• Iranian hackers blamed for Fortinet and Microsoft Exchange hacks

    From TechnologyDaily@1337:1/100 to All on Thu Nov 18 14:00:06 2021
    Iranian hackers blamed for Fortinet and Microsoft Exchange hacks

    Date:
    Thu, 18 Nov 2021 13:51:30 +0000

    Description:
    US, UK, and Australian security agencies blame Iranian state-sponsored threat actors of exploiting well-known vulnerabilities to compromise targets around the world.

    FULL STORY ======================================================================

    In a joint advisory, top cybersecurity authorities from the US, UK, and Australia have pointed fingers at Iran-backed threat actors for ongoing attacks that exploit multiple Microsoft Exchange and Fortinet vulnerabilities .

    According to the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdoms National Cyber Security Centre (NCSC), the threat actors have been using Fortinet vulnerabilities since at least March 2021 and a Microsoft Exchange ProxyShell vulnerability since at least October 2021.

    The agencies claim that the attackers exploit the bugs, namely
    CVE-2021-34473, 2020-12812, 2019-5591, and 2018-13379, to get a foothold into the network, which they then use for various malicious operations, including exfiltrating sensitive data, and deploying ransomware . TechRadar needs you!

    We're looking at how our readers use VPNs with streaming sites like Netflix
    so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

    Click here to start the survey in a new window << Firing indiscriminately

    Commenting on the activities of the threat actors, the agencies believe that the group focuses its efforts on exploiting known vulnerabilities rather than targeting specific sectors.

    The Iranian government-sponsored APT [advanced persistent threat] actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors, including the Transportation Sector and the
    Healthcare and Public Health Sector, as well as Australian organizations, the agencies note in the joint advisory.

    The advisory highlights some of the groups recent activities, and suggests that they may create persistence in the compromised networks by creating new user accounts on domain controllers, servers, workstations, and active directories.

    To mitigate the threat, the agencies advise admins to apply patches for the exploited vulnerabilities without delay, even as it helps admins double-down the security of their networks through several steps such as mandating strong passwords , and implementing multi-factor authentication ( MFA ).

    Build a digital moat around your network using one of these best firewall apps and services , and protect your computers against all kinds of cyber-attacks with these best endpoint protection tools



    ======================================================================
    Link to news story: https://www.techradar.com/news/iranian-hackers-blamed-for-fortinet-and-microso ft-exchange-hacks/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)