logo

CISA broke into a US federal agency, and no one noticed for a full 5 months

ID: 62fa4705-d207-54f8-9a09-adee0a2245b4

STIX ID: report--62fa4705-d207-54f8-9a09-adee0a2245b4

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-07-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA's 2023 SILENTSHIELD red team assessment of an unnamed federal agency exploited CVE-2022-21587 in an Oracle Solaris enclave to gain RCE, later achieved Windows domain admin via successful phishing, plaintext credentials on an open admin share, and kerberoasting, injected a persistent RAT, and pivoted into trusted partner organizations; the exercise exposed slow patching, ineffective log collection and detection, and a need for defense-in-depth and better vendor security practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.