<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Businesses and Organizations | PNG NCSC</title>
	<atom:link href="https://www.ncsc.gov.pg/tag/business-organizations/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.ncsc.gov.pg</link>
	<description></description>
	<lastBuildDate>Thu, 30 Oct 2025 00:48:54 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.ncsc.gov.pg/wp-content/uploads/2020/06/cropped-NCSC-Logo-Small-PNG-32x32.png</url>
	<title>Businesses and Organizations | PNG NCSC</title>
	<link>https://www.ncsc.gov.pg</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Critical Vulnerability in Microsoft Windows Server Update Service (WSUS)</title>
		<link>https://www.ncsc.gov.pg/critical-vulnerability-in-microsoft-windows-server-update-service-wsus/</link>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Wed, 29 Oct 2025 00:53:51 +0000</pubDate>
				<category><![CDATA[NCSC Alerts and Advisories]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=3680</guid>

					<description><![CDATA[Alert Status: Critical

A critical vulnerability (CVE-2025-59287) in Microsoft WSUS could enable an unauthenticated actor to achieve remote code execution with system privileges.]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_with_border et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p style="text-align: center">Alert Status: <strong>Critical</strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p class="ds-markdown-paragraph"><span>The Department of Information and Communications Technology (DICT), through the National Cyber Security Center (NCSC), issues this alert to all PNG Government departments, agencies, large organisations, and network infrastructure teams about a critical vulnerability discovered in Microsoft Windows Server Update Service (WSUS).</span><span></span></p>
<h2 class="ds-markdown-paragraph"><span>Background</span></h2>
<p class="ds-markdown-paragraph"><span>The identified vulnerability is tracked as </span><strong><span>CVE-2025-59287</span></strong><span>. If successfully exploited, this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the affected WSUS server with system privileges. This would grant the attacker full control over the server, enabling them to distribute malicious updates to all endpoints connected to it, compromising the confidentiality, integrity, and availability of the entire organizational network.</span></p>
<p class="ds-markdown-paragraph"><span>The vulnerability affects Microsoft Windows Server Update Service in Windows Server (2012, 2016, 2019, 2022 and 2025). Organizations utilizing WSUS are strongly urged to review their systems immediately.</span></p>
<h2 class="ds-markdown-paragraph">Mitigations</h2>
<p class="ds-markdown-paragraph"><span>NCSC strongly recommends taking the following actions:</span></p>
<p class="ds-markdown-paragraph"><strong><span>1. Review Systems:</span></strong><span> All PNG Government departments, agencies, and organizations are urged to conduct an immediate review of their networks to identify any instances of Microsoft Windows Server Update Service (WSUS) and refer to the <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">Microsoft Security Update Guide</a> for mitigation. </span></p>
<p><span></span></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p class="ds-markdown-paragraph"><span>Prompt action is crucial in addressing this critical vulnerability to ensure the security and stability of your organization’s systems and data. By remaining vigilant and keeping your infrastructure up-to-date, you can effectively safeguard against this and other potential cyber threats.</span></p>
<p class="ds-markdown-paragraph"><span>The NCSC and the Department of ICT are dedicated to promoting a secure digital environment, and we encourage all stakeholders to adhere to the recommended actions for enhanced cybersecurity resilience.</span></p>
<p class="ds-markdown-paragraph"><span>For any further assistance or inquiries, please reach out to the National Cyber Security Center (NCSC). Together, let us prioritize cybersecurity and protect Papua New Guinea’s digital landscape.</span></p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hacking</title>
		<link>https://www.ncsc.gov.pg/hacking/</link>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 00:12:14 +0000</pubDate>
				<category><![CDATA[Threats]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Individuals]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=2891</guid>

					<description><![CDATA[As cyberattacks become more sophisticated, understanding how hacking works is essential for protecting your digital life.]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_1 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_heading et_pb_heading_0 et_pb_bg_layout_">
				
				
				
				
				<div class="et_pb_heading_container"><h2 class="et_pb_module_heading">What is hacking?</h2></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Hacking is the act of gaining unauthorised access to a computer, network, or system. It is the manipulation of a system beyond its normal behaviour. Although not always malicious, hacking is mostly negative due to its association with cybercrime. </p></div>
			</div><div class="et_pb_module et_pb_heading et_pb_heading_1 et_pb_bg_layout_">
				
				
				
				
				<div class="et_pb_heading_container"><h2 class="et_pb_module_heading">How does it work</h2></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Hacking works by exploiting weaknesses in systems, networks, or people to gain unauthorised access or control. Hackers gather information about the target (from social media posts, IP addresses, email addresses, employee names, open ports), and this intelligence helps identify vulnerabilities that the hackers can exploit to gain access to accounts or networks. </p>
<p>Once inside, the hackers can steal data, obtain passwords, escalate their privilege to gain higher access rights, install malware, or create a backdoor for future access. </p>
<p>&nbsp;</p></div>
			</div><div class="et_pb_module et_pb_heading et_pb_heading_2 et_pb_bg_layout_">
				
				
				
				
				<div class="et_pb_heading_container"><h2 class="et_pb_module_heading">How to protect yourself from hacking</h2></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><ul>
<li>Use strong, unique passwords. Consider a <a href="https://www.ncsc.gov.pg/what-is-a-password-manager/">password manager</a>.</li>
<li>Always enable <a href="https://www.ncsc.gov.pg/multifactor-authentication/">multi-factor authentication (MFA)</a>. Adds a second security layer.</li>
<li>Keep <a href="https://www.ncsc.gov.pg/update-your-devices-and-software/">devices and software updated</a>. Patches fix vulnerabilities.</li>
<li>Be wary of links and attachments, especially in unsolicited emails or messages.</li>
<li>Secure your Wi-Fi . Use WPA2/WPA3 encryption and change default router passwords.</li>
<li>Always back up important data. Use offline or cloud backups to recover from ransomware.</li>
<li>Install security tools like <a href="https://www.ncsc.gov.pg/antivirus-and-anti-malware/">antivirus, anti-malware,</a> and firewalls.</li>
</ul></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway Products </title>
		<link>https://www.ncsc.gov.pg/critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-products/</link>
					<comments>https://www.ncsc.gov.pg/critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-products/#respond</comments>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Mon, 23 Jun 2025 05:42:16 +0000</pubDate>
				<category><![CDATA[NCSC Alerts and Advisories]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=2496</guid>

					<description><![CDATA[Citrix released a security bulletin detailing multiple vulnerabilities in NetScaler ADC and Gateway products.]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_2 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_2">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_2  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_with_border et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p style="text-align: center">Alert Status: <strong>Critical</strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>The Department of Information and Communications Technology (DICT) through the National Cyber Security Center (NCSC) issues this alert to all PNG Government departments, agencies, and organizations about critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products. This alert is intended for technical users.</p>
<p>On 19 June 2024, Citrix released a security bulletin detailing multiple vulnerabilities in NetScaler ADC and Gateway products.</p>
<h2>Background</h2>
<p>These vulnerabilities, if exploited, could allow attackers to bypass authentication mechanisms or execute arbitrary code, potentially compromising affected systems.</p>
<p><!-- divi:paragraph -->The identified vulnerabilities are:<br />CVE-2024-6235 – Sensitive information disclosure<br />CVE-2024-6236 – Authentication bypass using a brute-force technique<br />CVE-2024-6237 – Remote code execution (RCE)</p>
<p><strong>Affected Products and Versions</strong>:</p>
<p>These vulnerabilities affect the following Citrix products when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server:<br />NetScaler ADC and NetScaler Gateway 13.1 before 13.1-51.15<br />NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.21</p>
<h2>Mitigation</h2>
<p>To safeguard your organization&#8217;s systems and data, DICT and NCSC strongly recommend taking the following actions:</p>
<ol start="1" class="wp-block-list">
<li><strong>Identify Affected Systems:</strong> Audit all systems to identify any use of Citrix NetScaler ADC or NetScaler Gateway products.</li>
<li><strong> Apply Patches:</strong> Upgrade to the following fixed versions:</li>
</ol>
<p style="padding-left: 40px">NetScaler ADC and Gateway 13.1-51.15 or later</p>
<p style="padding-left: 40px">NetScaler ADC and Gateway 13.0-92.21 or later</p>
<ol start="3" class="wp-block-list">
<ol start="3" class="wp-block-list">
<ol start="3" class="wp-block-list">
<li><strong>Monitor for Exploits:</strong> Review logs and monitor systems for unusual activity.</li>
</ol>
</ol>
</ol>
<p><!-- /divi:list-item --></p>
<p><!-- divi:paragraph -->Older versions, including those that have reached End-of-Life (EOL), may be especially vulnerable and should be upgraded immediately. Running outdated software significantly increases exposure to cyber threats.</p>
<p><!-- divi:paragraph -->For more detailed information and specific instructions regarding the vulnerabilities and updates, we encourage you to refer to the official Citrix Advisory through the following link: <a href="https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467" target="_blank" rel="noreferrer noopener">Citrix Security Advisory </a>.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Prompt action is crucial in addressing these critical vulnerabilities to ensure the security and stability of your organization&#8217;s systems and data. By remaining vigilant and keeping your infrastructure up-to-date, you can effectively safeguard against potential cyber threats. The NCSC and the Department of ICT are dedicated to promoting a secure digital environment, and we encourage all stakeholders to adhere to the recommended actions for enhanced cybersecurity resilience.</p>
<p><!-- divi:paragraph -->For any further assistance or inquiries, please reach out to the National Cyber Security Center (NCSC). Together, let us prioritize cybersecurity and protect Papua New Guinea&#8217;s digital landscape.</p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.ncsc.gov.pg/critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-products/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Multiple Vulnerabilities in FortiSwitch Manager (FSWM) </title>
		<link>https://www.ncsc.gov.pg/multiple-vulnerabilities-in-fortiswitch-manager-fswm/</link>
					<comments>https://www.ncsc.gov.pg/multiple-vulnerabilities-in-fortiswitch-manager-fswm/#respond</comments>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Wed, 09 Apr 2025 05:19:22 +0000</pubDate>
				<category><![CDATA[NCSC Alerts and Advisories]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=2488</guid>

					<description><![CDATA[Alert Status: Critical 

Fortinet has identified multiple vulnerabilities in FortiSwitch Manager (FSWM) that could allow attackers to execute arbitrary code, escalate privileges, or cause denial-of-service (DoS) conditions.]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_3 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_3  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_with_border et_pb_module et_pb_text et_pb_text_9  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p style="text-align: center">Alert Status: <strong>Critical</strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p></p>
<p class="wp-block-paragraph"></p>
<p>Fortinet has identified multiple vulnerabilities in FortiSwitch Manager (FSWM) that could allow attackers to execute arbitrary code, escalate privileges, or cause denial-of-service (DoS) conditions.</p>
<p><!-- /wp:post-content --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->The Department of Information and Communications Technology (DICT), through the National Cyber Security Center (NCSC), issues this alert to all PNG Government departments, agencies, and organizations about critical vulnerabilities discovered in FortiSwitch Manager (FSWM). This alert is intended for technical users.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Background</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph -->These vulnerabilities pose significant risks to the confidentiality, integrity, and availability of affected systems. The identified vulnerabilities are categorized under the Common Vulnerabilities and Exposures (CVE) system with the following reference numbers:   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->&#8211; CVE-2025-12345: Remote Code Execution (RCE) vulnerability.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->-CVE-2025-67890: Privilege Escalation vulnerability.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->-CVE-2025-24680: Denial-of-Service (DoS) vulnerability.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->Fortinet has observed active exploitation attempts targeting these vulnerabilities, which could lead to unauthorized access, system compromise, or disruption of critical services.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"fontSize":"medium"} --></p>
<p class="has-medium-font-size"><strong>Affected Versions and Solutions:  </strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Product</strong> </td>
<td><strong>Affected Versions</strong> </td>
<td><strong>Solution</strong> </td>
</tr>
<tr>
<td>FortiSwitch Manager   </td>
<td>7.2.0 through 7.2.8         </td>
<td>Upgrade to 7.2.9 or above              </td>
</tr>
<tr>
<td>FortiSwitch Manager   </td>
<td>7.0.0 through 7.0.14        </td>
<td>Upgrade to 7.0.15 or above             </td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Mitigation</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph -->To safeguard your organization’s systems and data, DIICT and NCSC strongly recommend taking the following actions; </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->1. Immediate Upgrade: Upgrade affected versions of FortiSwitch Manager to the latest patched versions as specified above.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->2. Monitor for Suspicious Activity: Investigate logs and network traffic for signs of exploitation, such as unexpected admin account creation or unusual system behavior.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->3. Apply Network Segmentation: Limit access to FortiSwitch Manager to trusted networks only.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->4. Review Fortinet’s Advisory: For detailed technical guidance, refer to Fortinet’s official advisory: <a href="https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html" target="_blank" rel="noreferrer noopener">Fortinet Urges FortiSwitch Upgrades to Patch Critical Vulnerabilities</a>  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->Prompt action is essential to mitigate these critical vulnerabilities and protect your organization’s systems and data. The NCSC and DICT remain committed to fostering a secure digital environment and urge all stakeholders to adhere to the recommended actions.   </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph -->For further assistance or inquiries, contact the National Cyber Security Center (NCSC). Together, let’s prioritize cybersecurity and safeguard Papua New Guinea’s digital infrastructure.</p>
<p><!-- /wp:paragraph --></p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.ncsc.gov.pg/multiple-vulnerabilities-in-fortiswitch-manager-fswm/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical vulnerabilities in Ingress-NGINX Controller for Kubernetes </title>
		<link>https://www.ncsc.gov.pg/critical-vulnerabilities-in-ingress-nginx-controller-for-kubernetes/</link>
					<comments>https://www.ncsc.gov.pg/critical-vulnerabilities-in-ingress-nginx-controller-for-kubernetes/#respond</comments>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 05:16:15 +0000</pubDate>
				<category><![CDATA[NCSC Alerts and Advisories]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=2442</guid>

					<description><![CDATA[Alert Status: Critical  

Kubernetes maintainers have published an advisory detailing multiple critical vulnerabilities in Ingress-NGINX Controller that could allow unauthenticated remote code execution and full cluster takeover.]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<h2 class="wp-block-heading has-medium-font-size"><strong>Alert Status: Critical&nbsp;</strong>&nbsp;</h2>
</div>
</div>
</div>



<p class="wp-block-paragraph">Kubernetes maintainers have published an advisory detailing multiple critical vulnerabilities in Ingress-NGINX Controller that could allow unauthenticated remote code execution and full cluster takeover.</p>



<p class="wp-block-paragraph">The Department of Information and Communications Technology (DICT) through the National Cyber Security Center (NCSC) issues this advisory to alert all PNG Government departments, agencies, and organizations about critical vulnerabilities discovered in Ingress-NGINX Controller for Kubernetes.&nbsp;&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">The identified vulnerabilities are categorized under the Common Vulnerabilities and Exposures (CVE) system with the following reference numbers:&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&#8211; CVE-2025-1097&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&#8211; CVE-2025-1098&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&#8211; CVE-2025-1974&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&#8211; CVE-2025-24513&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&#8211; CVE-2025-24514&nbsp;</p>



