The Zerologon vulnerability Microsoft patched in Windows Server last month is actively being exploited in several attacks, Microsoft warned.
An intruder breached a federal agency’s internal network and accessed data files using compromised credentials and custom malware, the Cybersecurity and Infrastructure Security Agency said in an Analysis Report.
CISA alerted administrators that activity from the LokiBot information stealing trojan has been increasingly sharply since July.
The SAFE DATA Act is the latest attempt to pass a national privacy law, but it relies on notice-and-consent and does not apply to federal agencies.
Federal agencies have until the end of Monday to install fixes for a recently-fixed elevation of privilege vulnerability in Windows which could be used to take control of the entire network, CISA said in an emergency directive.