CISA has added a BeyondTrust command injection vulnerability to the List of Known Exploitable Vulnerabilities (KEV).

CISA announced that a command injection vulnerability (CVE-2024-12686) in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) is being actively used in attacks.
US federal agencies are asked to implement the updates and protect their networks by February 3.
On December 19, the cybersecurity organization added another BeyondTrust command injection vulnerability ( CVE-2024-12356 ) to the KEV List
See also: CISA adds Oracle and Mitel vulnerabilities to KEV List
BeyondTrust discovered both vulnerabilities while investigating a breach of some Remote Support SaaS instances in early December. The attackers stole an API key, which they later used to reset passwords for local application accounts.
In early January, the Treasury Department US revealed that its network was breached by attackers who used a stolen Remote Support SaaS API key to compromise a BeyondTrust instance used by the service.
The attack was linked to Chinese state-backed hackers known as Silk Typhoon. The attackers targeted the Office of Foreign Assets Control (OFAC), which administers trade and economic sanctions programs, and the Committee on Foreign Investment in the United States (CFIUS) , which reviews foreign investments for national security risks. They also breached the systems of the Treasury Department's Office of Financial Investigation
See also: CISA warns of 4 new vulnerabilities

It is believed that the Silk Typhoon group used the stolen BeyondTrust digital key to access “ information related to potential sanctions actions and other documents .”
BeyondTrust says it has released security updates for the two vulnerabilities across all cloud instances. However, those running self-hosted instances must deploy the updates manually.
While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.
The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
See also: CISA – Issues Best Practices for Securing Microsoft 365 Cloud Environments
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.
Source: www.bleepingcomputer.com
