Attackers breach US government agencies through ColdFusion flaw

Attackers breach US government agencies through ColdFusion flaw

In a new advisory that shows why it’s critical to keep Adobe ColdFusion deployments up to date, the US Cybersecurity and Infrastructure Security Agency (CISA) warns that two federal agencies were breached by attackers in June through an unpatched vulnerability in the application server software. The attackers used their access to deploy web shells and collect information that would enable lateral movement in the environments. The breached ColdFusion instances were outdated in both cases as the exploited vulnerability had a fix available since March.

“Analysis suggests that the malicious activity conducted by the threat actors was a reconnaissance effort to map the broader network,” CISA said in its advisory without attributing the attacks to any known group. “No…


Source link

About coldfusion

Check Also

Robots Learn to Say "No" to Humans [Demo Included] | ColdFusion – MSN

Robots Learn to Say "No" to Humans [Demo Included] | ColdFusion – MSN

[unable to retrieve full-text content]Robots Learn to Say “No” to Humans [Demo Included] | ColdFusion  MSN …

Leave a Reply

Your email address will not be published. Required fields are marked *