logo

CISA orders agencies to patch BeyondTrust bug exploited in attacks

ID: 30f47016-c505-5b2d-bab6-9c6f28098210

STIX ID: report--30f47016-c505-5b2d-bab6-9c6f28098210

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-01-13

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA has flagged two command-injection vulnerabilities in BeyondTrust Privileged Remote Access and Remote Support (CVE-2024-12686 and CVE-2024-12356) as actively exploited following a December breach of BeyondTrust's Remote Support SaaS that resulted in a stolen API key; the key was used to reset application account passwords and access customer environments, including the U.S. Treasury. The intrusions have been attributed to the Chinese state-backed group Silk Typhoon, prompting CISA to add the flaws to its Known Exploited Vulnerabilities catalog and mandate mitigations for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.