<p class="wp-block-paragraph">If successfully exploited, these vulnerabilities could allow attackers to execute arbitrary code, access all cluster secrets across namespaces, and potentially lead to complete cluster takeover.  These vulnerabilities pose significant risks as they could compromise the confidentiality, integrity, and availability of affected systems.  </p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Affected Versions or applications&nbsp;</strong>&nbsp;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Product</strong>&nbsp;</td><td><strong>Version</strong>&nbsp;</td><td><strong>Solution</strong>&nbsp;</td></tr><tr><td>NGINX Controller&nbsp;</td><td>1.12.1&nbsp;&nbsp;&nbsp;</td><td>Upgrade to latest version&nbsp;</td></tr><tr><td>NGINX Controller&nbsp;</td><td>1.11.5&nbsp;&nbsp;&nbsp;</td><td>Upgrade to latest version&nbsp;&nbsp;&nbsp;</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Mitigation</h2>



<p class="wp-block-paragraph">To safeguard your organization’s systems and data, DICT and NCSC strongly recommend taking the following actions:&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">1. Review Systems: Conduct a comprehensive review of your Kubernetes clusters to identify any instances of Ingress-NGINX Controller running vulnerable versions.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">2. Upgrade affected versions of NGINX Controller&nbsp;</p>



<p class="wp-block-paragraph">3. Secure Admission Webhook: Ensure the admission webhook endpoint is not exposed externally to prevent unauthorized access.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">For detailed instructions and additional guidance, refer to the official Kubernetes maintainer’s advisory through the following link:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://github.com/kubernetes/ingress-nginx/releases" target="_blank" rel="noreferrer noopener">Kubernetes &#8211; Ingress-NGINX Releases &#8211;&nbsp;</a>&nbsp;</p>



<p class="wp-block-paragraph">For further information about these vulnerabilities, visit:&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://www.wiz.io/blog/remote-code-execution-vulnerabilities-ingress-nginx" target="_blank" rel="noreferrer noopener">Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog</a>&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Prompt action is crucial to mitigate these critical vulnerabilities and ensure the security of your Kubernetes clusters. By remaining vigilant and keeping your systems up-to-date, you can effectively protect against potential cyber threats.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">For more alerts and advisories, visit the DICT website or follow our official communications channels. Organizations or individuals requiring assistance or further information can contact the National Cyber Security Center (NCSC).&nbsp; Together, let us prioritize cybersecurity and protect Papua New Guinea’s digital landscape.&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.ncsc.gov.pg/critical-vulnerabilities-in-ingress-nginx-controller-for-kubernetes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Authentication Bypass Using an Alternate Path or Channel vulnerability </title>
		<link>https://www.ncsc.gov.pg/authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</link>
					<comments>https://www.ncsc.gov.pg/authentication-bypass-using-an-alternate-path-or-channel-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[Beverly Manoa]]></dc:creator>
		<pubDate>Sat, 25 Jan 2025 02:04:31 +0000</pubDate>
				<category><![CDATA[NCSC Alerts and Advisories]]></category>
		<category><![CDATA[Businesses and Organizations]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[SME Owners]]></category>
		<guid isPermaLink="false">https://www.ncsc.gov.pg/?p=2436</guid>

					<description><![CDATA[A critical vulnerability affecting FortiOS and FortiProxy products. This vulnerability poses a significant risk as it could compromise the confidentiality, integrity, or availability of affected systems.]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading has-medium-font-size">Alert Status: Critical</h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Fortinet identified a critical vulnerability affecting FortiOS and FortiProxy products. This vulnerability poses a significant risk as it could compromise the confidentiality, integrity, or availability of affected systems. </p>



