CISA broke into a US federal agency, and no one noticed for a full 5 months
ID: 62fa4705-d207-54f8-9a09-adee0a2245b4
STIX ID: report--62fa4705-d207-54f8-9a09-adee0a2245b4
Feed Name: The Register (Security)
CISA's 2023 SILENTSHIELD red team assessment of an unnamed federal agency exploited CVE-2022-21587 in an Oracle Solaris enclave to gain RCE, later achieved Windows domain admin via successful phishing, plaintext credentials on an open admin share, and kerberoasting, injected a persistent RAT, and pivoted into trusted partner organizations; the exercise exposed slow patching, ineffective log collection and detection, and a need for defense-in-depth and better vendor security practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
