[unable to retrieve full-text content]CISA Calls on Network Defenders to Take Action Against Adobe ColdFusion Vulnerability Risks Executive Gov Source link
Read More »Hackers breach US Government agencies running end-of-life software – CyberNews.com
[unable to retrieve full-text content]Hackers breach US Government agencies running end-of-life software CyberNews.com Source link
Read More »CISA Calls on Network Defenders to Take Action Against Adobe ColdFusion Vulnerability Risks
The Cybersecurity and Infrastructure Security Agency has issued an advisory concerning the exploitation of a vulnerability within select versions of the Adobe ColdFusion web application development platform that resulted in the compromise of two public-facing servers operated by a federal civilian executive branch agency. CISA said in its Dec. 5 cybersecurity advisory that each server was illegally accessed in two separate incidents in June, though it is not clear if the same malicious actors are behind both breaches. CISA documented the tactics, techniques and procedures that the malicious actors employed — including the implanting of software tools and the subsequent attempts to harvest user account credentials — and called on network defenders to monitor… Source link
Read More »CISA: Threat Actor Breached Federal Systems via Adobe ColdFusion Flaw – CISA: Threat Actor Breached Federal … – Dark Reading
[unable to retrieve full-text content]CISA: Threat Actor Breached Federal Systems via Adobe ColdFusion Flaw – CISA: Threat Actor Breached Federal … Dark Reading Source link
Read More »Attackers breach US government agencies through ColdFusion flaw – CSO Online
[unable to retrieve full-text content]Attackers breach US government agencies through ColdFusion flaw CSO Online Source link
Read More »Unpatched Adobe ColdFusion bug led to double breach of US federal agency – SC Media
[unable to retrieve full-text content]Unpatched Adobe ColdFusion bug led to double breach of US federal agency SC Media Source link
Read More »Mexican Pegasus trial, Fed ColdFusion breach, Malicious loan app – CISO Series
[unable to retrieve full-text content]Mexican Pegasus trial, Fed ColdFusion breach, Malicious loan app CISO Series Source link
Read More »Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers – The Hacker News
[unable to retrieve full-text content]Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers The Hacker News Source link
Read More »Hackers use patched security bug in Adobe ColdFusion to compromise U.S. agencies – The Hindu
[unable to retrieve full-text content]Hackers use patched security bug in Adobe ColdFusion to compromise U.S. agencies The Hindu Source link
Read More »Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers
Dec 06, 2023NewsroomVulnerability / Web Server Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers. “The vulnerability in ColdFusion (CVE-2023-26360) presents as an improper access control issue and exploitation of this CVE can result in arbitrary code execution,” CISA said, adding an unnamed federal agency was targeted between June and July 2023. The shortcoming affects ColdFusion 2018 (Update 15 and earlier versions) and ColdFusion 2021 (Update 5 and earlier versions). It has been addressed in versions Update 16 and Update 6, respectively, released on March 14, 2023. It was added by CISA to the Known… Source link
Read More »