The top U.S. cyber watchdog agency issued an emergency directive Friday, mandating that all federal agencies protect themselves against a dangerous vulnerability in a popular software program. The watchdog said it is conducting investigations into whether China had used the program to spy on the agencies.

The program used by the agencies is called Ivanti Connect Secure, which allows employees to remotely connect to work. A devastating vulnerability in the program, first discovered in December by the cybersecurity company Volexity, can grant hackers significant access to the businesses or government agencies that use it and allows for the creation of additional back doors to return later.

As news of the vulnerability has become widespread, at least 1,700 known organizations around the world have been hacked with it, Volexity has found.

In a press call with reporters late Friday afternoon, Eric Goldstein, the executive assistant director at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), said that hackers have learned about the vulnerability and increasingly have tried to hack companies and government agencies that use Connect Secure.

“We have observed additional targeting of federal agencies as part of the broader opportunity campaign at this point. Each of those instances are under investigation by CISA and the relevant agency,” Goldstein said.

Someone tried to use the Ivanti flaw to try to hack some federal agencies, Goldstein said, though it wasn’t yet clear if any had been successful. Around 15 agencies use the software, he said.

The hacking campaign echoes a strikingly similar one in 2021, when CISA announced that a vulnerability in an earlier version of the same program, at the time called Pulse Secure, had enabled hackers to gain access to multiple federal U.S. agencies. The cybersecurity company Mandiant, now owned by Google, said at the time that the hackers who had gained access to federal systems were members of a Chinese intelligence service conducting espionage.

A spokesperson for China’s embassy in Washington said in an email that “the Chinese government’s position on cyber security is consistent and clear. We have always firmly opposed and cracked down on all forms of cyber hacking in accordance with the law. The remarks by the U.S. side is completely distorting the truth.”

deflected that claim at the time, and often disputes the frequent accusations of cyberespionage made by U.S. and other Western officials and Western cybersecurity companies. The embassy did not immediately reply to a request for comment about CISA’s investigation.

Goldstein stopped short of blaming China for the most recent attempts, but said that what his agency had seen “would be consistent with what we have seen from PRC actors,” using an acronym for the country’s official name, the People’s Republic of China.

“At this time, we do not have any evidence to suggest that PRC actors have used these vulnerabilities to exploit federal agencies. But of course, we are focused on that very issue and driving urgent mitigation to ensure that both our federal networks and critical infrastructure are taking the right steps in response,” he said.

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like
Chicago crime: Sketch shows suspect of sexual assault at LaBagh Woods, Forest Preserves of Cook County police say

Urgent Update: Police Release Sketch of LaBagh Woods Sexual Assault Suspect in Chicago

CHICAGO (WLS) — In a recent development, investigators have unveiled an updated…
UC Berkeley graduate denied diploma on stage over Palestinian flag

UC Berkeley Graduate Denied Diploma Onstage for Displaying Palestinian Flag: A Controversial Stand for Free Speech?

In Berkeley, a graduate was denied their diploma during the ceremony for…
Gavin Newsom ripped by Democrats for $20M 'Governor's legacy fund'

Democrats Slam Gavin Newsom Over Controversial $20M ‘Governor’s Legacy Fund’: What You Need to Know

In a move that has stirred discontent among his Democratic peers, Gavin…
Woman killed by flying restaurant umbrella in freak accident at South Carolina lakeside restaurant

Tragic Incident at South Carolina Lakeside Restaurant: Woman Fatally Struck by Windborne Umbrella

A tragic and unusual accident occurred in a quaint lakeside town in…
Supreme Court rejects Florida's attempt to sue California and Washington over immigrant truck drivers

Supreme Court Dismisses Florida’s Lawsuit Against California and Washington Regarding Immigrant Truck Drivers

Washington — On Tuesday, the Supreme Court dismissed Florida’s attempt to initiate…
Orange County chemical leak evacuations end as officials say no more danger to public

Orange County Officials Declare End to Evacuations Following Chemical Leak, Ensuring Public Safety

Residents of Southern California can finally breathe a sigh of relief as…
New UFO videos solicit baffled explanations ranging from angels and demons to jetpacks and balloons

Mysterious UFO Videos Spark Debate: Are They Angels, Jetpacks, or Just Balloons?

The latest release of UFO disclosure files by former President Trump sparked…
Trump to head to Walter Reed for

Trump Scheduled to Visit Walter Reed Medical Center for Evaluation

Washington — President Trump is scheduled to visit the Walter Reed National…
Skydiver dies after midair collision with another jumper during group jump in Washington state

Tragic Skydiving Accident in Washington: Midair Collision Claims Life of Jumper

A tragic skydiving accident claimed the life of a participant on Sunday…
America's schools face a backlash on digital devices as screens saturate classrooms

Backlash Grows as Digital Device Overload Saturates America’s Classrooms

Not long ago, the trend in American public schools was to ensure…
Brad Pitt and Angelina Jolie's son Knox debuts shocking new hairstyle

Knox Jolie-Pitt Unveils Dramatic New Hairstyle, Sparking Buzz Across Social Media

Brad Pitt and Angelina Jolie’s youngest son, Knox Jolie-Pitt, made waves over…
Supreme Court denies NFL’s bid to keep former Dolphins coach Brian Flores' discrimination lawsuit from heading to court

Supreme Court Rejects NFL’s Attempt to Block Former Dolphins Coach Brian Flores’ Discrimination Lawsuit from Proceeding

The Supreme Court has turned down the NFL’s appeal to prevent the…