CISA: hacking groups linked to China's Ministry of State Security have exploited F5, Citrix, Pulse Secure, and Microsoft Exchange bugs to hack US gov't networks
Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity Ravie Lakshmanan / The Hacker News : CISA: Chinese Hackers Exploiting Unpatched Devices to Target U.S. Agencies Ken Wieland / Light Reading : US agency red flags Chinese state-affiliated cyberattacks Ionut Arghire / SecurityWeek : Chinese Hackers Using Publicly Available Resources in Attacks on U.S. Government Lindsey O'Donnell / Threatpost : Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs Mariam Baksh / Nextgov : Hackers Connected to China Have Compromised U.S. Government Systems, CISA says Tweets: Florian Roth / @cyb3rops : While newbie hackers believe that the front line runs between “the community and vendors” (I blame MrRobot&the EvilCorp theme), the actual&relevant battle has been fought between companies that create&preserve our prosperity & foreign actors that stole it https://us-cert.cisa.gov/... https://twitter.com/... Us-Cert / @uscert_gov : 🚨 @CISAgov and @FBI issued an advisory on Chinese Ministry of State Security-affiliated cyber threat activity. Protect your network and information systems by regularly applying the latest security patches & updates. Read more at https://us-cert.cisa.gov/.... #Cybersecurity #InfoSec https://twitter.com/... Bad Packets / @bad_packets : Bad Packets initial vulnerability scans (post-public disclosure) found: • 14,500 Pulse Secure VPN servers vulnerable to CVE-2019-11510 • 25,000 Citrix (NetScaler) servers vulnerable to CVE-2019-19781 • 3,000 BIG-IP F5 servers vulnerable to CVE-2020-5902 https://twitter.com/... @cisagov : Today we published an advisory with @FBI about open source information and common exploits used for malicious activity by Chinese MSS affiliated cyber actors. Learn how to strengthen network defense and reduce exposure: https://us-cert.cisa.gov/.... #Cybersecurity #NationalSecurity https://twitter.com/... Catalin Cimpanu / @campuscodi : Some of these attacks have been successful, per CISA (see table below). But the CISA advisory goes beyond attacks on networking gear. It also includes common TTPs and MITRE ATT&CK identifiers used by Chinese actors in general. More in the alert, here: https://us-cert.cisa.gov/... https://twitter.com/... Kevin Beaumont / @gossithedog : Many of these date back 12 months or more, I recommend checking your network boundaries. If you don't know what your network boundaries IP ranges are, search for your org on https://shodan.io/ and such to find out. https://twitter.com/...