CouRRier News Today
CouRRier News Today
Skip to content
  • Cybersecurity
  • Weather
  • Life
  • Sports
  • Loot
  • Local
  • FORUM

October 2024

There were 1,821 posts published in October 2024 (this is page 6 of 183).

Post navigation

Anthony Rizzo, Alex Verdugo discuss uncertain Yankees futures after World Series loss

The biggest story of the Yankees’ offseason will be their attempt to keep Juan Soto. But while the Yanks try to do that, there are a handful of their other key players who are also about to hit the open market.

in Sports | October 31, 2024 | 41 Words

World Series 2024: Brutal loss in Game 5 sends New York Yankees into the offseason with a lot to regret

The Yankees had a 5-0 lead and their ace on the mound before it all fell apart, ending their season in particularly painful fashion.

in Sports | October 31, 2024 | 24 Words

Rockwell Automation FactoryTalk ThinManager

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v4 9.3
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Rockwell Automation
  • Equipment: FactoryTalk ThinManager
  • Vulnerabilities: Missing Authentication For Critical Function, Out-of-Bounds Read

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow an attacker to send crafted messages to the device resulting in database manipulation or a denial-of-service condition.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following Rockwell Automation FactoryTalk product versions are affected:

  • ThinManager: Versions 11.2.0 to 11.2.9
  • ThinManager: Versions 12.0.0 to 12.0.7
  • ThinManager: Versions 12.1.0 to 12.1.8
  • ThinManager: Versions 13.0.0 to 13.0.5
  • ThinManager: Versions 13.1.0 to 13.1.3
  • ThinManager: Versions 13.2.0 to 13.2.2
  • ThinManager: Version 14.0.0

3.2 Vulnerability Overview

3.2.1 MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306

An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.

CVE-2024-10386 has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

A CVSS v4 score has also been calculated for CVE-2024-10386. A base score of 9.3 has been calculated; the CVSS vector string is (CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).

3.2.2 OUT-OF-BOUNDS READ CWE-125

A denial-of-service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, resulting in a denial-of-service condition.

CVE-2024-10387 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

A CVSS v4 score has also been calculated for CVE-2024-10387. A base score of 8.7 has been calculated; the CVSS vector string is (CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: United States

3.4 RESEARCHER

Tenable Network Security reported these vulnerabilities to Rockwell Automation.

4. MITIGATIONS

Rockwell Automation has provided a fix for the affected versions on the FactoryTalk ThinManager download site.

Rockwell Automation encourages users of the affected software to apply these risk mitigations if possible.

  • Implement network hardening for ThinManager Device(s) by limiting communications to TCP 2031 to only the devices that need connection to the ThinManager.
  • For information on how to mitigate security risks on industrial automation control systems, users are encouraged to implement Rockwell Automation’s suggested security best practices to minimize the risk of the vulnerability.

For more information, see Rockwell Automation’s security bulletin.

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

5. UPDATE HISTORY

  • October 31, 2024: Initial Publication
in Cybersecurity, DHS | October 31, 2024 | 681 Words

Foreign Threat Actor Conducting Large-Scale Spear-Phishing Campaign with RDP Attachments

CISA has received multiple reports of a large-scale spear-phishing campaign targeting organizations in several sectors, including government and information technology (IT). The foreign threat actor, often posing as a trusted entity, is sending spear-phishing emails containing malicious remote desktop protocol (RDP) files to targeted organizations to connect to and access files stored on the target’s network. Once access has been gained, the threat actor may pursue additional activity, such as deploying malicious code to achieve persistent access to the target’s network. 

