The Long Tail of BeyondTrust [CVE-2024-12356]
ID: e4b0727e-1a93-5df7-924f-2f6e244e7d35
STIX ID: report--e4b0727e-1a93-5df7-924f-2f6e244e7d35
Feed Name: Censys Blog
Date Published: 2025-01-31
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; The Censys Research Team
Censys Research Team details a critical remote command injection (CVE-2024-12356) affecting BeyondTrust PRA and RS products; patches were issued but numerous on-premises instances remain exposed. The report documents evidence of exploitation by a Chinese state-backed actor using a stolen BeyondTrust API key against the U.S. Treasury and some SaaS customers, highlights exposure counts (778 inferred vulnerable on-prem hosts; 23,743 exposed hosts overall), and warns of a prolonged window of opportunity for attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
