The CISA has recently published a joint CSA with the NSA and the FBI about the top CVEs that are exploited by the threat actors since 2020 and the threat actors are Chinese state-sponsored.
Chinese cyber threat actors are still exploiting known vulnerabilities of US and allied networks for the purpose of stealing intellectual property from tech companies.
CSA’s mission is to inform all the agencies under federal and state governments about these CVEs. Primarily focusing on the individuals and organizations that are involved in critical infrastructure.
PRC state-sponsored cyber activities are being assessed by the NSA, CISA, and FBI. Among the most significant and dynamic threats to the U.S. government and civilian infrastructure are state-sponsored actors with ties to the PRC.
Here below we have mentioned all the CVEs that are most used by the Chinese state-sponsored threat actors since 2020:-
In order to gain access to web-facing applications, state-sponsored threat actors continue to use VPNs as a means of obscuring their activities.
It should be noted that a number of the CVEs listed above allow for unauthorized access to sensitive networks to be gained by the actors in a stealthy manner.
Organizations are encouraged by the NSA, CISA, and FBI to apply these recommendations mentioned below as soon as possible:-
Cyber Attack with Zero Trust Networking – Download Free E-Book
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…