menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

7d

read

99

img
dot

Image Credit: Securityaffairs

Attackers target Zyxel RCE vulnerability CVE-2023-28771

  • Attackers are actively targeting the Zyxel RCE vulnerability CVE-2023-28771, according to GreyNoise researchers.
  • On June 16, a surge in exploit attempts against the Zyxel IKE decoders vulnerability was observed, with 244 unique IPs involved.
  • The main targets of the attack were the U.S., U.K., Spain, Germany, and India.
  • All 244 IP addresses related to the exploitation attempts were traced back to Verizon Business in the U.S., but the use of UDP means the IPs could be spoofed.
  • The exploit attempts were linked to Mirai botnet variants, as confirmed by VirusTotal.
  • GreyNoise recommends blocking the identified malicious IPs, verifying device patches, monitoring for post-exploitation activities, and limiting exposure on IKE/UDP port 500.
  • In April 2023, Zyxel addressed the CVE-2023-28771 vulnerability in its firewall devices and urged customers to install patches to mitigate the risk.
  • The U.S. CISA added the vulnerability to its Known Exploited Vulnerability to Catalog after observing active exploitation.

Read Full Article

like

5 Likes

For uninterrupted reading, download the app