Cybersecurity firm Sophos had released an emergency patch for its product called ‘XG Firewall‘ which had a SQL injection vulnerability, a zero-day bug. Hackers already had started exploiting this vulnerability in the wild, so if you are using this product you should download and install the patch as soon as possible.
Sophos had identified this vulnerability through one of their customers on April 22, Wednesday. Customer had mentioned a suspicious field value is visible in the interface. Furthermore, after investigating the case, Sophos identified it is an active attack and not an error in their system.
Hackers had used an unknown SQL injection vulnerability to access the XG exposed devices. They then aimed at XG Firewall devices that had administration or user portal control being exposed through the internet. Moreover, they also did use the SQL vulnerability to download a payload, fetching files from XG Firewall.
The below diagrams illustrates Asnarok’s penetration into Firewall and the malware’s exfiltration stages,
The data stolen from the product includes usernames, passwords, license details of the product, emails ids and user accounts. However, Sophos mentioned that their authentication systems like LDAP and AD were safe.
After analyzing and tracking the footprints of the hackers, Sophos confirmed the actors did not penetrate the XG Firewall devices, and had not breached the firewall of its customers. This malware was named as ‘Asnarok’ by the Sophos team.
The UK based company had already deployed an emergency patch for its product, and the product’s auto-update feature if enabled will take care of this vulnerability. Along with the patch for XG Firewall, Sophos has included a feature, a special box in the product which will intimate the admins if their device is compromised.
Enterprises that have already been hacked to exploit this vulnerability, Sophos recommends the below steps,
Enterprises also should disable the firewall administration interface on the ports if the same is not a mandatory configuration for the network. Disable WAN’s control panel using these instructions.
Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.
Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…
Discover the top 7 smartphones of 2024 with best security features, offering privacy, performance, and…
Discover the top 11 log management tools for efficient system management and monitoring. Learn about…
Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…
Explore the top 5 best PAM Tools, market trends, and expert insights to secure the…
Explore the top solutions for Apple Device Management including to iOS Device Management and macOS…
View Comments
Now I am going to do my breakfast, when having my breakfast coming again to read additional news. Cory Delmer Sedda
Someone necessarily assist to make critically posts I might state. Belinda Clem Appledorf Ellen Blayne Ras
Congratulations, a good game with nice stuff as this, congratulations Charline Beltran Colner
When I originally commented I seem to have clicked on the -Notify me when new comments are added- checkbox and from now on each time a comment is added I recieve 4 emails with the same comment. There has to be an easy method you can remove me from that service? Kudos! Brittney Izaak Desdamonna
Very good post! We will be linking to this great content on our site. Keep up the great writing. Bria Hersch Weihs
This info is invaluable. Where can I find out more? Kellie Augustine Roanna
Accepted to our goliath environs and relay chief power conducive to you that created such undisturbed. Janetta Kristoforo Tiffie
If you would like to obtain much from this paragraph then you have to apply such methods to your won weblog. Madalyn Walden Nunci
Wow! Thank you! I permanently wanted to write on my blog something like that. Can I include a portion of your post to my site? Lenette Freedman Engedi
Hello, constantly i used to check webpage posts here early in the dawn, since i like to find out more and more. Rosamond Lezley Gaudet