enterprisesecuritymag

Recent Exploits of a Windows Print Spooler Vulnerability Has Been Spotted In The Wild.

Enterprise Security Magazine | Tuesday, January 18, 2022

A security flaw in the Windows Print Spooler component that was patched by Microsoft in February is being actively exploited in the wild, the U.S. Cybersecurity and Infrastructure Security Agency have warned.

FREMONT, CA: The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that a security defect in the Windows Print Spooler component, which was patched by Microsoft in February, is being actively abused in the wild. For that purpose, the agency has added the flaw to its Known Exploited Vulnerabilities Catalog, requiring FCEB agencies to fix the problems by May 10, 2022. The security flaw, identified as CVE-2022-22718, is one of four privilege escalation flaws in the Print Spooler that Microsoft fixed as part of their Patch Tuesday updates on February 8, 2022. It's worth mentioning that since the severe PrintNightmare remote code execution vulnerability was discovered last year, Microsoft has patched several Print Spooler problems, including 15 elevations of privilege vulnerabilities in April 2022.

The nature of the attacks and the identity of the threat actors who may be abusing the Print Spooler flaw is unclear to avoid further exploitation by hacker teams. When the patches were released two months ago, Microsoft assigned the tag "exploitation more likely."

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

The list has been updated with two additional security issues based on "evidence of active exploitation"- CVE-2018-6882 (CVSS rating: 6.1) - Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS). The CVSS score for CVE-2019-3568 is 9.8 - it is a vulnerability in WhatsApp's VoIP stack buffer.

CVE-2018-6882 was added just days after the Computer Emergency Response Team of Ukraine (CERT-UA) issued an advisory warning of phishing attempts targeting government bodies with the intention of forwarding victims' emails to a third-party email account using the Zimbra vulnerability.  UAC-0097 was identified as the source of the targeted intrusions, according to CERT-UA. In light of real-world attacks that exploit vulnerabilities, organisations should "prioritise fast remediation as part of their vulnerability management process," according to the report.

