The U.S. government has warned that multiple cybercriminal groups, including state-sponsored hacking groups, have exploited a four-year-old software vulnerability to compromise U.S. federal agencies.
Hackers from multiple hacking groups exploited known vulnerabilities in Telerik, a web server user interface tool, in a joint alert released Wednesday by the CISA, FBI, and the Center for Multilateral Information Sharing and Analysis (known as MS-ISAC). It became clear that The software was designed for building web application components and themes and ran on Internet-facing web servers at US government agencies.
CISA does not name the Federal Civilian Executive (FCEB) agencies compromised, including the Department of Homeland Security, the Department of Treasury, and the Federal Trade Commission.
When contacted by email, CISA spokesperson Zee Zaman declined to answer TechCrunch’s questions.
The Telerik vulnerability is tracked as CVE-2019-18935 and has a severity rating of 9.8 out of 10.0, ranking as one of the most commonly exploited vulnerabilities in 2020 and 2021. This bug he first discovered in 2019, and the US National Security Agency warned earlier. It was actively exploited by Chinese government-backed hackers to target computer networks holding “sensitive intellectual property, economic, political, and military information.”
CISA says the bug allowed malicious attackers to “successfully execute remote code” on the agency’s Web server, exposing access to the agency’s internal network. The advisory noted that the compromised institution’s vulnerability scanner failed to detect the bug. This is because he had Telerik’s software installed where the scanner would not normally scan.
According to CISA’s recommendations, cybersecurity agencies will conduct multiple hacking campaigns from November 2022 to early January 2023, including state-sponsored hacking groups and Vietnam-linked credit card skimming actors known as the XE Group. It says it has confirmed that the group is exploiting this vulnerability.
CISA published the indicators of compromise and urged organizations running vulnerable Telerik software to ensure security patches were applied.
Progress Software, which acquired Telerik in 2014, did not respond to our inquiries.
CISA added an Adobe ColdFusion bug to its list of known exploited vulnerabilities this week, exploiting the vulnerability (tracked as CVE-2023-26360 with a severity score of 8.6) to allow attackers to I warned you that it could allow you to execute arbitrary code.