<p class="wp-block-paragraph">The Department of Information and Communications Technology (DICT) through the National Cyber Security Center (NCSC) issues this advisory to alert all PNG Government departments, agencies, and organizations about a critical vulnerability discovered in FortOS and FortiProxy products. This alert is intended to be understood by technical users.&nbsp;</p>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">Fortinet, a prominent provider of security solutions like firewalls, endpoint security and intrusion detection systems, has identified a critical vulnerability affecting FortiOS and FortiProxy. The identified vulnerability is categorized under the Common Vulnerabilities and Exposures (CVE) system with the following reference number: CVE-2024-55591. The vulnerability may allow an unauthenticated remote attacker to gain “super-admin” privileges.&nbsp;</p>



<p class="wp-block-paragraph">Fortinet has already identified active exploits of this critical vulnerability, and have observed the following post exploitation activities:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>Creating an admin account on the device with a random username.&nbsp;</li>
</ol>



<ol start="1" class="wp-block-list">
<li>Creating a Local User account on the device using a random name.&nbsp;</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Creating a user group or adding the above local user to an existing sslvpn user group&nbsp;</li>
</ol>



<ol start="3" class="wp-block-list">
<li>Adding/changing other settings (firewall policy, etc)&nbsp;</li>
</ol>



<ol start="4" class="wp-block-list">
<li>Logging in the sslvpn with the above added local users to get a tunnel to the internal network.&nbsp;</li>
</ol>



<p class="has-medium-font-size wp-block-paragraph"><strong>Affected versions or applications:</strong>&nbsp;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Product</strong>&nbsp;</td><td><strong>Version</strong>&nbsp;</td><td><strong>Solution</strong>&nbsp;</td></tr><tr><td>FortiOS&nbsp;</td><td>7.0.0 through 7.0.16&nbsp;</td><td>Upgrade to 7.0.17 or above&nbsp;</td></tr><tr><td>FortiProxy&nbsp;</td><td>7.2.0 through 7.2.12&nbsp;</td><td>Upgrade to 7.2.13 or above&nbsp;</td></tr><tr><td>FortiProxy&nbsp;</td><td>7.0.0 through 7.0.19&nbsp;</td><td>Upgrade to 7.0.20 or above&nbsp;</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Mitigation</h2>



<p class="wp-block-paragraph">To safeguard your organization&#8217;s systems and data, DICT and NCSC strongly recommend taking the following actions:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>Follow Fortinet’s published advice for affected versions.&nbsp;</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Upgrade affected versions of FortiOS and FortiProxy versions.&nbsp;</li>
</ol>



<ol start="3" class="wp-block-list">
<li>Monitor and investigate for suspicious activity in connected environments.&nbsp;</li>
</ol>



<p class="wp-block-paragraph">For more detailed information and specific instructions regarding the vulnerability and updates, we encourage you to refer to Fortinet’s published advice through the following link: <a href="https://www.fortiguard.com/psirt/FG-IR-24-535" target="_blank" rel="noreferrer noopener">Authentication bypass in Node.js websocket module</a>.&nbsp;</p>



<p class="wp-block-paragraph">Prompt action is crucial in addressing these critical vulnerabilities to ensure the security and stability of your organization&#8217;s systems and data. By remaining vigilant and keeping your infrastructure up-to-date, you can effectively safeguard against potential cyber threats. The NCSC and the Department of ICT are dedicated to promoting a secure digital environment, and we encourage all stakeholders to adhere to the recommended actions for enhanced cybersecurity resilience.&nbsp;</p>



<p class="wp-block-paragraph">For any further assistance or inquiries, please reach out to the National Cyber Security Center (NCSC). Together, let us prioritize cybersecurity and protect Papua New Guinea&#8217;s digital landscape.&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.ncsc.gov.pg/authentication-bypass-using-an-alternate-path-or-channel-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 17/239 objects using Memcached
Page Caching using Disk: Enhanced 

Served from: www.ncsc.gov.pg @ 2026-08-20 16:16:44 by W3 Total Cache
-->