Foxit Domain Hijacking
The agency warned that four of the vulnerabilities in foxit reader and phantompdf for windows feature a high severity rating.
Foxit domain hijacking. Submit malware for free analysis with falcon sandbox and hybrid analysis technology. Several vulnerabilities affecting foxit products were also mentioned this week in a vulnerability summary bulletin published by the u s. Following shortly after the io domain cock up that left thousands vulnerable to domain hijacking this week more than 750 domains were jacked.
Hybrid analysis develops and licenses analysis tools to fight malware. Cybersecurity and infrastructure security agency cisa. Hijacking the camera s wire will not help attackers gain access to the company s network.
At the same time you protect the information on the network from exfiltration. The hackers only intercepted credentials for 9 users and a total of 12 files none of the files were marked as secret and did not contain sensitive information. In each case the attackers gained access to and changed dns domain name system records of the victim organizations so their internet traffic was routed through attacker controlled servers.
More than 750 domain names were hijacked through the internet s own systems registrar gandi has admitted. The attacker initially modified a dns record for one particular server to point to a server in their possession and to intercept and forward the traffic to the original server that belongs to fox it. Zero day vulnerabilities discovered in foxit pdf reader the first vulnerability cve 2017 10951 was discovered by researcher ariele caltabiano and is a command injection bug and the second vulnerability cve 2017 10952 was discovered by steven seeley an offensive security researcher and is a file write issue.
The bugs are tracked as cve 2020 26534 cve 2020 26539 cve 2020 26537 and cve 2020 26535 and have a cvss score of 7 5. Installing a fox datadiode between cameras and the recording station will enable you to securely send footage to the recording station.