{"id":23587,"date":"2021-08-20T07:07:04","date_gmt":"2021-08-20T11:07:04","guid":{"rendered":"https:\/\/devopsnews.online\/?p=23587"},"modified":"2021-08-20T07:07:04","modified_gmt":"2021-08-20T11:07:04","slug":"cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau","status":"publish","type":"post","link":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/","title":{"rendered":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau"},"content":{"rendered":"

A recent study by a government watchdog organization revealed that threats actors have exploited an unpatched Citrix flaw in order to breach the network of the US Census Bureau in January.<\/p>\n

Indeed, the attack was originally stopped before the hackers could steal data or install a backdoor. Yet, a flaw within the servers of the US Census Bureau, which hadn’t been fixed, allowed the cyber attackers to access the compromised systems. The Bureau is then criticized for not fixing the flaw beforehand as well as lagging in its discovery and reporting of the attack.<\/p>\n

It was found out that if the Bureau had coordinated with the team responsible for implementing the mitigation steps, then the attack could have been prevented.<\/p>\n

The report also showcased that the initial compromise at the Census Bureau was on servers that were used to provide the bureau\u2019s enterprise staff with remote-access capabilities to production, development, and lab networks. The attackers were then able to modify user account data on the systems to prepare for remote code execution, but they were successful in maintaining access to the system by creating a backdoor into the affected servers.<\/p>\n

Yet, the attackers were still able to make unauthorized changes to the remote-access servers, such as creating new user accounts but couldn’t establish a backdoor to communicate with the attacker\u2019s external command and control infrastructure.<\/p>\n

Thus, it was reported that by doing vulnerability scanning of the remote-access servers, the Bureau could have mitigated the attack before it happened. It has also not reported the incident as soon as it should have done, which gave more opportunities to the threat actors.<\/p>\n

 <\/p>\n","protected":false},"excerpt":{"rendered":"

A recent study by a government watchdog organization revealed that threats actors have exploited an unpatched Citrix flaw in order to breach the network of the US Census Bureau in January. Indeed, the attack was originally stopped before the hackers could steal data or install a backdoor. Yet, a flaw within the servers of the…<\/p>\n","protected":false},"author":123458,"featured_media":23588,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","pmpro_default_level":"","footnotes":""},"categories":[3239,1158],"tags":[3597,721,3661,112,27,1064],"yoast_head":"\nCyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America\" \/>\n<meta property=\"og:description\" content=\"A recent study by a government watchdog organization revealed that threats actors have exploited an unpatched Citrix flaw in order to breach the network of the US Census Bureau in January. Indeed, the attack was originally stopped before the hackers could steal data or install a backdoor. Yet, a flaw within the servers of the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\" \/>\n<meta property=\"og:site_name\" content=\"DevOps Online North America\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-20T11:07:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Yashesh Patel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:site\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yashesh Patel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\"},\"author\":{\"name\":\"Yashesh Patel\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\"},\"headline\":\"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau\",\"datePublished\":\"2021-08-20T11:07:04+00:00\",\"dateModified\":\"2021-08-20T11:07:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\"},\"wordCount\":285,\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg\",\"keywords\":[\"cyber\",\"cyberattack\",\"flaw\",\"security\",\"software\",\"us\"],\"articleSection\":[\"News\",\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\",\"url\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\",\"name\":\"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg\",\"datePublished\":\"2021-08-20T11:07:04+00:00\",\"dateModified\":\"2021-08-20T11:07:04+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg\",\"width\":2560,\"height\":1707},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/devopsnews.online\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/devopsnews.online\/#website\",\"url\":\"https:\/\/devopsnews.online\/\",\"name\":\"DevOps Online North America\",\"description\":\"by 31 Media Ltd.\",\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/devopsnews.online\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/devopsnews.online\/#organization\",\"name\":\"DevOps Online North America\",\"url\":\"https:\/\/devopsnews.online\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"width\":198,\"height\":64,\"caption\":\"DevOps Online North America\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/DevOpsAmerica\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\",\"name\":\"Yashesh Patel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"caption\":\"Yashesh Patel\"},\"sameAs\":[\"https:\/\/devopsnews.online\"],\"url\":\"https:\/\/devopsnews.online\/author\/yashesh-patel\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/","og_locale":"en_US","og_type":"article","og_title":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America","og_description":"A recent study by a government watchdog organization revealed that threats actors have exploited an unpatched Citrix flaw in order to breach the network of the US Census Bureau in January. Indeed, the attack was originally stopped before the hackers could steal data or install a backdoor. Yet, a flaw within the servers of the...","og_url":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/","og_site_name":"DevOps Online North America","article_published_time":"2021-08-20T11:07:04+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg","type":"image\/jpeg"}],"author":"Yashesh Patel","twitter_card":"summary_large_image","twitter_creator":"@DevOpsAmerica","twitter_site":"@DevOpsAmerica","twitter_misc":{"Written by":"Yashesh Patel","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#article","isPartOf":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/"},"author":{"name":"Yashesh Patel","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435"},"headline":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau","datePublished":"2021-08-20T11:07:04+00:00","dateModified":"2021-08-20T11:07:04+00:00","mainEntityOfPage":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/"},"wordCount":285,"publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"image":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg","keywords":["cyber","cyberattack","flaw","security","software","us"],"articleSection":["News","Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/","url":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/","name":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau - DevOps Online North America","isPartOf":{"@id":"https:\/\/devopsnews.online\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage"},"image":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg","datePublished":"2021-08-20T11:07:04+00:00","dateModified":"2021-08-20T11:07:04+00:00","breadcrumb":{"@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#primaryimage","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2021\/08\/philipp-katzenberger-Uiw1A9slks-unsplash-scaled.jpg","width":2560,"height":1707},{"@type":"BreadcrumbList","@id":"https:\/\/devopsnews.online\/cyberattacks-to-have-exploited-an-unpatched-flaw-within-the-us-census-bureau\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devopsnews.online\/"},{"@type":"ListItem","position":2,"name":"Cyberattacks to have exploited an unpatched flaw within the US Census Bureau"}]},{"@type":"WebSite","@id":"https:\/\/devopsnews.online\/#website","url":"https:\/\/devopsnews.online\/","name":"DevOps Online North America","description":"by 31 Media Ltd.","publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devopsnews.online\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/devopsnews.online\/#organization","name":"DevOps Online North America","url":"https:\/\/devopsnews.online\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","width":198,"height":64,"caption":"DevOps Online North America"},"image":{"@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/DevOpsAmerica"]},{"@type":"Person","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435","name":"Yashesh Patel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","caption":"Yashesh Patel"},"sameAs":["https:\/\/devopsnews.online"],"url":"https:\/\/devopsnews.online\/author\/yashesh-patel\/"}]}},"_links":{"self":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/23587"}],"collection":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/users\/123458"}],"replies":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/comments?post=23587"}],"version-history":[{"count":1,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/23587\/revisions"}],"predecessor-version":[{"id":23589,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/23587\/revisions\/23589"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media\/23588"}],"wp:attachment":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media?parent=23587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/categories?post=23587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/tags?post=23587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}