• Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA
  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
Thursday, July 30, 2026
No Result
View All Result
Subscribe Now
  • Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA
    TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

    TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

    NBA players are ‘being taught’ to flop

    NBA players are ‘being taught’ to flop

    Industry was warned for years about chemical ‘runaway’ dangers. Then came near-catastrophe in O.C.

    Industry was warned for years about chemical ‘runaway’ dangers. Then came near-catastrophe in O.C.

    Trump administration seeks government-wide NDAs to stop leaks : NPR

    Trump administration seeks government-wide NDAs to stop leaks : NPR

    Dog discharges shotgun inside truck, striking woman at Nebraska traffic light

    Dog discharges shotgun inside truck, striking woman at Nebraska traffic light

    Toshifumi Suzuki, Japan’s ‘God’ of Convenience Stores, Dies at 93

    Toshifumi Suzuki, Japan’s ‘God’ of Convenience Stores, Dies at 93

     Judge Sanctioned CoreCivic for Destroying Video in ICE Death Suit

     Judge Sanctioned CoreCivic for Destroying Video in ICE Death Suit

    Suspect dead after opening fire near White House security checkpoint, Secret Service says

    Suspect dead after opening fire near White House security checkpoint, Secret Service says

    Trump trashes Colbert’s high-rated finale as “no ratings”

    Trump trashes Colbert’s high-rated finale as “no ratings”

  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
The Insight Post
  • Home
  • Insight
  • Blog
  • Business
  • Entertainment
  • Health
  • Politics
  • Shop
    • Gift Shop
    • Value Shop
    • Store
    • Bargain Shop
    • Discount
  • Sports
  • Tech
  • Travel
  • USA
    TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

    TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

    NBA players are ‘being taught’ to flop

    NBA players are ‘being taught’ to flop

    Industry was warned for years about chemical ‘runaway’ dangers. Then came near-catastrophe in O.C.

    Industry was warned for years about chemical ‘runaway’ dangers. Then came near-catastrophe in O.C.

    Trump administration seeks government-wide NDAs to stop leaks : NPR

    Trump administration seeks government-wide NDAs to stop leaks : NPR

    Dog discharges shotgun inside truck, striking woman at Nebraska traffic light

    Dog discharges shotgun inside truck, striking woman at Nebraska traffic light

    Toshifumi Suzuki, Japan’s ‘God’ of Convenience Stores, Dies at 93

    Toshifumi Suzuki, Japan’s ‘God’ of Convenience Stores, Dies at 93

     Judge Sanctioned CoreCivic for Destroying Video in ICE Death Suit

     Judge Sanctioned CoreCivic for Destroying Video in ICE Death Suit

    Suspect dead after opening fire near White House security checkpoint, Secret Service says

    Suspect dead after opening fire near White House security checkpoint, Secret Service says

    Trump trashes Colbert’s high-rated finale as “no ratings”

    Trump trashes Colbert’s high-rated finale as “no ratings”

  • Video
  • World
    • Asia
    • Africa
    • South America
    • North America
    • Europe
    • Oceania
No Result
View All Result
No Result
View All Result
Home Tech

Guess what happened to this US agency that didn’t patch? • The Register

by Theinsightpost
June 19, 2023
in Tech
0 0
0
Guess what happened to this US agency that didn’t patch? • The Register

Infosec in brief Remember earlier this year, when we found out that a bunch of baddies including at least one nation-state group broke into a US federal government agency’s Microsoft Internet Information Services (IIS) web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution?

It turns out that this same gang of government-backed hackers used a different – and even older – Telerik flaw to break into another US federal agency’s Microsoft IIS web server, access the Document Manager component, upload webshells and other files, and establish persistence on the government network.

The US Cybersecurity and Infrastructure Security Agency and FBI warned about the first intrusion into a federal civilian executive branch agency’s Microsoft IIS web server back in March, and said the snafu happened between November 2022 and early January.

“Multiple cyber threat actors, including an APT actor, were able to exploit a .NET deserialization vulnerability (CVE-2019-18935) in Progress Telerik user interface (UI) for ASP.NET AJAX, located in the agency’s Microsoft Internet Information Services (IIS) web server,” the joint advisory revealed.

But wait, there’s more. On Thursday, the feds updated the March alert and said a forensic analysis of a different federal civilian executive branch agency “identified exploitation of CVE-2017-9248 in the agency’s IIS server by unattributed APT actors – specifically within the Telerik UI for ASP.NET AJAX DialogHandler component.”

This separate break-in, exploiting an almost six-year-old vulnerability, occurred in April. The agency was running an outdated version of the software, and a proof-of-concept exploit has been publicly available since January 2018, according to the feds.

“It should be noted that Telerik UI for ASP.NET AJAX versions prior to 2017.2.621 are considered cryptographically weak; this weakness is in the RadAsyncUpload function that uses encryption to secure uploaded files,” CISA added.

On April 14, the nation-state criminals used a brute force attack against the encryption key and gained unauthorized access to the Document Manager component within Telerik UI for ASP.NET AJAX.

After breaking in, they uploaded malicious scripts, downloaded and deleted sensitive files, made unauthorized modifications, and uploaded webshells to backdoor and remotely access the server.

“CISA and authoring organizations were unable to identify privilege escalation, lateral movement, or data exfiltration,” according to the alert. “However, the presence of webshells and file uploads indicated APT actors maintained access and had the potential to conduct additional malicious activity.”

And it also underscores the importance of patching.

Critical vulnerabilities: aka patch now

Speaking of patching, there’s a ton of critical fixes to implement now – if you haven’t already – across Microsoft, VMware, Fortinet, Adobe, and SAP software, and all of those are detailed in The Register‘s June Patch Tuesday coverage.

Plus, the ongoing MOVEit fiasco continues with a third vulnerability and a third fix.

And in other vulnerability news:

Google pushed a Chrome update that includes five security fixes. This includes one critical vulnerability, CVE-2023-3214, in the autofill payments function that could allow for arbitrary code execution.

Also, CISA identified six critical ICS vulnerabilities OT teams should be aware of: 

  • CVSS 9.8 – CVE-2023-1437: All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers that could allow an attacker to gain access to the remote file system, remotely execute commands and overwrite files.
  • Plus five critical bugs in Siemens products, including one 9.9-rated vulnerability that could lead to remote code execution or denial of service.

Fake security researchers target real ones on GitHub

Criminals posing as legit security researchers on GitHub and Twitter are pushing malicious repositories claiming to be proof-of-concept exploits for zero-day vulnerabilities.

Spoiler alert: these aren’t real PoCs but rather malware that infects Windows and Linux machines.

Security researchers at VulnCheck spotted the first malicious GitHub repository claiming to be a Signal zero-day in May. They reported the scam to GitHub, and it was taken down. The next day, VulnCheck discovered “an almost” identical repository purporting to be a WhatsApp zero-day.

This continued throughout May, with the researchers finding the fake repos, and GitHub removing them.

Apparently, the takedowns also forced the miscreants to put more effort into spreading malware. “The attacker has created half a dozen GitHub accounts and a handful of associated Twitter accounts,” VulnCheck researcher Jacob Baines said in a blog about the scam. “The accounts all pretend to be part of a non-existent security company called High Sierra Cyber Security.”

The accounts include profile pictures – at least one used a real headshot belonging to a Rapid7 employee – and had followers, Twitter handles, and (dead) links to the (fake) security company’s website.

The accounts attempt to trick real security researchers into downloading malicious binaries by tagging an exploit for a popular product like Chrome, Exchange, Discord, Signal or WhatsApp.

And while the Windows binary has a high detection rate on VirusTotal (43/71), VulnCheck notes that the Linux binary is stealthier (3/62), but “contains some very obvious strings indicating its nature.”

VulnCheck includes a list of seven phoney GitHub accounts, seven GitHub repositories, and four Twitter accounts, and cautions that if you’ve interacted with any of them, you may have been compromised.

Malware: hot. Botnets, backdoors: not

Ransomware is the most widespread malware-as-a-service (MaaS), accounting for 58 percent of all malware families between 2015 and 2022.

This is according to Kaspersky researchers, who based their latest report on 97 malware families circulating on the dark web.

Coming in second, infostealers made up 24 percent. The remaining 18 percent were split between botnets, loaders, and backdoors.

“Despite the fact that most of the malware families detected were ransomware, the most frequently mentioned families in dark web communities were infostealers,” the report indicates. “Ransomware ranks second in terms of activity on the dark web, showing an increase since 2021.”

