Cisco has confirmed that the Chinese threat group Salt Typhoon exploited a critical vulnerability, CVE-2018-0171, to infiltrate major U.S. telecom networks. This security flaw, which has existed for seven years, allowed the attackers to maintain access to the systems for over three years. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog. Additionally, CISA flagged other vulnerabilities, including those in Craft CMS and Palo Alto Networks' PAN-OS, amid ongoing attacks. The joint advisory from CISA, the National Security Agency, and the Federal Bureau of Investigation highlights the indiscriminate nature of the attacks targeting U.S. telecommunications infrastructure.
Authentication bypass vulnerabilities in @SonicWall SonicOS SSLVPN and @PaloAltoNtwks PAN-OS have been added to the Known Exploited Vulnerabilities (KEV) catalog by @CISAgov. #cybersecurity #infosec #ITsecurity https://t.co/ZHumAwHjKM
One of the most notable elements of the monumental hack of major telecommunications companies is just how “indiscriminate” it was in its pursuit of data, a top FBI official said Wednesday. https://t.co/aB1vedq3mn https://t.co/svzBOaOgwk
The Cybersecurity & Infrastructure Security Agency, National Security Agency, and the Federal Bureau of Investigation released a joint advisory this […] The post Chinese hackers Volt Typhoon had critical US infrastruct... https://t.co/3FafjhkZDg