right’ on C-21 firearms amendment: minister – National | Globalnews.ca

February 5, 2023

Site Links

  • About Us
  • Corrections & Clarifications
  • Ethical Principles
  • Privacy Policy
  • Terms & Conditions
  • Contact

© 2023 Google Publishers -

No Result
View All Result
  • World
    • Africa
    • China
    • Asia
    • Australia
    • Europe
    • India
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities

© 2023 Google Publishers -

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In