The Cybersecurity & Infrastructure Security Agency and FBI today advised organizations to protect VMware Horizon servers from a Log4Shell vulnerability recently exploited by Iranian-sponsored actors. 

“This important advisory highlights how our cyber adversaries, in this case Iran, are exploiting third- and fourth-party software supply chain vulnerabilities to penetrate targeted organizations,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “This particular attack against a federal executive branch agency highlights that no organization is immune from cyberattacks, not even federal agencies protected by advanced federal network protection resources. These Iranian cyberthreat actors exploited a known Log4Shell vulnerability in an unpatched VMware Horizon server to gain access to the federal network, install other legitimate computer tools to steal credentials, move across the network and maintain persistence. This appears to be a ‘hybrid’ attack designed to generate illegal cryptocurrency proceeds while conducting cyber espionage operations. If updates or workarounds were not promptly applied after VMware released updates for Log4Shell in December 2021, treat those VMware Horizon systems as compromised and follow proactive incident response procedures.” 

Related News Articles

Headline
The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for…
Headline
The Department of Health and Human Services Health Sector Cybersecurity Coordination Center June 27 issued an alert about a critical vulnerability in MOVEit, a…
Headline
A joint report released June 26 by the Cybersecurity and Infrastructure Security Agency, FBI, the Australian Cyber Security Centre and Canadian Centre for…
Headline
The Health Information Sharing and Analysis Center June 27 issued a threat bulletin alerting the health sector to active cyberthreats exploiting TeamViewer. H-…
Headline
The FBI and Department of Health and Human Services June 24 released an advisory about cyberthreat actors targeting health care organizations in attempts to…
Headline
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) this week released an advisory about Qilin, formerly "Agenda…