Nation-state hackers attempted to use Equifax vulnerability against DoD, NSA official says
Full article632 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
An NSA official says 24 hours after Equifax's breach was made public, a nation-state was scanning DoD for unpatched Apache Struts instances.
A government-backed hacking group tried to breach the Department of Defense via the exact same software vulnerability that was used to breach Equifax, an official with the National Security Agency said Tuesday during a speech at the 2018 RSA conference.
“The vulnerability that took down Equifax last year when it was released in March, we had a nation-state actor within 24 hours scanning looking for unpatched servers within the DoD,” said David Hogue, a senior technical director for the NSA’s Cybersecurity Threat Operations Center (NCTOC).
The malicious activity caught by NSA shows how most attackers, regardless of skill or available resources, will first rely on simplistic and easily accessible methods to compromise their victims. In this case, the attackers relied on a known vulnerability in the Apache Struts software framework to target the DoD.
Hogue said that most data breach incidents that are analyzed by his team are caused by phishing emails or unpatched vulnerable systems. Failing to patch the flaw in Apache Struts, despite it being available for months, allowed attackers to siphon millions of data points housed by Equifax.
Basic cyber hygiene, Hogue explained, could prevent a majority of these cases. It is the NSA’s mission to protect sensitive Pentagon computer networks, including U.S. Army computers located in warzones like Afghanistan.
“Within 24 hours I would say of whenever an exploit or vulnerability is released, it is weaponized and used against us,” said Hogue.
Hogue also said the use of “zero-day” vulnerabilities to breach systems appears to be increasingly rare, based on his own work.
“At NSA we have not responded to an intrusion response that’s used a zero-day vulnerability in over 24 months,” Hogue said. “The majority of incidents we see are a result of hardware and software updates that are not applying.”
A Ponemon Institute survey published earlier this year noted that 53 percent of polled cybersecurity experts said that the time between patch release and a related cyberattack attack had decreased an average of 29 percent over the last two years. In addition, the study described that 57 percent of respondents admitted to being breached because of a vulnerability for which a patch was already available.
Another 2018 study by cybersecurity firm Mimecast found that “94 percent of respondents had seen an increase in phishing attacks, and 92 percent had seen an increase in targeted spear phishing attacks with malicious links.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dod-apache-struts-equifax-david-hogue-nsa/