New Findings Challenge Attribution in Denmark's Energy Sector Cyberattacks
ID: 0c5ac4f1-4967-5f59-b61a-edb99845c01e
STIX ID: report--0c5ac4f1-4967-5f59-b61a-edb99845c01e
Feed Name: The Hacker News
Threat Score
Forescout analysis finds two distinct intrusion waves against ~22 Danish energy organizations in May 2023: an initial wave and a separate broader mass-exploitation wave that abused Zyxel firewall flaws (notably CVE-2023-28771 and older CVEs) and led to Mirai botnet variant deployments; some communications matched IPs previously used by Cyclops Blink, but attribution to Russia-linked Sandworm is disputed and remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
