Alert (AA20-259A)- Iran-Based Threat Actor Exploits VPN Vulnerabilities

imhotep

Well-known member
  • Mar 29, 2017
    14,828
    8
    35,346
    113
    FYI - CERT Release - 15 September 2020

    CISA and FBI are aware of a widespread campaign from an Iran-based malicious cyber actor targeting several industries mainly associated with information technology, government, healthcare, financial, insurance, and media sectors across the United States. The threat actor conducts mass-scanning and uses tools, such as Nmap, to identify open ports. Once the open ports are identified, the threat actor exploits CVEs related to VPN infrastructure to gain initial access to a targeted network. CISA and the FBI have observed the threat actor exploiting multiple CVEs, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902.

    Full advisory -

    https://us-cert.cisa.gov/ncas/alerts/aa20-259a
     
    • Like
    Reactions: mrazeez and D_Mad

    D_Mad

    Well-known member
  • Jun 11, 2013
    25,606
    42,097
    113
    Deniyaya
    AlarmingIdolizedAmericankestrel-max-1mb.gif
     

    U-tag

    Well-known member
  • Nov 18, 2011
    12,732
    14,352
    113
    මචං CSF වගේ firewall එකකින් VPS එකේ අපිට ඕනේ ports (80, 443, 22) ටික විතරක් open කරාම (අනික් ඒවා close කරලා) ඔහොම vulnerable වෙන්නේ නැද්ද?