logo

The Long Tail of BeyondTrust [CVE-2024-12356]

ID: e4b0727e-1a93-5df7-924f-2f6e244e7d35

STIX ID: report--e4b0727e-1a93-5df7-924f-2f6e244e7d35

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2025-01-31

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; The Censys Research Team

...
...

Censys Research Team details a critical remote command injection (CVE-2024-12356) affecting BeyondTrust PRA and RS products; patches were issued but numerous on-premises instances remain exposed. The report documents evidence of exploitation by a Chinese state-backed actor using a stolen BeyondTrust API key against the U.S. Treasury and some SaaS customers, highlights exposure counts (778 inferred vulnerable on-prem hosts; 23,743 exposed hosts overall), and warns of a prolonged window of opportunity for attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.