Threat Advisory: DifyTap Vulnerabilities
UltraViolet TIDE covers 4 DifyTap CVEs including 2 criticals (CVSS 9.4, 9.1) in Dify's LLM Ops platform. Learn what's at risk and how to respond now.
Find flaws in AI Systems
Find flaws in web, mobile, and IoT applications.
Live-fire exercises to sharpen detection and response.
Time-boxed security assessments across networks, apps, and infrastructure.
Simulated attacks to test detection and incident response.
Named security experts integrated seamlessly into your team.
Real-time detection and automated threat response.
24x7 monitoring and response by expert analysts.
Detection-focused SIEM migration without visibility gaps.
UltraViolet's proprietary AI platform powering all application penetration testing.
Unified security platform powering all UV services.
Cross-platform toolkit for advanced red team ops.
UltraViolet Cyber provides security services across the AI lifecycle, combining strategy, threat modeling, adversarial testing, monitoring, and training to support secure AI adoption.
Learn how a major U.S. airport operator achieved 24/7 threat detection, improved security maturity, and ...
Secure your code, infrastructure, and deployment pipelines before attackers exploit them.
Three-quarters of companies have an AI policy. Few have a governance program. Here's why the NIST AI RMF is the framework to ...
AI Governance by DesignAn Architecture-Aware Approach for Embedding Governance into AI Systems
UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients. Built by former intelligence operators, we unify application security, red teaming, detection, and engineering under one roof. Our UV Lens platform replaces silos with integrated, outcome-driven operations.
UltraViolet Cyber
The Cybersecurity and Infrastructure Security Agency (CISA) released an advisory on April 24, 2024, regarding actively exploited vulnerabilities within Cisco’s ASA and FTD software. A new Advanced Persistent Threat (APT) group classified as UAT4356 by Talos and STORM-1849 by the Microsoft Threat Intelligence Center was also nicknamed “ArcaneDoor” by researchers earlier this year. ArcaneDoor could take control of a Cisco ASA or FTD system by exploiting three new CVEs: CVE-2024-20353 (CVSS score 8.6), CVE-2024-20359 (CVSS score 6.0), and CVE-2024-20358 (CVSS score 6.0). Cisco has released free software updates for these vulnerabilities. CISA has reported that this vulnerability has been observed to be actively exploited in the wild. CISA strongly recommends affected Cisco customers apply the patches as quickly as their patch policy allows.
CVE-2024-20353 (CVSS score 8.6) is a Web Services Denial of Service Vulnerability. An unauthenticated threat actor could remotely reload the Cisco ASA or FTD software. By repeating this exploit, the management and VPN servers would suffer a denial of service (DoS) outage. Threat actors would exploit this vulnerability by sending specially generated HTTP requests to the publicly exposed service. This is one of two zero-day vulnerabilities that have been exploited by threat actors, including ArcaneDoor.
ArcaneDoor is believed to be a state-sponsored cyber espionage group. While researchers are still unsure of the initial intrusion method, backdoors “Line Runner” and “Line Dancer” were observed during campaigns associated with this threat group. Wired reported on this campaign and indicated that this activity appears to align with China’s state interests.
CVE-2024-20359 (CVSS score 6.0) is a Persistent Local Code Execution Vulnerability. A preloading of plug-ins and clients could allow unauthenticated local threat actors to execute code with root-level access. The exploit would require already compromised administrator-level access. This vulnerability was caused by improper file validation when read from system flash memory. Threat actors could load a file to disk0 on the file system. Upon the next device reload, the code would be executed. The vulnerability associated with CVE-2024-20358 (CVSS score 6.0) behaves much in the same way but for Linux operating systems.
Cisco Adaptive Security Appliance and Firepower Threat Defense . (2024, April 24). Retrieved April 25,
2024, from https://sec.cloudapps.cisco.com
Cisco Adaptive Security Appliance and Firepower Threat Defense . (2024, April 24). Retrieved April 25,
2024, from https://sec.cloudapps.cisco.com
Cisco Adaptive Security Appliance and Firepower Threat Defense . (2024, April 24). Retrieved April 25,
2024, from https://sec.cloudapps.cisco.com
Cisco Releases Security Updates Addressing ArcaneDoor . (2024, April 24). Retrieved April 25, 2024,
from https://www.cisa.gov/news-events/alerts/2024/04/24/cisco-releases-security-updates-addressing-arcanedoor-vulnerabilities-cisco-firewall-platform
Cisco Software Checker. Retrieved April 25, 2024, from
https://sec.cloudapps.cisco.com
Greig, J. CISA: Cisco and CrushFTP vulnerabilities are being actively exploited. (2024, April 24).
Retrieved April 25, 2024, from https://therecord.media/cisco-asa-crushftp-vulnerabilities-exploited-cis
NCSC TIP Line Runner. (2024, April 24). Retrieved April 25, 2024, from https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/line/ncsc-tip-line-runner.pdf
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.