U.S. govt reveals top security flaws exploited by Chinese hackers since 2020

Share post:

Top security agencies in the US have published the top security vulnerabilities exploited by the People’s Republic of China (PRC) hackers since 2020. NSA, CISA and FBI confirm once again that these Chinese-sponsored hackers are targeting U.S. and allied networks and technology companies in order to gain access and steal sensitive data.

Major flaws include: Apache Log4j (CVE-2021-44228) a remote code execution flaw; Pulse Connect Secure (CVE-2019-11510), an arbitrary file read flaw; GitLab CE/EE (CVE-2021-22205), a remote code execution bug; Atlassian (CVE-2022-26134), a remote code execution bug; Microsoft Exchange (CVE-2021-26855), a remote code execution bug; F5 Big-IP (CVE-2020-5902), a remote code execution flaw; VMware vCenter Server (CVE-2021-22005), an arbitrary file upload bug; Citrix ADC (CVE-2019-19781), a path traversal flaw; Cisco Hyperflex (CVE-2021-1407), a command line execution flaw; and Buffalo WSR (CVE-2021-20090), a relative path traversal flaw.

Others include Atlassian Confluence Server and Data Center (CVE-2021-26084), a remote code execution flaw; Hikvision Webserver (CVE-2021-36260), a command injection flaw; SitecoreXP (CVE-2021-42237), a remote code execution flaw; F5 Big-IP (CVE-2022-1388), a remote code execution flaw; Apache (CVE-2022-24112), an authentication bypass flaw; ZOHO (CVE-2021-40539), a remote code execution flaw; Microsoft (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) all remote code execution flaws; and Apache HTTP Server (CVE-2021-41773), a path traversal flaw.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 6, 2024 – Ransomware gang claims responsibility for attacking Italian healthcare service, Russian gang blamed for attacks in Europe, and...

Ransomware gang claims responsibility for attacking Italian healthcare service, Russian gang blamed for attacks in Europe, and more. Welcome...

Microsoft reveals critical security flaw affecting Android apps

Microsoft has identified a serious vulnerability in Android apps that could allow malicious software to hijack legitimate apps...

Chinese government websites “Riddled with security flaws” say researchers

A recent study conducted by researchers from the Harbin Institute of Technology reveals significant security issues plaguing Chinese...

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways