CyberCX Hack Report: Insights from a year of offensive security testing

Nightmare before Christmas? Patch now to avoid a cyber crisis this holiday season

Threat Advisory

Microsoft Teams

This Threat Advisory was updated on 14 December 2022, following reports of vulnerability exploitation in FortiOS and Citrix appliances. On 13 December (around 0200 AEDT), Fortinet disclosed that recently patched CVE-2022-42475 is being actively exploited in limited attacks.[i] On 13 December (23:20 AEDT), the US National Security Agency (NSA) reported that CVE-2022-27518 in Citrix appliances is being actively exploited in targeted attacks by APT5.[ii] Both CVEs enable unauthenticated remote code execution (RCE). 


Published by Cyber Cyber Intelligence on 12 December 2022

 

Prawns, family barbecues and backyard cricket aren’t the only Christmas traditions for Australian and New Zealand cyber professionals. For years, cyber threat activity has spiked during the holiday season, increasing risk when many organisations have reduced staff and paused technology programs. 

Cyber risk can rise over the holiday season, especially for organisations that don’t use December to adequately prepare. Reduced staffing and technology change freezes during this time limit security teams’ ability to manage vulnerabilities, detect threats, respond to incidents and adapt to the always-changing cyber threat landscape.  

Criminal and nation-state hackers don’t pause at Christmas

Cyber threat actors see these organisational challenges as an opportunity. For several years, CyberCX Intelligence has observed cyber criminals and nation-state actors rapidly weaponise vulnerabilities that are disclosed late in the year and integrate exploits for these vulnerabilities into their tool chains. As a result, cyber security incidents often increase in December and January, including through the Christmas-New Year period.

 

Vulnerability exploitation events that have affected Australian and New Zealand organisations during the Christmas-New Year period.

 

Why we shouldn’t be complacent in 2022

In 2022, CyberCX Intelligence has observed significant shifts in the Australian and New Zealand threat landscape which likely foreshadow even higher cyber risk this holiday period than in previous years.  

These shifts include: 

 

Tips to protect your organisation (and your holidays)

Ensure that patching across your critical assets and systems is up-to-date

Update 1330 AEDT 14 December

Pay particular attention to internet-facing platforms such as:

Review and update your Cyber Security Incident Response Plans

At minimum, make sure your Plans:

 

i https://www.fortiguard.com/psirt/FG-IR-22-398 

ii https://media.defense.gov/2022/Dec/13/2003131586/-1/-1/0/CSA-APT5-CITRIXADC-V1.PDF 

iii https://www.fortiguard.com/psirt/FG-IR-22-398 

iv https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/ 

v https://media.defense.gov/2022/Dec/13/2003131586/-1/-1/0/CSA-APT5-CITRIXADC-V1.PDF 

 


 

Other Cyber Security Resources

Ready to get started?

Find out how CyberCX can help your organisation manage risk, respond to incidents and build cyber resilience.