{"id":1714,"date":"2025-02-03T10:03:35","date_gmt":"2025-02-03T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/03\/beyondtrust-zero-day-breach-17-saas-customers-api-key-compromised\/"},"modified":"2025-02-03T10:03:35","modified_gmt":"2025-02-03T10:03:35","slug":"beyondtrust-zero-day-breach-17-saas-customers-api-key-compromised","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/03\/beyondtrust-zero-day-breach-17-saas-customers-api-key-compromised\/","title":{"rendered":"BeyondTrust Zero-Day Breach \u2013 17 SaaS Customers API Key Compromised"},"content":{"rendered":"<p>    BeyondTrust Zero-Day Breach \u2013 17 SaaS Customers API Key Compromised<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>BeyondTrust, a leading identity and access management firm, disclosed a critical security breach impacting 17 customers of its Remote Support <a href=\"https:\/\/cybersecuritynews.com\/new-itdr-platform-for-saas-at-black-hat-usa\/\" target=\"_blank\" rel=\"noreferrer noopener\">SaaS platform<\/a>.<\/p>\n<p>The breach was attributed to the exploitation of zero-day vulnerabilities and has since been linked to the China-based hacking group Silk Typhoon.\u00a0<\/p>\n<p>While U.S. federal agencies and law enforcement continue their investigations, BeyondTrust has taken measures to fix the issue.<\/p>\n<p>The breach was discovered after BeyondTrust saw unusual activity in their Remote Support SaaS system. A root cause analysis revealed that an infrastructure API key had been compromised by a <a href=\"https:\/\/cybersecuritynews.com\/apple-zero-day-vulnerability-iphone-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerability<\/a> in a third-party application.<\/p>\n<p>This allowed attackers to reset local application passwords and gain unauthorized access to certain Remote Support SaaS instances.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Exploiting Critical Zero-day Vulnerabilities<\/strong><\/h2>\n<p>The attackers exploited a critical zero-day vulnerability in a third-party application to access an online asset in BeyondTrust\u2019s <a href=\"https:\/\/cybersecuritynews.com\/aws-cdk-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS account<\/a>.\u00a0<\/p>\n<p>This access enabled them to obtain an infrastructure API key, which was then used against another AWS account operating the Remote Support infrastructure.\u00a0<\/p>\n<p>The two vulnerabilities identified during the investigation are:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/us-treasury-yellens-computer\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2024-12356<\/a>:<\/strong> A critical command injection flaw allowing unauthenticated attackers to execute <a href=\"https:\/\/cybersecuritynews.com\/flax-typhoon-abusing-operating-system\/\" target=\"_blank\" rel=\"noreferrer noopener\">operating system<\/a> commands remotely.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/us-treasury-yellens-computer\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2024-12686<\/a>:<\/strong> A medium-severity vulnerability enabling administrative users to upload malicious files and inject commands.<\/li>\n<\/ul>\n<p>Both vulnerabilities were actively exploited in the wild, prompting BeyondTrust to issue patches for all cloud-based instances while urging self-hosted customers to apply updates manually.<\/p>\n<p>The attack has been attributed to Silk Typhoon (formerly Hafnium), a China-linked cyber-espionage group known for targeting government entities and critical infrastructure.\u00a0<\/p>\n<p>The group reportedly accessed unclassified data from the U.S. Treasury Department using the stolen API key.<\/p>\n<p>\u201cNo BeyondTrust products outside of <a href=\"https:\/\/cybersecuritynews.com\/simplehelp-remote-support-software-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Remote Support<\/a> SaaS were affected. No FedRAMP instances were affected. No other BeyondTrust systems were compromised, and ransomware was not involved\u201d, the company said.<\/p>\n<p>BeyondTrust implemented several immediate actions following the breach:<\/p>\n<ul class=\"wp-block-list\">\n<li>Revoked the compromised API key.<\/li>\n<li>Quarantined affected customer instances and provided alternative Remote Support SaaS environments.<\/li>\n<li>Engaged a third-party forensics firm for investigation.<\/li>\n<li>Coordinated with federal law enforcement and shared threat intelligence with relevant agencies<\/li>\n<\/ul>\n<p>Additionally, BeyondTrust applied patches for <a href=\"https:\/\/www.beyondtrust.com\/remote-support-saas-service-security-investigation\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered<\/a> vulnerabilities across all SaaS instances and continues to support affected customers by providing logs, indicators of compromise (IOCs), and other <a href=\"https:\/\/cybersecuritynews.com\/what-is-digital-forensics\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic<\/a> artifacts.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Recommendations<\/strong><\/h2>\n<ul class=\"wp-block-list\">\n<li>Keeping self-hosted instances up-to-date with patches.<\/li>\n<li>Leveraging external authentication providers like SAML over local accounts.<\/li>\n<li>Configuring outbound event notifications for session activities.<\/li>\n<li>Integrating with SIEM systems for monitoring suspicious activity.<\/li>\n<li>Enforcing least privilege principles for user roles and endpoint access<\/li>\n<\/ul>\n<p>This breach underscores the growing risks associated with non-human identities, such as API keys, when combined with software vulnerabilities. Organizations are urged to adopt robust security practices to safeguard against similar exploits.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013\u00a0Analyse Malware Files &amp; Links with ANY.RUN Sandox\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=meme&amp;utm_content=demo&amp;utm_term=030225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-zero-day-breach\/\">BeyondTrust Zero-Day Breach \u2013 17 SaaS Customers API Key Compromised<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-zero-day-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BeyondTrust Zero-Day Breach \u2013 17 SaaS Customers API Key Compromised BeyondTrust, a leading identity and access management firm, disclosed a critical security breach impacting 17 customers of its Remote Support SaaS platform. The breach was attributed to the exploitation of zero-day vulnerabilities and has since been linked to the China-based hacking group Silk Typhoon.\u00a0 While [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648,517],"tags":[130],"class_list":["post-1714","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1714"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1714"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1714\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}