Thousands of Buggy BeyondTrust Systems Remain Exposed
ID: 7469d648-f1d6-5424-85ca-a1e7feb8b272
STIX ID: report--7469d648-f1d6-5424-85ca-a1e7feb8b272
Feed Name: Dark Reading
Date Published: 2025-01-03
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
A critical vulnerability (CVE-2024-12356, CVSS 9.8) in BeyondTrust Privileged Remote Access and Remote Support is being actively exploited by Chinese state-sponsored actors; the flaw was used to breach the U.S. Department of the Treasury and Censys reports 8,602 BeyondTrust instances still exposed on the internet (72% in the U.S.). BeyondTrust auto-patched cloud customers and force-updated self-hosted instances, but the patch status of exposed systems is unknown; the report recommends checking patches or restricting inbound connectivity to trusted IPs when patching is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
