Malware & Threats China Hackers Behind US Treasury Breach Caught Targeting IT Supply Chain Silk Typhoon APT caught using IT supply chain entry points to conduct reconnaissance, siphon data, and move laterally on victim networks. Ryan NaraineMarch 5, 2025
Nation-State Rapid7 Flags New PostgreSQL Zero-Day Connected to BeyondTrust Exploitation Rapid7 finds a new zero-day vulnerability in PostgreSQL and links it to chain of attacks against a BeyondTrust Remote Support product. Ryan NaraineFebruary 13, 2025
Malware & Threats CISA Warns of Second BeyondTrust Vulnerability Exploited in Attacks Attackers have been exploiting a second vulnerability in BeyondTrust’s remote management solutions, CISA warns. Ionut ArghireJanuary 14, 2025
Nation-State China Targeted Foreign Investment, Sanctions Offices in Treasury Hack: Reports Chinese cyberspies targeted offices dealing with foreign investments and sanctions in the recent US Treasury hack. Eduard KovacsJanuary 13, 2025
Government CISA: No Federal Agency Beyond Treasury Impacted by BeyondTrust Incident CISA says no federal agencies other than Treasury were impacted by the recent compromise of a BeyondTrust cloud-based service. Ionut ArghireJanuary 7, 2025
Vulnerabilities CISA Urges Immediate Patching of Exploited BeyondTrust Vulnerability CISA is urging federal agencies to patch a recent critical vulnerability in BeyondTrust remote access products in one week. Ionut ArghireDecember 20, 2024
Vulnerabilities BeyondTrust Patches Critical Vulnerability Discovered During Security Incident Probe A critical vulnerability in BeyondTrust Privileged Remote Access and Remote Support could lead to arbitrary command execution. Ionut ArghireDecember 18, 2024
CISO Strategy Okta Hack Blamed on Employee Using Personal Google Account on Company Laptop Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop. Ryan NaraineNovember 3, 2023
Data Breaches Okta Support System Hacked, Sensitive Customer Data Stolen Okta warns that hackers broke into its support case management system and stole sensitive data that can be used to impersonate valid users. Ryan NaraineOctober 20, 2023