State-sponsored hacking groups have breached a United States aerospace organization using exploits targeting critical vulnerabilities in Zoho and Fortinet, as disclosed in a joint announcement published by CISA, the FBI and the U.S. Cybersecurity Council (USCYBERCOM) on Thursday.
See also: Chrome: All users will switch to Enhanced Safe Browsing feature

The groups behind this leak have not yet been named, but while the joint advisory does not link the attackers to a specific state, the USCYBERCOM press release links the malicious actors to exploitation efforts from Iran.
CISA participated in the response to the incident from February to April and reported that hacking groups had breached the network of the affected airline organization since January, after they hacked a server that was exposed on the Internet and was running Zoho ManageEngine ServiceDesk Plus and a Fortinet firewall.
“CISA, the FBI and CNMF confirmed that malicious APT actors exploited CVE-2022-47966 to gain unauthorized access to a public application (Zoho ManageEngine ServiceDesk Plus), to establish persistence and to move laterally across the network,” the advisory states.
See also: Cyberport technology center attacked by ransomware
“This vulnerability allows remote code execution in the ManageEngine application. Additional APT actors have also been observed exploiting CVE-2022-42475 to confirm their presence on an organization.”
Όπως προειδοποιούν οι τρεις αμερικανικές υπηρεσίες, αυτές οι ομάδες συχνά ανιχνεύουν ευπάθειες σε συσκευές που είναι προσβάσιμες στο διαδίκτυο και δεν έχουν ενημερωθεί για κρίσιμα και εύκολα εκμεταλλεύσιμα προβλήματα ασφαλείας.
After penetrating a target's network, attackers will maintain persistence in the compromised network infrastructure components . These network devices will likely be used as stepping stones for lateral movement into the victims' networks, as malicious infrastructure, or a combination of both .
Network defenders are advised to implement the mitigations communicated in this advisory and the NSA-recommended best practices for infrastructure security.
They include, but are not limited to, securing all systems against all known exploitable vulnerabilities, monitoring for unauthorized use of remote access software, and removing unnecessary (disabled) accounts and groups (especially privileged accounts).

See also: Microsoft: North Korean hackers are attacking Russian targets
Previous attacks and warnings for system security
CISA mandated federal agencies to protect their systems from the exploits of CVE-2022-47966 in January, a few days after attacks began by threat actors on unpatched ManageEngine instances exposed on the internet to open reverse shells after the proof-of-concept (PoC) was published online.
Months after the CISA warning, the North Korean Lazarus group also began exploiting the Zoho vulnerability, successfully breaching health organizations and a network infrastructure provider.
The FBI and CISA issued several other warnings (1, 2) about state-backed groups exploiting ManageEngine flaws to target critical infrastructure, including financial services and healthcare.
The CVE-2022-42475 FortiOS SSL-VPN vulnerability was also used as a zero-day in attacks against government agencies and related targets, as disclosed by Fortinet in January.
Fortinet also warned that during the attacks, additional malicious payloads were downloaded to the compromised devices, payloads that were not able to be recovered for analysis.
Customers were initially encouraged to update their devices for possible attacks from mid-December, after Fortinet silently patched the flaw on November 28 without disclosing that it was already being exploited by malicious actors.
Information source: bleepingcomputer.com
