Gaming and Wagering Protection Community

 View Only
31 Mar, 2022 11:27 AM

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to warn organizations that Russian state-sponsored cyber actors have gained network access through exploitation of default MFA protocols and a known vulnerability. As early as May 2021, Russian state-sponsored cyber actors took advantage of a misconfigured account set
to default MFA protocols at a non-governmental organization (NGO), allowing them to enroll a new device for MFA and access the victim
network. The actors then exploited a critical Windows Print Spooler vulnerability, “PrintNightmare” (CVE-2021-34527) to run
arbitrary code with system privileges. Russian state-sponsored cyber actors successfully exploited the vulnerability while targeting an NGO using
Cisco’s Duo MFA, enabling access to cloud and email accounts for document exfiltration.

Statistics
0 Favorited
1 Views
1 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.