If you're wondering which bugs in particular miscreants are exploiting to break into, or attempt to break into, US government networks, wonder no more. And then make sure you've patched them.
Uncle Sam's Dept of Homeland Security has this month identified at least six possible routes into the nation's computer systems, and the method used to gain total control over the machines once inside. Those six vulnerabilities are...
...plus CVE-2020-1472, aka ZeroLogon, in Microsoft Windows, which is exploited to escalate one's privileges, via the Netlogon protocol, to domain-level administrator access, granting total control.
So, for instance, we're told, miscreants can use, and have used, the Fortinet bug to obtain the usernames and plain-text passwords of SSL VPN users from the gateway's memory, log in as them, and then use ZeroLogon to infiltrate the network's central ..