The top U.S. cyber watchdog agency issued an emergency directive Friday, mandating that all federal agencies protect themselves against a dangerous vulnerability in a popular software program. The watchdog said it is conducting investigations into whether China had used the program to spy on the agencies.

The program used by the agencies is called Ivanti Connect Secure, which allows employees to remotely connect to work. A devastating vulnerability in the program, first discovered in December by the cybersecurity company Volexity, can grant hackers significant access to the businesses or government agencies that use it and allows for the creation of additional back doors to return later.

As news of the vulnerability has become widespread, at least 1,700 known organizations around the world have been hacked with it, Volexity has found.

In a press call with reporters late Friday afternoon, Eric Goldstein, the executive assistant director at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), said that hackers have learned about the vulnerability and increasingly have tried to hack companies and government agencies that use Connect Secure.

“We have observed additional targeting of federal agencies as part of the broader opportunity campaign at this point. Each of those instances are under investigation by CISA and the relevant agency,” Goldstein said.

Someone tried to use the Ivanti flaw to try to hack some federal agencies, Goldstein said, though it wasn’t yet clear if any had been successful. Around 15 agencies use the software, he said.

The hacking campaign echoes a strikingly similar one in 2021, when CISA announced that a vulnerability in an earlier version of the same program, at the time called Pulse Secure, had enabled hackers to gain access to multiple federal U.S. agencies. The cybersecurity company Mandiant, now owned by Google, said at the time that the hackers who had gained access to federal systems were members of a Chinese intelligence service conducting espionage.

A spokesperson for China’s embassy in Washington said in an email that “the Chinese government’s position on cyber security is consistent and clear. We have always firmly opposed and cracked down on all forms of cyber hacking in accordance with the law. The remarks by the U.S. side is completely distorting the truth.”

deflected that claim at the time, and often disputes the frequent accusations of cyberespionage made by U.S. and other Western officials and Western cybersecurity companies. The embassy did not immediately reply to a request for comment about CISA’s investigation.

Goldstein stopped short of blaming China for the most recent attempts, but said that what his agency had seen “would be consistent with what we have seen from PRC actors,” using an acronym for the country’s official name, the People’s Republic of China.

“At this time, we do not have any evidence to suggest that PRC actors have used these vulnerabilities to exploit federal agencies. But of course, we are focused on that very issue and driving urgent mitigation to ensure that both our federal networks and critical infrastructure are taking the right steps in response,” he said.

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like
"Star Wars" lightsaber, "Wizard of Oz" witch hat and more iconic film props going up for auction

Iconic Movie Props Head to Auction: Star Wars Lightsaber, Wizard of Oz Witch Hat and More

A lightsaber tied to one of the most unforgettable moments in George…
South Carolina personal trainer goes missing, last spotted walking toward wooded area

South Carolina Personal Trainer Reported Missing After Last Seen Heading Toward Wooded Area

A South Carolina woman has been missing since last week after she…
Teen accused of killing stepsister on Carnival cruise ship ordered detained before murder trial

Teen Held Before Trial in Carnival Cruise Ship Stepsister Murder Case

A teenage boy accused of killing 18-year-old Anna Kepner on a Carnival…
Why the millionaire co-founder of e.l.f. Cosmetics left his beauty empire to become a Catholic priest

Why e.l.f. Cosmetics’ Millionaire Co-Founder Walked Away From Business to Become a Catholic Priest

Scott Vincent Borba helped build e.l.f. Cosmetics into a major beauty brand,…
Russia linked to arson attacks on properties connected to UK PM Keir Starmer, police say

Police Probe Russia Link in Arson Attacks on Properties Tied to UK PM Keir Starmer

British authorities on Monday disclosed fresh details about a string of arson…
SpaceX to buy AI coding assistant Cursor for $60 billion

SpaceX Eyes $60 Billion Acquisition of AI Coding Assistant Cursor in Landmark Tech Deal

Days after a blockbuster initial public offering, SpaceX announced Tuesday that it…
Ridglan Farms update: Wisconsin beagle research facility that drew protests is closing as Big Dog Ranch Rescue group takes in dogs

Wisconsin Beagle Research Facility Ridglan Farms to Close as Big Dog Ranch Rescue Takes In Dogs

A controversial beagle breeding and research facility in Wisconsin is shutting down,…
BASE jumping accident kills 2 including extreme athlete Andy Lewis, who performed with Madonna at Super Bowl

Andy Lewis Among 2 Killed in BASE Jumping Accident; Madonna Super Bowl Performer Dead at 37

Two people were killed in a BASE jumping accident over the weekend…
8 people killed in B-52 bomber crash during 'routine test mission,' Edwards Air Force Base in Kern County, California confirms

8 Killed in B-52 Bomber Crash During Routine Test Mission, Edwards Air Force Base Confirms

EDWARDS AFB, Calif. (KABC) — Eight people were killed after an Air…
Savannah Guthrie reveals new details in mom’s disappearance that don’t add up as questions haunt case: expert

Nancy Guthrie Mystery Reveals Emerging Threat Catching Unsuspecting Americans Off Guard

A possible “wrench attack” motive is drawing increased attention in the Feb.…
Chicago shooting: Bicyclist shot, killed in Grant Park, police say

Grant Park Shooting: Bicyclist Fatally Shot in Chicago, Police Investigate

CHICAGO (WLS) — A 27-year-old man was fatally shot early Tuesday while…
Yum! Brands sells struggling Pizza Hut in $2.7 billion deal

Yum! Brands Strikes $2.7 Billion Deal to Sell Struggling Pizza Hut Unit

Yum! Brands announced Tuesday that it has agreed to sell Pizza Hut…