U.S. State Government Network Breached via Former Employee's Account
ID: db6b8f70-f63c-51b4-a794-49eb9663da46
STIX ID: report--db6b8f70-f63c-51b4-a794-49eb9663da46
Feed Name: The Hacker News
Threat Score
CISA and MS-ISAC warn that an unnamed U.S. state government network was breached when a former employee's admin credentials—apparently exposed in a separate leak—were used to access an internal VPN and virtual machines, retrieve stored administrative credentials with both on-premises and Azure (Entra ID) privileges, perform LDAP queries, and publish host and user data on the dark web; no cloud lateral movement was observed and MFA was not enabled on the compromised accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
