CyberzSOC

Publication detail
← Back to advisories & guidance

Update on SVR Cyber Operations and Vulnerability Exploitation ↗ source

October 10, 2024 NSA Alert
Co-sealed by: CNMF, FBI, NCSC-UK, NSA

Summary

The Federal Bureau of Investigation (FBI), the The authoring agencies recommend the following mitigations to protect their networks. Mission Force (CNMF), and the United See the Mitigations section for the complete Kingdom’s National Cyber Security Centre (NCSC-UK) are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, • Reduce attack surface by disabling techniques, and procedures (TTPs) employed by Internet-accessible services that you do the Russian Federation’s Foreign Intelligence not need, or restrict access to trusted Service (SVR) in recent cyber operations and networks, and removing unused provide network defenders with information to applications and utilities from help counter SVR cyber threats. workstations and development Since at least 2021, Russian SVR cyber actors – also tracked as APT29, Midnight Blizzard authentication whenever possible. (formerly Nobelium), Cozy Bear, and the Dukes – have consistently targeted US, European, and and applications with administrative global entities in the defense, technology, and access to email for unusual activity. finance sectors to collect foreign intelligence and enable future cyber operations, including in support of Russia’s ongoing invasion of Ukraine since February 2022. Their operations continue to pose a global threat to government and private sector organizations.

News Coverage

DateSourceArticle
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2023-20198

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-20198 10.0 Critical Cisco IOS XE Web UI Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to cr…
CVE-2023-35078 10.0 Critical Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated…
CVE-2021-42013 9.8 Critical Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf…
CVE-2023-29357 9.8 Critical Microsoft SharePoint Server Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authe…
CVE-2023-40077 9.8 Critical Google Android In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege w…
CVE-2023-42793 9.8 Critical JetBrains TeamCity JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-6345 9.6 Critical Google Chromium Skia Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potential…
CVE-2023-4966 9.4 Critical Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured a…
CVE-2018-13379 9.1 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil…
CVE-2023-38545 8.8 High curl curl This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy …
CVE-2023-40088 8.8 High Google Android In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This c…
CVE-2022-40507 8.4 High Qualcomm, Inc. Snapdragon Memory corruption due to double free in Core while mapping HLOS address to the list.
CVE-2023-36745 8.0 High Microsoft Microsoft Exchange Server 2019 Cumulative Update 13 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-4911 7.8 High GNU GNU C Library GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a loc…
CVE-2023-5044 7.6 High Kubernetes ingress-nginx Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVE-2021-41773 7.5 High Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf…
CVE-2022-27924 7.5 High Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitra…
CVE-2022-2794 7.5 High HP Inc. Certain HP PageWide Pro printers Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.
CVE-2023-24955 7.2 High Microsoft SharePoint Server Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code …
CVE-2023-40289 7.2 High n/a n/a A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privile…
CVE-2023-24023 6.4 Medium n/a n/a Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-…
CVE-2023-37580 6.1 Medium Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.
CVE-2023-40076 5.5 Medium Google Android In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This …
CVE-2021-27850 — Apache Software Foundation Apache Tapestry A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…
CVE-2023-38546 — curl curl This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl p…
CVE-2023-45866 — n/a n/a Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.