Article 69WRM Federal agency hacked by 2 groups thanks to flaw that went unpatched for 4 years

Federal agency hacked by 2 groups thanks to flaw that went unpatched for 4 years

by
Dan Goodin
from Ars Technica - All content on (#69WRM)
digital-american-flag-800x534.jpg

Enlarge (credit: Getty Images)

Multiple threat actors-one working on behalf of a nation-state-gained access to the network of a US federal agency by exploiting a four-year-old vulnerability that remained unpatched, the US government warned.

Exploit activities by one group likely began in August 2021 and last August by the other, according to an advisory jointly published by the Cybersecurity and Infrastructure Security Agency, the FBI, and the Multi-State Information Sharing and Analysis Center. From last November to early January, the server exhibited signs of compromise.

Vulnerability not detected for 4 years

Both groups exploited a code-execution vulnerability tracked as CVE-2019-18935 in a developer tool known as the Telerik user interface (UI) for ASP.NET AJAX, which was located in the agency's Microsoft Internet Information Services (IIS) web server. The advisory didn't identify the agency other than to say it was a Federal Civilian Executive Branch Agency under the CISA authority.

Read 9 remaining paragraphs | Comments

External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments