Tag / 5 entries / feed available

Zero-Day Vulnerability

5 of the 76 analyses in Data Breaches carry this tag. All 5 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

056

MOVEit Data Breach June 2023

Contained by: PEC

The June 2023 MOVEit data breach began with the exploitation of a zero-day SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer software; over 200 organizations were confirmed affected within the first weeks, a toll that climbed to more than 2,700 organizations and over 95 million individuals as disclosures continued into 2024. The Clop ransomware group was responsible, utilizing web shell deployment and data exfiltration methods to access and steal personal and sensitive information, highlighting substantial risks in application security and third-party systems.

035

Microsoft Exchange Server Breach

Prevented by: PEC, EGR

In January 2021, over 30,000 U.S. companies experienced a cyberattack on Microsoft Exchange email servers. The breach exploited several zero-day vulnerabilities, resulting in unauthorized email access and potentially sensitive data exposure. The attack was primarily attributed to the state-sponsored Hafnium group from China, leveraging server-side request forgery and other sophisticated methods.

022

NotPetya Ransomware Attack

Prevented by: PEC

The NotPetya ransomware attack in June 2017 caused extensive financial damage exceeding $10 billion by utilizing a compromised software update from MeDoc, a Ukrainian accounting software. The malware employed the EternalBlue exploit to propagate widely, primarily acting as a wiper rather than traditional ransomware. It severely disrupted corporate operations globally, affecting numerous high-profile organizations such as Maersk and FedEx, and has been attributed to state-sponsored actors linked to Russian military intelligence.

003

Google Aurora Incident

Prevented by: PEC, EGR

The Google Aurora Incident was a significant cyber attack in December 2009 targeting Google and other corporations. The attack, attributed to actors linked to the Chinese state, aimed to steal intellectual property and infiltrate Gmail accounts of Chinese human rights activists. Attackers exploited a zero-day vulnerability in Internet Explorer, using malware to gain unauthorized access and exfiltrate sensitive data.

RSS feed for this tag →

Now playing Bandcamp