TLP: CLEAR
 
 
Greetings state, local, tribal, and territorial government partners,
 
Today, CISA   released   a Cybersecurity Advisory (CSA), Threat   Actors Exploit Adobe ColdFusion CVE-2023-26360 for Initial Access to Government Servers, to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). The vulnerability   in ColdFusion (CVE-2023-26360)   presents as an improper access control issue and exploitation of this CVE can result in arbitrary code execution.
 
CISA encourages network defenders and critical infrastructure organizations to review the CSA to improve their cybersecurity posture and protect against similar exploitation based on threat actor   activity. CISA also urges software manufacturers to incorporate secure-by-design and -default principles into their software development practices to limit the impact of threat actor activity.
 
For more guidance to protect against the most common and impactful threats, visit CISA’s Cross-Sector   Cybersecurity Performance Goals. For more information on Secure by Design, see CISA’s Secure   by Design webpage.
 
 
Multi-State Information Sharing and Analysis Center (MS-ISAC)
Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC)
31 Tech Valley Drive
East Greenbush, NY 12061
 
24×7 Security Operations Center
SOC@cisecurity.org –   1-866-787-4722
 
TLP: CLEAR
Information may be distributed without restriction, subject to standard copyright rules.
 
Please send all opt out requests to  info@cisecurity.org.  
 
This message and attachments may contain confidential information. If it appears   that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
 
This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
  . . . . . 