More in News

Recent advancements in digital networks have introduced a range of cybersecurity challenges. As the commercial ecosystem continues to expand, traditional security tools increasingly fail to address the scale and complexity of emerging threats. In response to these challenges, the integration of artificial intelligence into firewall solutions has fundamentally transformed the manner in which organizations safeguard their systems and data. AI-enhanced firewall solutions have significantly improved their capacity to learn, adapt, and respond to evolving threats with remarkable precision. This development represents a new phase in modern network defense strategies. The combination of artificial intelligence, automation, analytics, and intelligence has substantially increased the resilience of digital infrastructure, enabling organizations to protect themselves against cyber risks better. What Are the Steps to Advance Toward Adaptive Intelligence? From the inception of the static protection model, firewalls have functioned as static gatekeepers, filtering traffic based on predefined rules in accordance with signature-based detection methodologies. Although these systems have been effective in blocking certain threats, they exhibit limited flexibility in identifying and mitigating new and emerging attack patterns. The advent of artificial intelligence (AI) has catalyzed a paradigm shift, enabling firewalls to transition from rigid rule sets to adaptive, behavior-based protection mechanisms. Through the application of machine learning algorithms, AI-enabled firewalls continuously monitor network and link traffic, detect anomalies, and adjust defensive measures in real time as attacks progress. This dynamic approach enhances preventive capabilities over time, facilitating real-time intrusion detection rather than addressing breaches post-occurrence. As digital infrastructures progressively become more interconnected and complex, adaptive AI firewall systems will increasingly contribute to the overall cybersecurity ecosystem. This comprehensive security framework will integrate data from a variety of sources, including endpoint protection, identity management, and cloud security tools. AI-driven firewalls can enhance visibility across complex networks and identify potential risks that isolated security systems may overlook through the correlation of data and pattern recognition. Predictive analytics can use historical attack data and global threat intelligence to anticipate potential threats to firewalls. This strategy helps organizations build passive defense capabilities, enhancing their prevention and response efforts while improving resource efficiency and response times. What Are the Future Directions and Potential Business Impacts? Automation, data processing, and regulatory requirements will continue to influence the development of artificial intelligence (AI) firewall solutions. As businesses face increasing demands for stringent control over confidential data and compliance with regulations, AI systems are becoming essential in navigating the complexities of cybersecurity landscapes. Future innovations are expected to involve a more profound examination of user intentions and application behaviors, thereby enhancing the efficacy of firewall solutions. With the rising dependence on cloud computing and edge networks, the architecture of AI firewall technology is evolving to become more geographically distributed and autonomous. For organizations, this evolution signifies enhanced protection and improved operational efficiency, while simultaneously reducing the overhead associated with security management. Consequently, this will foster greater digital resilience and instill a higher level of trust in technological solutions moving forward. ...Read more
inadvertently shared or exposed. Secure AI chat systems provide safeguards that prevent unauthorized data usage and maintain confidentiality. The need for internal productivity is driving adoption. Employees can use AI chat tools to automate routine tasks, generate insights, and access knowledge quickly, improving efficiency without compromising security. Technology Architecture and Security-Centric AI Design Secure AI chat solutions are built on advanced architectures that prioritize security, control, and scalability. These platforms integrate multiple layers of protection while delivering the capabilities of modern conversational AI. Enterprises often deploy AI chat solutions within their own infrastructure or secure cloud environments, ensuring full control over data and system operations. It reduces reliance on external platforms and minimizes exposure to security risks. Organizations can determine who has permit to access data, ensuring that sensitive information is only available to authorized users. The granular control enhances security and accountability. Data encryption is fundamental to secure AI chat systems. It is particularly important for organizations handling confidential or regulated information. Auditability and monitoring capabilities provide visibility into system usage. Enterprises can track interactions, monitor access patterns, and identify potential security threats in real time. It supports compliance requirements and strengthens risk management. Secure AI chat platforms connect with internal databases, knowledge management systems, and business applications while maintaining strict security controls. It enables seamless access to information without compromising data integrity. Strategic Implementation and Enterprise Value Creation For CEOs and business leaders, secure AI chat solutions represent a strategic investment that enables innovation while maintaining control and compliance. Successful implementation requires a comprehensive approach that aligns technology with organizational priorities. Clear policies must define how AI chat systems are used, what data can be accessed, and how risks are managed. It ensures consistent and secure adoption across the organization. Users must understand how to interact with AI systems responsibly, including guidelines for handling sensitive information. It reduces the risk of human error and enhances overall security. As organizations expand their use of AI, secure chat solutions must be able to handle increasing workloads and integrate with additional systems without compromising performance or security. Enterprises must choose providers that offer robust security features, compliance capabilities, and ongoing support to ensure long-term reliability. Technologies such as zero-trust security models, federated learning, and advanced encryption will further enhance the safety and effectiveness of these platforms. Secure AI chat solutions will continue to evolve with advancements in artificial intelligence, cybersecurity, and enterprise architecture. For leaders seeking to scale AI responsibly, these solutions are essential for achieving sustainable growth and maintaining trust in an increasingly digital world. ...Read more
The European cybersecurity community is increasingly struggling with the evolving and increasingly interconnected nature of digital environments and new methods of exploiting vulnerabilities. While traditional penetration testing remains valuable, manual testing can be time-consuming and may not sufficiently evaluate all potential attack paths. Organisations are thus looking into intelligent solutions that can test systems more continually and adjust to evolving risks. An autonomous AI pentesting platform signals a trend towards quicker security evaluations, extensive coverage, and more functional vulnerability management. How Are Autonomous Testing Tools Improving Security Assessments? AI is revolutionising the way security teams are detecting and assessing vulnerabilities. AI is transforming the way security teams are discovering and evaluating vulnerabilities. Intelligent testing systems can analyse applications, networks and configurations to discover potential weaknesses that warrant a closer look. Instead of waiting for an assessment, security controls can be analysed more frequently through automated testing and challenges identified sooner. Another capability that is gaining importance is attack path analysis. AI systems are capable of correlating individual weaknesses and figuring out how the attacker could proceed through the environment. Vulnerabilities presented in context assist security teams in prioritising vulnerabilities by their potential impact rather than by the finding's severity. The machine is also accelerating the testing process. Less manual effort is needed to gather information on exposed assets, ascertain available services and map potential entry points in systems. Security experts can then focus more time on examining complicated findings and determining the direction to take organisations. Which Trends Are Shaping AI-Powered Pentesting across Europe? Continuous testing has become a priority as organisations seek more effective protection against ever-evolving threats. Automated assessments can be performed in different settings to identify new vulnerabilities once software updates, configuration changes or infrastructure modifications have been made. Frequent testing will enable a more responsive security program, without the need to start from scratch with each test. There still needs to be human supervision. Security folks analyse results, confirm key results, and set remediation plans in motion. Incorporating automated analysis with human analysis can help to eliminate false alarms and still give attention to important vulnerabilities. The need for an independent AI-based pentesting platform underscores Europe's drive to enhance cybersecurity by leveraging intelligent automation. This is achieved through continuous testing, attack path analysis, human supervision and responsible data handling practices, to enable organisations to discover vulnerabilities early, enhance remediation efforts and bolster defences against the ever-evolving threat of digital attacks. ...Read more
Organisations across Europe are increasingly utilising cloud platforms, branch and remote offices, data centres, and connected devices, which has brought secure access gateway routing software to the forefront of discussions. Providing safe and efficient user and application access to resources is essential in these environments without introducing additional network complexity. Modern solutions successfully integrate secure access with smart routing. Organisations need to view networking and security as a unified set of processes rather than as separate components, allowing for more effective management through integrated architectures. How Is Secure Access Gateway Routing Software Being Applied? Software-defined routing can be used to link branches with corporate apps and cloud services, and to roll out the same policies for security. The intelligent routing can also be used to route traffic through appropriate network paths depending on the application. The businesses rely on private applications, public cloud environment, and software-as-a-service platform. Gateway routing software that is secure may be used to manage access to these resources, implement security policies and monitor access. Enterprises that operate in multiple cloud environments must be able to link users, applications and workloads reliably. Centralised routing and security controls can help to manage this complex environment more easily, while offering visibility of network activity. Industrial organisations can apply secure segmentation and controlled access to connect devices and operational systems and reduce unnecessary exposure over the broader network. IT teams can control routing policies, access control and security needs through a single platform instead of having to configure them in multiple locations. How Is the Technology Supporting Modern European Enterprises? The Zero Trust approach is fast becoming a key business application. Rather than granting access to the system automatically based on the fact that a user is on a corporate network, this could be done based on the system's assessment of identity, device attributes, application needs and other context data. Gateway technologies are able to monitor traffic, enforce Web access policies, recognise potentially harmful traffic, and manage employee access to Internet resources. This is especially helpful for organisations that have employees spread out across the country. Application-aware routing can detect various categories of traffic and choose suitable routes for the network according to the business needs and performance. This can enhance the availability of applications with low latency requirements like collaboration, voice, cloud and other applications. It can be used with remote work, branch connectivity, cloud access, multi-cloud, secure internet access, zero trust networking and connected operational systems. The smart routing, automated policy enforcement, access based on identity and integrated security will be more prevalent in the future. ...Read more

Weekly Brief