CISA orders agencies to patch BeyondTrust bug exploited in attacks
ID: 30f47016-c505-5b2d-bab6-9c6f28098210
STIX ID: report--30f47016-c505-5b2d-bab6-9c6f28098210
Feed Name: Bleeping Computer
CISA has flagged two command-injection vulnerabilities in BeyondTrust Privileged Remote Access and Remote Support (CVE-2024-12686 and CVE-2024-12356) as actively exploited following a December breach of BeyondTrust's Remote Support SaaS that resulted in a stolen API key; the key was used to reset application account passwords and access customer environments, including the U.S. Treasury. The intrusions have been attributed to the Chinese state-backed group Silk Typhoon, prompting CISA to add the flaws to its Known Exploited Vulnerabilities catalog and mandate mitigations for federal agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
