CYBER 101

  • Alerts
  • Blog
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Domains
  • FAQ
  • Incidents
  • News
  • Tutorials

Subscribe to our newsletter

No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
  • Jobs
  • Vendors
Get Help
CyberMaterial
Home Alerts

CISA warns of .NET vulnerability exploit

March 16, 2023
Reading Time: 2 mins read
in Alerts

 

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a cybersecurity advisory in collaboration with the Federal Bureau of Investigation and the Multi-State Information Sharing and Analysis Center (MS-ISAC), warning of malicious cyber activity targeting a federal civilian executive branch (FCEB) agency.

Analysts have identified that multiple cyber threat actors, including an advanced persistent threat (APT) actor, were able to exploit a vulnerability in Progress Telerik UI for ASP.NET AJAX.

The vulnerability, CVE-2019-18935, allows for remote code execution, and Telerik UI for ASP.NET AJAX builds before R1 2020 (2020.1.114) are vulnerable to this exploit.

To mitigate similar malicious cyber activities, CISA recommends that organizations implement a patch management solution to ensure compliance with the latest security patches, validate output from patch management and vulnerability scanning against running services to check for discrepancies and account for all services, and limit service accounts to the minimum permissions necessary to run services.

In the cybersecurity advisory, IT infrastructure defenders are provided with tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and methods to detect and protect against similar exploitation.

The exploitation of a .NET deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX, which allows for remote code execution, underscores the importance of applying software updates and security patches in a timely manner.

Failure to do so can leave organizations vulnerable to cyber attacks, with cybercriminals seeking to exploit known vulnerabilities in popular software platforms to gain unauthorized access to networks and systems.

To prevent such exploits, organizations must remain vigilant and ensure that their security systems are up to date with the latest patches and updates.

Read More

Tags: Advanced Persistent ThreatsAlertsAlerts 2023APTASP.NETCISACISA InsightsCISA ReportGovernmentMarch 2023TelerikVulnerabilities
0
VIEWS
ADVERTISEMENT

Related Posts

DotRunpeX distribute numerous known malware

DotRunpeX distribute numerous known malware

March 21, 2023
Google Pixel flaw compromises sensitive data

Google Pixel flaw compromises sensitive data

March 21, 2023
Ubuntu: new vulnerabilities

Ubuntu: new vulnerabilities

March 21, 2023
New CatB ransomware evasion technique

New CatB ransomware evasion technique

March 21, 2023

More Articles

Incidents

Advanced Phishing Scams Target Middle East

July 6, 2022
Alerts

VMware security advisory (AV22-428)

August 2, 2022
Incidents

Coinbase Fined 3.3 Million Euros by Dutch Central Bank

January 27, 2023
Book

Firewalls Don’t Stop Dragons

January 6, 2023

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.