None
EN
CISA says hackers breached federal agency using GeoServer exploit
[]
BleepingComputer
CISA has revealed that attackers breached the network of an unnamed U.S. federal civilian executive branch (FCEB) agency last year after compromising an unpatched GeoServer instance.
The security bug (tracked as CVE-2024-36401) is a critical remote code execution (RCE) vulnerability patched on June 18, 2024.
Two days after the first attacks were detected, threat actors gained access to a U.S. federal agency's GeoServer server and compromised another one roughly two weeks later.
In the next stage of the attack, they moved laterally through the agency's network, breaching a web server and an SQL server.
In July, the U.S. cybersecurity agency issued another advisory following a proactive hunt engagement at a U.S. critical infrastructure organization.
['cisa'
'breached'
'threat'
'exploited'
'federal'
'hackers'
'remote'
'exploit'
'geoserver'
'agency'
'execution'
'network'
'server'
'security'
'using'
'vulnerabilities']