US Federal Agencies Hacked by Multiple Threat Actors Exploiting Old Flaws.

1 min read
Source: The Register
US Federal Agencies Hacked by Multiple Threat Actors Exploiting Old Flaws.
Photo: The Register
TL;DR

Criminals, including potentially an APT group, exploited a three-year-old Telerik bug to break into a US federal government agency's Microsoft Internet Information Services web server between November 2022 and early January. The Feds became aware of the intrusion after spotting warning signs at a federal civilian executive branch agency. The Telerik bug, which received a 9.8 out of 10 CVSS severity score, was first discovered in 2019 and is especially popular with Beijing-backed criminals. The cybersecurity agency suggests organizations stay on top of patching to ensure their software is up to date and limit permissions to the minimum necessary to run services.

Share this article

Want the full story? Read the original reporting

Read on The Register