CISA, government, and industry partners are coordinating, responding, and assessing the impact of this campaign. CISA urges organizations to take proactive measures:

  •  Restrict Outbound RDP Connections:
    • It is strongly advised that organizations forbid or significantly restrict outbound RDP connections to external or public networks. This measure is crucial for minimizing exposure to potential cyber threats.
    • Implement a Firewall along with secure policies and access control lists.
  • Block RDP Files in Communication Platforms:
    • Organizations should prohibit RDP files from being transmitted through email clients and webmail services. This step helps prevent the accidental execution of malicious RDP configurations.
  • Prevent Execution of RDP Files: 
    • Implement controls to block the execution of RDP files by users. This precaution is vital in reducing the risk of exploitation.
  • Enable Multi-Factor Authentication (MFA):
    • Multi-factor authentication must be enabled wherever feasible to provide an essential layer of security for remote access.
    • Avoid SMS MFA whenever possible.
  • Adopt Phishing-Resistant Authentication Methods:
    • Organizations are encouraged to deploy phishing-resistant authentication solutions, such as FIDO tokens. It is important to avoid SMS-based MFA, as it can be vulnerable to SIM-jacking attacks.
  • Implement Conditional Access Policies:
    • Establish Conditional Access Authentication Strength to mandate the use of phishing-resistant authentication methods. This ensures that only authorized users can access sensitive systems.
  • Deploy Endpoint Detection and Response (EDR):
    • Organizations should implement Endpoint Detection and Response (EDR) solutions to continuously monitor for and respond to suspicious activities within the network.
  • Consider Additional Security Solutions:
    • In conjunction with EDR, organizations should evaluate the deployment of antiphishing and antivirus solutions to bolster their defenses against emerging threats.
  • Conduct User Education:
    • Robust user education can help mitigate the threat of social engineering and phishing emails. Companies should have a user education program that highlights how to identify and report suspicious emails.
    • Recognize and Report Phishing: Avoid phishing with these simple tips.
  • Hunt For Activity Using Referenced Indicators and TTPs:
    • Utilize all indicators that are released in relevant articles and reporting to search for possible malicious activity within your organization’s network.
    • Search for unexpected and/or unauthorized outbound RDP connections within the last year.

CISA urges users and administrators to remain vigilant against spear-phishing attempts, hunt for any malicious activity, report positive findings to CISA, and review the following articles for more information:

  • Microsoft: Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files
  • AWS Security: Amazon identified internet domains abused by APT29
  • The Centre for Cybersecurity Belgium: Warning: Government-themed Phishing with RDP Attachments
  • Computer Emergency Response Team of Ukraine: RDP configuration files as a means of obtaining remote access to a computer or “Rogue RDP”
in Cybersecurity, DHS | October 31, 2024 | 509 Words

World Series 2024: For the Dodgers, scale and scope of championship cannot be overstated

The impact of L.A.’s victory in Game 5 extends well beyond the stars to the team’s unsung heroes and fans around the world.

in Sports | October 31, 2024 | 24 Words

Why Tomorrow Could Be a Big Day for the Stock Market — And the U.S. Presidential Election

in Money, News | October 31, 2024 | 0 Words

Aaron Judge owns costly fifth-inning error in Yankees’ World Series loss: ‘I gotta make the play’

Gerrit Cole and the Yankees appeared to be cruising to a Game 5 World Series victory, but then quickly things changed.

in Sports | October 31, 2024 | 20 Words

LeBron and Bronny James return home, both take the court in Lakers game in Cleveland

Bronny James entered the game to a massive ovation from Cavaliers fans on Wednesday night.

in Sports | October 31, 2024 | 15 Words

World Series: Yankees fans called for interference after trying to rip glove off Mookie Betts’ hand in Game 4

These Yankees fans certainly tried their best to stop Mookie Betts from making the out on Tuesday.

in Sports | October 31, 2024 | 17 Words

Dodgers vs. Yankees: Anthony Volpe’s grand slam helps New York force World Series Game 5

The Yankees scored 11 runs in Game 4 to fend off a sweep in this Fall Classic.

in Sports | October 31, 2024 | 15 Words

Post navigation

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • July 2020
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • June 2013
  • April 2012
  • March 2012
  • February 2012
  • October 1839

Meta

  • Log in
Independent Publisher empowered by WordPress