NextGen Healthcare Mirth Connect Under Attack - CISA Issues Urgent Warning
ID: c8eb7fe1-8d31-5a17-861f-918380b7aa69
STIX ID: report--c8eb7fe1-8d31-5a17-861f-918380b7aa69
Feed Name: The Hacker News
Threat Score
CISA added CVE-2023-43208—an unauthenticated RCE in NextGen Mirth Connect caused by insecure use of Java XStream—to its Known Exploited Vulnerabilities catalog citing active exploitation; Microsoft has observed nation-state and cybercrime actors leveraging Mirth Connect and other product flaws for initial access. Federal agencies are required to update to Mirth Connect 4.4.1+ (and apply specified Chrome patches) by June 10, 2024 to mitigate the active threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
