"CISA Urges Patching of Microsoft Exchange and Cisco ASA Flaws Exploited in Ransomware Attacks"

TL;DR Summary
The U.S. CISA has warned of Akira ransomware exploiting a now-patched vulnerability in Cisco ASA and FTD software, with evidence suggesting it has been used to compromise multiple susceptible Cisco Anyconnect SSL VPN appliances. Akira is one of the 25 groups with newly established data leak sites in 2023, claiming nearly 200 victims, and is linked to the Conti syndicate. Federal agencies are required to remediate identified vulnerabilities by March 7, 2024. The ransomware landscape has become lucrative, attracting new players, and the U.S. GAO has called for enhanced oversight into recommended practices for addressing ransomware.
- CISA Warning: Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability The Hacker News
- Microsoft Exchange Server Flaw Exploited as a Zero-Day Bug DARKReading
- CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks SecurityWeek
- Microsoft Exchange update enables Extended Protection by default BleepingComputer
- Microsoft 0-day, Neuberger addresses Munich, trojan steals faces CISO Series
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
2 min
vs 3 min read
Condensed
81%
517 → 96 words
Want the full story? Read the original article
Read on The Hacker News