CyberzSOC

Publication detail
← Back to advisories & guidance

Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization ↗ source

February 15, 2024 CISA Advisory
Co-sealed by: CISA, CSA

Summary

CISA Analysis: Fiscal Year 2022 Risk and Vulnerability Assessments The Cybersecurity and Infrastructure Security Agency (CISA) conducts Risk and Vulnerability Assessments (RVAs) for the federal civilian executive branch (FCEB); high priority private and public sector critical infrastructure operators; and select state, local, tribal, and territorial (SLTT) stakeholders. Concurrently, the United States Coast Guard (USCG) conducts RVAs on maritime critical infrastructure operated by SLTT and private-sector organizations. The RVA is intended to assess the entity’s network capabilities and network defenses against potential threats. In Fiscal Year 2022 (FY22), CISA and USCG conducted 121 RVAs across multiple critical infrastructure sectors.1 Each RVA maps the results to the MITRE ATT&CK® framework, which includes 14 tactics that cyber threat actors use to obtain and maintain unauthorized access to a network or system. The goal of the RVA analysis is to develop effective strategies that positively impact the security posture of FCEB, critical infrastructure, maritime, and SLTT stakeholders. During each RVA, CISA and USCG collect data through remote and onsite actions.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2021-4428 2.7 Low what3words Autosuggest Plugin A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerabilit…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.