06/16/2023
At the moment, not much is known other than the fact that several large and level organizations have been hit. Some and some . Among these are the and the .
Data was stolen from these organizations through the use of a backend exploit of the vulnerability that is susceptible to remote injection. This vulnerability is known as CVE-2023-34362.
The vulnerability allows for the injection of a (or a script that is deplpyed through the web to execute a function). Using this script which was called they were able to access unauthorized areas of the software known as (In use by the govt since 2002) and create administrator profiles to begin stealing information and data from the orgs utilizing it.
Its unconfirmed what information they've stolen and where it will go, but they're threatening to publish all of it on the if they aren't given an unspecified ransom. Naturally, I assume a lot of it will also be sold to foreign govts as well for more profit, assuming the hit wasn't commissioned and paid for up front already.
The founder of the company, , which created this software that's widely used is Joseph Alsop and he has been a prominent donor to campaigns since Hillary Clinton's 2000 Senatorial run on through 's recent run. Possibly an inflencing factor in the purchase of the software by the US Govt.
This comes as multiple dangerous groups threaten to shut down the entire in the next 24hrs. in an effort to supposedly put a stop to the effort.