Meanwhile, botnet, backdoor and loader mentions are on the decline. ®

ShareTweetSend
Previous Post

Packers’ Jordan Love wishes rival Bears fans a ‘Happy Father’s Day’

Next Post

Riakporhe talks potential Opetaia fight: “Once you break bones it’s never the same again”

Related News

Google engineer charged with insider trading after making .2M on Polymarket
Tech

Google engineer charged with insider trading after making $1.2M on Polymarket

May 27, 2026
The Osprey Farpoint 40 Has Been My Go-To Travel Bag for 8 Years
Tech

The Osprey Farpoint 40 Has Been My Go-To Travel Bag for 8 Years

May 27, 2026
Source: AI inference provider Baseten is in talks to raise B at a post-money valuation of B, up from B after its 0M Series E announced in January (The Information)
Tech

Source: AI inference provider Baseten is in talks to raise $1B at a post-money valuation of $11B, up from $5B after its $300M Series E announced in January (The Information)

May 26, 2026
New tune for Code.org’s Hadi Partovi: CEO of piano education venture with unique method and big ambitions
Tech

New tune for Code.org’s Hadi Partovi: CEO of piano education venture with unique method and big ambitions

May 26, 2026
Next Post
Riakporhe talks potential Opetaia fight: “Once you break bones it’s never the same again”

Riakporhe talks potential Opetaia fight: "Once you break bones it's never the same again"

Discussion about this post

Subscribe To Our Newsletters

    Customer Support


    1251 Wilcrest Drive
    Houston, Texas
    77042 USA
    Call-832.795.1420
    e-mail – news@theinsightpost.com

    Subscribe To Our Newsletters

      Categories

      • Africa
      • Africa-East
      • African Sports
      • American Sports
      • Arts
      • Asia
      • Australia
      • Business
      • Business Asia
      • Business- Africa
      • Canada
      • Defense
      • Education
      • Egypt
      • Energy
      • Entertainment
      • Europe
      • European Soccer
      • Finance
      • Germany
      • Ghana
      • Health
      • Insight
      • International
      • Investing
      • Japan
      • Latest Headlines
      • Life & Living
      • Markets
      • Mobile
      • Movies
      • New Zealand
      • Nigeria
      • Politics
      • Scholarships
      • Science
      • South Africa
      • South America
      • Sports
      • Tech
      • Travel
      • Travel-Africa
      • UK
      • USA
      • Weather
      • World
      No Result
      View All Result

      Recent News

      TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

      TX Rep. Brandon Gill Mocks James Talarico Over Fauci Action Figure Post

      July 30, 2026
      Secretary-General of ASEAN receives the Governor of the Banco Central de Timor-Leste

      Secretary-General of ASEAN receives the Governor of the Banco Central de Timor-Leste

      July 30, 2026
      Tunisia: Tunis Exchange Halts Trading After Market Drop Triggers Circuit Break

      Tunisia: Tunis Exchange Halts Trading After Market Drop Triggers Circuit Break

      July 30, 2026
      The Guyana Commission Of Inquiry Must Not Take The Place Of Immediate Reforms

      The Guyana Commission Of Inquiry Must Not Take The Place Of Immediate Reforms

      July 30, 2026
      • Home
      • Advertise With Us
      • About Us
      • Corporate
      • Consumer Rewards
      • Forum
      • Privacy Policy
      • Social Trends

      Theinsightpost ©2026 | All Rights Reserved. Theinsightpost is an Elnegy LLC company, registered in Texas, USA

      Welcome Back!

      Login to your account below

      Forgotten Password?

      Retrieve your password

      Please enter your username or email address to reset your password.

      Log In

      Add New Playlist

      We are using cookies to give you the best experience on our website.

      You can find out more about which cookies we are using or switch them off in .

      No Result
      View All Result
      • Home
      • Insight
      • Blog
      • Business
      • Entertainment
      • Health
      • Politics
      • Shop
        • Gift Shop
        • Value Shop
        • Store
        • Bargain Shop
        • Discount
      • Sports
      • Tech
      • Travel
      • USA
      • Video
      • World
        • Asia
        • Africa
        • South America
        • North America
        • Europe
        • Oceania

      Theinsightpost ©2026 | All Rights Reserved. Theinsightpost is an Elnegy LLC company, registered in Texas, USA

      The Insight Post
      Powered by  GDPR Cookie Compliance
      Privacy Overview

      This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

      Strictly Necessary Cookies

      Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

      Cookie Policy

      More information about our Cookie Policy