Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » CISA adds a second BeyondTrust flaw to the KEV catalog amid active attacks
Global Security

CISA adds a second BeyondTrust flaw to the KEV catalog amid active attacks

AdminBy AdminJanuary 14, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 14, 2025Ravi LakshmananVulnerability / Cyber ​​Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a second security flaw affecting BeyondTrust’s Privileged Remote Access (PRA) and Remote Support (RS) products to its list of known vulnerabilities (KEV) catalog with reference to evidence of active exploitation in the wild.

The vulnerability in question CVE-2024-12686 (CVSS Score: 6.6), a moderate vulnerability that could allow an attacker with existing administrative privileges to enter commands and operate as a site user.

Cyber ​​security

“BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that could be used by an attacker with existing administrative privileges to download a malicious file,” CISA said.

“Successful exploitation of this vulnerability could allow a remote attacker to execute basic operating system commands in the context of the site user.”

The addition of CVE-2024-12686 to the KEV catalog comes nearly a month after it added another critical security flaw affecting the same product (CVE-2024-12356CVSS score: 9.8), which can also cause arbitrary commands to be executed.

BeyondTrust said both vulnerabilities were discovered as part of an investigation into a cyber incident in early December 2024 in which attackers used a compromised Remote Support SaaS API key to compromise some instances and reset passwords for local application accounts.

Although the API key has been revoked, the exact way in which it was compromised is still unknown. It is suspected that threat actors used the two flaws as zero days to compromise BeyondTrust’s systems.

Earlier this month, the US Treasury Department revealed its network was hacked using a compromised API key in what it said was a “major cyber security incident”. The hack was blamed on a Chinese government group called Silk typhoon (aka hafnium).

Cyber ​​security

The threat actors are believed to have specifically targeted the Office of Foreign Assets Control (OFAC), the Office of the Financial Conduct Authority and the Committee on Foreign Investment in the United States (CFIUS), according to multiple reports from Washington Post and CNN.

Also added to the KEV catalog is a patched critical security vulnerability affecting Qlik Sense (CVE-2023-48365, CVSS Score: 9.9) that allows an attacker to elevate privileges and execute HTTP requests on the backend server hosting the software .

It should be noted that the security flaw has been actively exploited in the past Cactus ransomware group. Federal agencies must apply the necessary patches by February 3, 2024 to protect their networks from active threats.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.