logo

US Treasury Department outs the blast radius of BeyondTrust's key leak

ID: 63efa94d-a71f-5285-8e57-fde1d5759ef6

STIX ID: report--63efa94d-a71f-5285-8e57-fde1d5759ef6

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-12-31

Date Updated: 2026-04-26

Author: Richard Speed

...
...

The U.S. Department of the Treasury disclosed that an API key theft from BeyondTrust’s Remote Support SaaS allowed a threat actor—attributed to a China state-sponsored APT—to access departmental workstations and unclassified files; federal agencies and third-party forensics are investigating while BeyondTrust has revoked the key, patched on-premises software, and updated cloud instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.