CYBERSECURITY

Anthropic-Linked Vulnerability Exploited From China, Targets US and Japan

Anthropic-Linked Vulnerability Exploited From China, Targets US and Japan

How the Attack Unfolded

A critical authentication bypass in the open‑source Rejetto HTTP File Server (HFS) was recently used in the wild, with attackers originating from a Chinese IP address. The breach, which grants full administrative control and remote code execution, was first detected by security researcher VulnCheck and has since affected multiple servers across the United States and Japan.

The vulnerability, classified as CVE‑2023‑ , allows attackers to send specially crafted requests that circumvent HFS’s login mechanism. Once authenticated, the attacker can upload and execute arbitrary code, effectively taking over the compromised system. The exploit was identified in a series of log entries that revealed repeated attempts from a single IP block in China, targeting servers that had not applied the latest security patches.

What Does This Mean for Open‑Source Software Users?

Security logs show that the intrusion began on March 12th, when the attacker began probing for vulnerable HFS installations. By March 15th, the attacker had successfully bypassed authentication on at least five servers in the United States and three in Japan. The compromised servers were primarily small businesses and educational institutions that rely on HFS for file sharing. The attacker then uploaded malicious scripts that allowed remote control of the servers, potentially enabling data exfiltration or further lateral movement within the victim networks.

VulnCheck’s analysis indicates that the attacker used a custom payload that exploited a flaw in HFS’s session handling. The payload was designed to trigger a buffer overflow, which the attacker used to inject shellcode. Once the shellcode executed, the attacker gained a root shell on the affected machines. The attack chain was short and efficient, suggesting that the attacker had prepared the exploit in advance and was targeting known, unpatched systems.

Is China the Primary Source of Cyber Attacks on HFS?

The incident highlights the ongoing risk posed by outdated open‑source components. HFS, while popular for its lightweight design, has a history of security issues that have not been fully addressed. The recent exploit demonstrates that even well‑known vulnerabilities can be weaponized if patches are not applied promptly. Organizations that rely on HFS should verify that they are running the latest version and consider disabling unnecessary services. Regular vulnerability scanning and timely patch management remain essential defenses against such attacks.

Frequently Asked Questions

The IP address from which the attacks originated was registered in China, but this does not conclusively prove state sponsorship. Cybercriminals often use compromised machines worldwide to mask their true location. However, the sophistication of the exploit and the targeted nature of the attacks suggest a level of expertise that could be associated with organized threat actors. Security analysts are monitoring the situation closely, and further investigations may reveal whether this incident is part of a larger campaign.

The consequences for affected organizations include potential data loss, system downtime, and reputational damage. In the long term, this breach underscores the need for comprehensive security strategies that include continuous monitoring, rapid incident response, and a proactive approach to patch management. As open‑source software continues to be widely adopted, the importance of maintaining secure configurations cannot be overstated.

Content written by Priya Nair for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment