logo

Joint CyberSecurity Advisory Alert on PrintNightmare Vulnerability and Default MFA Protocols Exploited by Russian State-Sponsored Cyber Actors (AA22-074A)

ID: fc6538ff-84b7-5d04-b1a7-01a8a43e6b35

STIX ID: report--fc6538ff-84b7-5d04-b1a7-01a8a43e6b35

Feed Name: FortiGuard Threat Signals

Threat Score
88/100

Date Published: 2025-07-25

Date Updated: 2026-07-28

...
...

FortiGuard Labs summarizes a CISA/FBI advisory reporting that Russian state-sponsored actors compromised an NGO by brute-forcing credentials, re-enrolling a dormant Duo MFA device, exploiting PrintNightmare (CVE-2021-34527) to escalate privileges, and altering the domain controller hosts file to disable MFA; the actors then moved laterally to exfiltrate data from cloud storage and email accounts and the advisory includes mitigations and FortiGuard coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.