Faculty of Engineering and Architecture - mmf@gelisim.edu.tr
03 February 2023 Friday
Hackers use Mitel VoIP Zero-day in potential ransomware attack
A suspected ransomware attack against an anonymous target exploited a Mitel VoIP device as an entry point to perform remote code execution and provide initial access to the environment. The findings come from cybersecurity firm CrowdStrike, which traced the source of the attack to a Linux-based Mitel VoIP device located in the network perimeter, while also identifying a previously unknown exploit, as well as several actor-adopted forensics measures.
To remove traces of their actions, on the device, the exploit is tracked as CVE-2022-29499 and was fixed by Mitel in April 2022. It is rated 9.8 out of 10 for severity in the CVSS vulnerability scoring system, making it a critical shortcoming. "A vulnerability has been identified in the Mitel Service Appliance component of MiVoice Connect (Mitel Service Appliances – SA 100, SA 400 and Virtual SA) that could allow a malicious actor to execute remote code (CVE-2022-29499). In the Service Appliance context," the company stated in an advisory. This exploit required two HTTP GET requests used to retrieve a specific resource from a server, triggering remote code execution by fetching rogue commands from the attacker-controlled infrastructure.
The unmanned agricultural aircraft IGU ZİHA-01, developed by Istanbul Gelisim University (IGU), was exhibited at MÜSİAD Expo-24 fair and attracted the intense attention of the ...
Prof. Bahri Sahin, the rector of Istanbul Gelisim University (IGU), paid a visit to the office of Prof. Necip Simsek, who was recently appointed as ...
International Exchange and Cooperation Office of Istanbul Gelisim University recently held a significant collaboration meeting as part of the "Korean Language Dissemination Education" project, supported ...
Istanbul Gelisim University (IGU) continues its international collaborations with the aim of strengthening its academic ties with the Turkish world. In this regard, an important ...
Istanbul Gelisim University (IGU) Technology Transfer Office (TTO) participated actively in the MUSIAD EXPO 2024 Fair held in TÜYAP last week. The participation certificate given ...
Istanbul Gelisim University participated in the European Institute of Innovation and Technology (EIT) Deep Tech Talent Days held on November 12-13, 2024, delivering strong international ...
Istanbul Gelisim University (IGU) Technology Transfer Office (TTO), which stands out with its many projects and collaborations in scientific and technological fields, continues its activities. ...
MUSIAD Expo 2024 Fair has started. IGU Technology Transfer Office (TTO) participated in the fair held in Tüyap between 26-29 November. İGÜ TTO's innovative unmanned ...
Bezmialem Vakıf University Fatih Campus hosted a breakfast meeting where Technology Transfer Offices (TTO) and TEKMER managers in Istanbul came together. During the meeting, the ...
The US-based "Accreditation Board for Engineering and Technology" (ABET) Committee, a non-profit and independent non-governmental organization that evaluates engineering faculties, visited Istanbul Gelisim University between ...