Advanced hackers use Fortinet flaws in likely attempt to breach government networks, feds warn
Full article515 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The attackers could be using the bugs to access “key networks" as part of data-exfiltration or encryption attempts, officials said.
Advanced hackers are exploiting old flaws in popular enterprise software made by Fortinet in a possible attempt to access networks in multiple critical infrastructure sectors, the FBI and Department of Homeland Security warned on Friday.
“Advanced persistent threat” actors — a term that usually refers to state-linked groups — are likely using the software flaws to breach “multiple government, commercial, and technology services networks,” states the advisory from the FBI and DHS’s Cybersecurity and Infrastructure Security Agency.
The agencies said that the attackers, whom they did not identify, could be using the bugs in Fortinet software to access “key networks as pre-positioning for follow-on data exfiltration or data encryption attacks.”
The three vulnerabilities are in FortiOS, security software that government agencies and big corporations use to manage their networks. Hackers could exploit the bugs to intercept sensitive data on networks. Fortinet disclosed the vulnerabilities in 2018, 2019 and 2020 and issued fixes for them. That the bugs continue to be useful to hackers points to the fact that some organizations still have not updated their software.
The FBI and CISA advised organizations that haven’t applied the software patches to do so immediately.
“The security of our customers is our first priority,” California-based Fortinet, which is a popular U.S. government contractor, said in a statement. The company said it promptly issued fixes for the vulnerabilities when they were discovered, and urged customers that hadn’t applied them to do so.
The advisory is part of a recurring effort by U.S. government officials to warn companies of ongoing hacking operations based on popular software. The FBI and CISA in September publicized a suspected Chinese intelligence operation that allegedly exploited software made by F5 Networks and Citrix, among other vendors.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fortinet-apt-exploit-cisa-fbi/