CISA: Hackers access to federal networks without SolarWinds

CISA: Hackers access to federal networks without SolarWinds -- FCW


By Justin Katz
 
The Cybersecurity and Infrastructure Security Agency says it has evidence that hackers are breaching the federal government's networks by other paths than the recently discovered vulnerabilities in SolarWinds Orion.
"Specifically, we are investigating incidents in which activity indicating abuse of Security Assertion Markup Language (SAML) tokens consistent with this adversary's behavior is present, yet where impacted SolarWinds instances have not been identified," according to updated guidance published Wednesday. "CISA is continuing to work to confirm initial access vectors and identify any changes to the tactics, techniques, and procedures (TTPs)."
Characteristics such as a SAML tokens having a 24-hour validity periods or not containing multi-factor authentication details where expected are red flags.

Related Keywords

New York , United States , Czech Republic , Washington , Solarwinds Orion , Justin Katz , Tatyana Bolton , New York Times , Infrastructure Security Agency , R Street Institute , Cyberspace Solarium Commission , Jetbrains , Microsoft , Security Assertion Markup Language , Marine Corps , Inside Defense , புதியது யார்க் , ஒன்றுபட்டது மாநிலங்களில் , செக் குடியரசு , வாஷிங்டன் , ஜஸ்டின் க்யாட்ஸ் , தடியான போல்டன் , புதியது யார்க் முறை , ர் தெரு நிறுவனம் , மின்வெளி சோலாரியம் தரகு , மைக்ரோசாஃப்ட் , கடல் கார்ப்ஸ் , உள்ளே பாதுகாப்பு ,

© 2025 Vimarsana