CISA orders agencies to patch BeyondTrust bug exploited in attacks
- CISA has identified a command injection vulnerability in BeyondTrust's software that is actively exploited in attacks, mandating U.S. Federal agencies to secure their networks by February 3.
- BeyondTrust discovered two vulnerabilities during an investigation of a breach involving stolen API keys, which were used to compromise its Remote Support SaaS instances.
- The Treasury Department's network was breached using a stolen BeyondTrust API key, linked to Chinese state-backed hackers known as Silk Typhoon, targeting sensitive information.
- BeyondTrust has issued security patches for the identified vulnerabilities, but users of self-hosted instances are required to apply them manually.
Insights by Ground AI
Does this summary seem wrong?
Coverage Details
Total News Sources0
Leaning Left0Leaning Right0Center2Last UpdatedBias Distribution100% Center
Bias Distribution
- 100% of the sources are Center
100% Center
C 100%
Factuality
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage