Thursday , April 24 2025
Payment

Ransomware attack on Indian payment system linked to Jenkins bug

Researchers found that recently the ransomware attack on the digital payment system used by many of India’s banks started with a vulnerability in Jenkins, an open-source automation system for software developers. Juniper Networks recently published a study on the abuse of CVE-2024-23897, a vulnerability in Jenkins Command Line Interface.

      Source: Juniper blog post

The National Payments Corporation of India (NPCI) announced on July 31 that it is facing a disruption due to a ransomware attack on a third-party technology provider.

SonicWall patched SSLVPN Vuln Allowing Firewall Crashing

SonicWall has revealed a vulnerability in its SonicOS SSLVPN Virtual Office interface that could let remote attackers crash firewall appliances....
Read More
SonicWall patched SSLVPN Vuln Allowing Firewall Crashing

GitLab Releases Security Update For Multiple Vulns

GitLab has announced a security advisory urging users to upgrade their self-managed installations right away. Versions 17.11.1, 17.10.5, and 17.9.7...
Read More
GitLab Releases Security Update For Multiple Vulns

ISPAB president “whatsapp” got hacked via phishing link

Imdadul Haque, the president of Internet Service Provider of Bangladesh (ISPAB) said, I automatically got back my WhatsApp account. What...
Read More
ISPAB president “whatsapp” got hacked via phishing link

Zyxel released patches 2 vulns in its USG FLEX H series firewalls

Zyxel Networks has issued critical security patches for two high-severity vulnerabilities in its USG FLEX H series firewalls. These flaws...
Read More
Zyxel released patches 2 vulns in its USG FLEX H series firewalls

South Korea’s largest SK Telecom Hit by Malware: SIM-related info leaked

South Korea's largest mobile operator, SK Telecom, is warning that a malware infection allowed threat actors to access sensitive USIM-related...
Read More
South Korea’s largest SK Telecom Hit by Malware: SIM-related info leaked

ChatGPT Develops Exploit for CVEs Before Public PoCs Share

Security researcher Matt Keeley showed that artificial intelligence can now develop working exploits for critical vulnerabilities before public proof-of-concept (PoC)...
Read More
ChatGPT Develops Exploit for CVEs Before Public PoCs Share

TP-Link Router Vulns Allow to Execute Malicious SQL Commands

Several vulnerabilities have been found in TP-Link routers, exposing users to serious security risks from SQL injection flaws in their...
Read More
TP-Link Router Vulns Allow to Execute Malicious SQL Commands

SSL.com’s domain validation system’s bug found: Hacker exploited

SSL.com has revealed a major security flaw in its domain validation system, which could enable attackers to acquire fake SSL...
Read More
SSL.com’s domain validation system’s bug found: Hacker exploited

Amazon Follows Microsoft’s Lead, Halts Some Data Center Deals

Amazon has paused some data center lease negotiations for its cloud division, particularly in international markets, according to Wells Fargo...
Read More
Amazon Follows Microsoft’s Lead, Halts Some Data Center Deals

Hackers Exploit Zoom’s Remote Control Feature for System Access

ELUSIVE COMET is a threat actor conducting a sophisticated attack campaign that uses Zoom's remote control feature to access victims'...
Read More
Hackers Exploit Zoom’s Remote Control Feature for System Access

Services were restored one day later, but the RansomEXX ransomware gang later claimed responsibility for the attack last week. They stated on their leak site that they stole 142 GB from a digital payment platform connected to C-Edge.

Juniper Networks analyzed a report submitted by NPCI to the Indian Computer Emergency Response Team. The researchers stated that the attack highlights the importance of promptly applying security patches and fixing server misconfigurations to prevent the exploitation of security vulnerabilities.

Analysis of the Attack:

Brontoo Technology Solutions reported to CertIn that the attack started from a misconfigured Jenkins server. Further analysis showed that the attacker used CVE-2024-23897 to access the victim’s system without permission.

    Source: Juniper blog post

CVE-2024-23897 is a vulnerability in the Jenkins Command Line Interface, where an attacker tries to gain unauthorized access to targeted systems. The sample ransom note by this group looks like the image below:

CVE-2024-23897: In-Depth Technical Analysis

Jenkins is a free automation server that helps developers worldwide build, test, and deploy software. The vulnerability affects the Jenkins Command Line (CLI), which can be accessed using SSH, WebSocket, or HTTP via a CLI Client.

An unauthenticated user can read the first few lines of any files on the file system due to a vulnerability. This vulnerability is caused by not properly validating user-supplied strings when processing CLI commands. It exists because the command parser’s built-in feature is enabled by default. If this vulnerability is successfully exploited, sensitive files and data may be leaked, commands can be executed, and a ransomware attack can be enabled. Juniper Threat Labs will use a specific version to demonstrate this attack. Click here to read out the full report.

Check Also

ransomware

Bengaluru firm got ransomware attack, Hacker demanded $70,000

Bengaluru’s Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a …

Leave a Reply

Your email address will not be published. Required fields are marked *