Experts Alert Linear eMerge E3 Systems to a Serious Unpatched Vulnerability

An unpatched flaw in Nice Linear eMerge E3 access controller systems could enable the execution of arbitrary operating system (OS) commands, according to cybersecurity security researchers.

According to VulnCheck, the vulnerability, which has been given the CVE identifier CVE-2024-9441, has a CVSS score of 9.8 out of a possible 10.0.

“A vulnerability in the Nortek Linear eMerge E3 allows remote unauthenticated attackers to cause the device to execute arbitrary command,” SSD Disclosure said in an advisory for the flaw released late last month, stating the vendor has yet to provide a fix or a workaround.

The following Nortek Linear eMerge E3 Access Control versions are affected by the defect: 1.00.05 and 1.00.07, 0.32-03i, 0.32-04m, 0.32-05p, 0.32-05z, 0.32-07p, 0.32-07e, 0.32-08e, 0.32-08f, 0.32-09c, and 1.00.05.

After being made public, proof-of-concept (PoC) exploits for the vulnerability were made available, which sparked worries that threat actors might take advantage of it.

Notably, a threat actor called Flax Typhoon used another critical vulnerability that affected E3, CVE-2019-7256 (CVSS score: 10.0), to enlist vulnerable devices into the now-demolished Raptor Train botnet.

Even though the issue was first revealed in May 2019, the company didn’t fix it until earlier this March.

“But given the vendor’s slow response to the previous CVE-2019-7256, we don’t expect a patch for CVE-2024-9441 any time soon,” VulnCheck’s Jacob Baines said. “Organizations using the Linear Emerge E3 series should act quickly to take these devices offline or isolate them.”

According to a statement provided to SSD Disclosure, Nice advises users to adhere to security best practices, which include limiting internet access to the product, implementing network segmentation, and setting it up behind a network firewall.

Microsoft and the US Take Control of 107 Russian Domains in a Large-Scale Cyberfraud Raid

On Thursday, Microsoft and the US Department of Justice (DoJ) announced the seizure of 107 domains from state-sponsored threat actors connected to Russia, which were being used to enable computer fraud and abuse within the nation.

“The Russian government ran this scheme to steal Americans’ sensitive information, using seemingly legitimate email accounts to trick victims into revealing account credentials,” stated Lisa Monaco, Deputy Attorney General.

Threat actor COLDRIVER, also known as Blue Callisto, BlueCharlie (or TAG-53), Calisto (sometimes spelled Callisto), Dancing Salome, Gossamer Bear, Iron Frontier, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, has been linked to the activity.

The group has been operational since at least 2012 and is considered to be part of Center 18 of the Russian Federal Security Service (FSB).

Two group members, Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets, were sanctioned by the US and UK governments in December 2023 for their spear-phishing and malicious credential harvesting activities. The same two people were then subject to sanctions by the European Council in June 2024.

According to the Department of Justice, threat actors were using the recently taken over 41 domains to “commit violations of unauthorized access to a computer to obtain information from a department or agency of the United States, unauthorized access to a computer to obtain information from a protected computer, and causing damage to a protected computer.”

The domains are purportedly part of a spear-phishing campaign that targets the email accounts of the federal government of the United States and other victims in an attempt to obtain credentials and important information.

In addition, Microsoft announced that it had filed a corresponding civil action to take control of 66 more internet domains that COLDRIVER had been using to target more than 30 civil society organizations and entities between January 2023 and August 2024.

This includes think tanks and NGOs that assist government workers, military personnel, and intelligence officials, especially those who aid Ukraine and other NATO nations like the U.K. and the U.S. Access Now and the Citizen Lab previously documented COLDRIVER’s targeting of NGOs in August 2024.

New Zealand Women vs. India Women: A Growing Rivalry in Women’s Cricket

Over the past ten years, women’s cricket has experienced tremendous growth in terms of popularity and skill. The match between the Indian women’s cricket team and the New Zealand women’s team has been one of the most thrilling in recent memory. Fans are treated to exciting matches that highlight the advancement of women’s cricket on the global scene each time these two teams play.

Historical Context

India and New Zealand have historically been strong rivals in the women’s cricket league. Both sides have a long history of turning out elite players and have participated in prestigious competitions such as the T20 World Cup and the ICC Women’s World Cup. New Zealand has always been one of the stronger teams, especially in the early years of women’s international cricket, even though India has gained popularity more recently due to increased investment in women’s cricket.

In the past, New Zealand has typically prevailed over India in their interactions, but recently, the tide has started to turn. India’s younger players, including Shafali Verma and Smriti Mandhana, have given the team new life and increased their threat level on the international scene.

Memorable Matches

Some of the recent clashes between these two sides have been high-octane affairs, particularly in the limited-overs formats.

1. 2017 ICC Women’s World Cup

In one of the pivotal matches of the 2017 Women’s World Cup, India faced New Zealand in a virtual knockout game. India, led by a masterclass century from Mithali Raj, posted a competitive total. New Zealand, in reply, crumbled under pressure, with India winning the match comprehensively. This win propelled India to the semi-finals and highlighted the growing strength of Indian women’s cricket.

2. 2022 Women’s Cricket World Cup

In a closely fought encounter during the 2022 ICC Women’s Cricket World Cup, New Zealand emerged victorious against India by 62 runs. New Zealand’s Amelia Kerr played a stellar all-round game, scoring 50 runs and taking crucial wickets to break India’s back. India struggled to chase the total, with their batters failing to build substantial partnerships. The match was a reminder of New Zealand’s tenacity and ability to perform in pressure situations.

Key Players to Watch

1. Sophie Devine (New Zealand)

A powerful hitter and exceptional leader, Sophie Devine has been one of the pillars of New Zealand women’s cricket. Known for her aggressive batting style, Devine is a match-winner on her day and can change the course of a game with both bat and ball.

2. Amelia Kerr (New Zealand)

Amelia Kerr is a rising star in world cricket. At a young age, she’s already made a name for herself with her all-round performances. Her leg-spin and solid batting make her a key player in New Zealand’s lineup.

3. Smriti Mandhana (India)

Smriti Mandhana has been the face of Indian women’s cricket for several years now. Her ability to dominate bowling attacks with elegant stroke play and her consistency at the top of the order make her a vital part of India’s lineup.

4. Harmanpreet Kaur (India)

Known for her explosive batting and remarkable leadership, Harmanpreet Kaur is a player who thrives under pressure. Her century in the 2017 World Cup semi-final is still regarded as one of the greatest innings in women’s cricket history.

The Rivalry Today

As women’s cricket continues to evolve, so does the rivalry between New Zealand and India. The two teams now stand shoulder-to-shoulder in terms of talent and performance. Both teams have their eyes on major ICC tournaments, and each encounter between them is seen as a potential preview of key matchups in the knockout stages of global events.

Off the field, the visibility of women’s cricket has grown, and matchups like New Zealand vs. India are crucial in driving the sport’s popularity. With players like Sophie Devine, Amelia Kerr, Smriti Mandhana, and Harmanpreet Kaur leading their respective teams, the competition between these two nations is fiercer than ever.

Conclusion

India vs. The New Zealand Women The rivalry between women is becoming more and more exciting. Due to the talent on both sides, cricket fans everywhere can expect an exciting game of cricket during these matches. Matches like these will be crucial to the future of women’s cricket as the sport continues to grow internationally and inspire the upcoming generation of cricket players and fans.

Watch this space for more fireworks as these two teams continue their global rivalry!