Security firm Rubrik is latest to be felled by GoAnywhere vulnerability

Security firm Rubrik is the latest to be taken down by the GoAnywhere vulnerability.

Getty Images

Silicon Valley data security firm Rubrik said it experienced a network intrusion made possible by a zero-day vulnerability in a product it uses called GoAnywhere.

In an advisory posted Tuesday, Rubrik CISO Michael Mestrovich said the breach investigation found the intruder had access to primarily internal sales information, such as company name and contact information, and limited access to information from Rubrik distributors. It said it was found to have accessed an unreasonable number of purchase orders. The investigation, which was assisted by an unnamed third-party company, concluded that sensitive information such as social security numbers, financial account numbers, and payment card data were not compromised.

tight

“We have detected unauthorized access to a limited amount of information in one of our non-production IT test environments as a result of the GoAnywhere vulnerability,” writes Mestrovich. “Importantly, based on current research conducted with the assistance of third-party forensic experts, the unauthorized access did not include data that we protected on behalf of our customers via Rubric products. did not.”

Mestrovich excluded key details from disclosure. Most notably when the breach occurred and when and when Rubrik patched the vulnerability. On February 2nd, her Fortra, a cybersecurity firm, privately alerted customers that it had identified a zero-day exploit of a vulnerability in her GoAnywhere MFT, an enterprise-grade managed file transfer app. Fortra has urged customers to take steps to mitigate the threat until a patch is available. On February 6th, Fortra released version 7.1.2, fixing his vulnerability tracked as CVE-2023-0669.

If you don’t know when the intrusion occurred, it could be that the vulnerability was zero-day at the time it was exploited against Rubrik, or that Rubrik did not install any available patches or take other mitigations. It is impossible to determine whether a breach occurred because timely way.

Rubrik representatives did not respond to emails seeking comment on the timing of the intrusion and when and when the company patched or mitigated the vulnerability. This information will be updated later as it becomes available.

CVE that keeps giving

CVE-2023-0669 has proven to be a valuable asset for attackers. Two weeks after Fortra first disclosed the vulnerability, one of the largest hospital chains in the US gave hackers access to the protected health information of his million patients. The intrusion stated that it exploited this vulnerability. The compromised data included protected medical information as defined in the Health Insurance Portability and Accountability Act, as well as patient personal information, said Community Health, a chain of hospitals in Franklin, Tennessee. Systems said.

Bleeping Computer recently reported that members of the Clop ransomware gang admitted to exploiting a GoAnywhere vulnerability to hack 130 organizations. Research by security firm Huntress confirms that the malware used in the intrusion exploiting CVE-2023-0669 was indirectly related to Clop.

Recently, Clop’s dark website claimed that a ransomware group compromised Rubrik. As evidence, the threat actor posted nine screenshots that appear to show sensitive information belonging to Rubrik. The screenshots appeared to support her Rubrik’s claims that the data obtained in the intrusion was mostly limited to inside sales information.

The Clop site also claimed that the group hacked Hatch Bank and provided 10 screenshots that appear to support the claim. Hatch Bank, a bank that serves fintech companies, announced in late February that it had experienced a breach that gave it access to the names and social security numbers of about 140,000 customers. A letter sent by Hatch Bank to some customers identified a zero-day vulnerability in GoAnywhere as the cause.

CVE-2023-0669 poses a significant threat. Everyone using GoAnywhere should prioritize investigating their exposure to this vulnerability and responding accordingly.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *