CyberzSOC

Publication detail
← Back to advisories & guidance

PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure ↗ source

February 7, 2024 NSA Advisory
Co-sealed by: ASD/ACSC, CCCS, CISA, DOE, EPA, FBI, NCSC-NZ, NCSC-UK, NIST, NSA, TSA

Summary

Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States. application, access, and security logs CISA, NSA, FBI and the following partners are and store logs in a central system. releasing this advisory to warn critical • Plan “end of life” for technology infrastructure organizations about this beyond manufacturer’s supported assessment, which is based on observations lifecycle. from the U.S. authoring agencies’ incident response activities at critical infrastructure organizations compromised by the PRC state-sponsored cyber group known as Volt Typhoon (also known as V anguard Panda, BRONZE SILHOUETTE, Dev0391, UNC3236, Voltzite, and Insidious Taurus): The U.S. authoring agencies have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations—primarily in Communications, Energy, Transportation Systems, and Water and Wastewater Systems Sectors—in the continental and noncontinental United States and its territories, including Guam.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2022-42475 9.3 Critical Fortinet FortiOS Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.