Ссылка
click to show
click to show
Unpatched UniFi Devices under attack
Summary
Per multiple users on reddit, Unifi devices not patched for the Security Advisory earlier this week had a Super Admin added within the last 12 hours with more users chiming in as regions wake up. Attackers appear to exfiltrate data via the UniFi backup feature once inside.
Quotes
Quote
u/k987654321: Hey guys can someone help me please. I’m away on holiday (in another country) and just had a notification that a Super Admin had been added to my account whilst I’ve been here.
I logged onto the UniFi iOS app and there was someone called John Sim in there. I promptly removed as you can see.
u/thetoxicnerve: I just had exactly the same happen on my UDR. Same username too "John Sim".
u/jeffporten: Confirming that we saw the same attack, same username. We've removed the b****** from the superuser list and inspected the logs
u/EagerCDNBeaver: I also just had the same thing on mine.
u/thomasrw1: Just had 2 sites with this user created (have a lot more sites that were fine).
u/ravicc: I got hit with this too. I was on Unifi OS 5.0.16. I got the update notification on Thursday. I delayed the update last night since I was travelling this week. So, I was on the previous version of the UniFiOS. I also noticed that there were multiple backups triggered. Not sure where these backups went and what they were attempting to do. And what sensitive information is in the backups.
My thoughts
It just goes to show how quickly a CVE goes from being announced as patched to being exploited. I actually would have likely been an attacked user myself had I not noticed the notification about the automatic update having failed. This is a developing situation so I'm sure there'll be updates about what specifically is stolen via backups along with other details over the next couple days. I'll add news agency sources as they become available.
Sources