Outdated Vulnerability Exploited by Multiple Hacker Groups to Breach US Federal Agency.

1 min read
Source: The Hacker News
Outdated Vulnerability Exploited by Multiple Hacker Groups to Breach US Federal Agency.
Photo: The Hacker News
TL;DR Summary

Multiple threat actors, including a nation-state group, exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal entity in the U.S. The vulnerability, tracked as CVE-2019-18935, relates to a .NET deserialization vulnerability affecting Progress Telerik UI for ASP.NET AJAX that, if left unpatched, could lead to remote code execution. Organizations are recommended to upgrade their instances of Telerik UI ASP.NET AJAX to the latest version, implement network segmentation, and enforce phishing-resistant multi-factor authentication for accounts that have privileged access.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

83%

48784 words

Want the full story? Read the original article

Read on The Hacker News