logo

CISA Shares Lessons Learned from an Incident Response Engagement

ID: 42465b56-eef3-5bb4-83f1-23305c1cbedc

STIX ID: report--42465b56-eef3-5bb4-83f1-23305c1cbedc

Feed Name: CISA Cybersecurity Advisories

Threat Score
78/100

Date Published: 2025-09-22

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive Summary:** CISA responded to a multi-week compromise of an FCEB agency where cyber threat actors exploited GeoServer CVE-2024-36401 to achieve RCE on public-facing servers, used web shells and living-off-the-land techniques for persistence and discovery, deployed Stowaway as a proxy-based C2 channel, attempted privilege escalation (dirtycow), and conducted lateral movement to internal web and SQL servers; the advisory includes MITRE ATT&CK mappings, IOCs, a timeline, and prioritized mitigations such as immediate KEV patching, IRP testing, centralized logging, phishing-resistant MFA, and application allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.