Agencies in the U.S. and United Kingdom this week released an advisory detailing tactics used to exploit a known vulnerability in Cisco routers to deploy malware and recommendations to protect vulnerable Cisco devices. 

“This joint U.S. and U.K. advisory cites with high confidence that elements of the Russian Military Intelligence Service have been exploiting a known vulnerability in Cisco network routers since at least 2017,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “Like the SolarWinds compromise, this highlights the ongoing targeting of strategic third-party network technology, which is widely present in government and private-sector networks. These strategic cyberattacks on the technology supply chain may give the Russian government a basis to conduct covert reconnaissance of sensitive networks, steal data and/or pre-position itself for future destructive cyberattacks. It is strongly recommended that the patch for vulnerability CVE-2017-6742 be implemented as soon as possible.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
A joint advisory issued the week of July 8 by the Cybersecurity and Infrastructure Security Agency, National Security Agency, FBI and several international…
Headline
The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for…
Headline
The Department of Health and Human Services Health Sector Cybersecurity Coordination Center June 27 issued an alert about a critical vulnerability in MOVEit, a…
Headline
A joint report released June 26 by the Cybersecurity and Infrastructure Security Agency, FBI, the Australian Cyber Security Centre and Canadian Centre for…
Headline
The Health Information Sharing and Analysis Center June 27 issued a threat bulletin alerting the health sector to active cyberthreats exploiting TeamViewer. H-…
Headline
The FBI and Department of Health and Human Services June 24 released an advisory about cyberthreat actors targeting health care organizations in attempts to…