Today: 2 August 2025
18 November 2021
1 min read

Iran-backed hackers exploiting Microsoft, Fortinet bugs

The group has highlighted the ongoing malicious cyber activity by an advanced persistent threat (APT) group associated with the government of Iran…reports Asian Lite News

Federal cyber agencies across the US, the UK and Australia have warned that the Iranian government-sponsored hackers are exploiting several vulnerabilities in Microsoft Exchange email server and cyber security company Fortinet to perform malicious activities, which include deploying ransomware.

In an advisory, The US Cybersecurity and Infrastructure Security Agency (CISA) said that they have highlighted the ongoing malicious cyber activity by an advanced persistent threat (APT) group associated with the government of Iran.

“The Federal Bureau of Investigation (FBI) and CISA have observed this Iranian government-sponsored APT exploit Fortinet and Microsoft Exchange ProxyShell vulnerabilities to gain initial access to systems in advance of follow-on operations, which include deploying ransomware,” the CISA said in a statement late on Wednesday.

By breaking into systems through Fortinet vulnerabilities, cybercriminals can “conduct data exfiltration, data encryption, or other malicious activity.”

The CISA, the FBI, the Australian Cyber Security Centre (ACSC), and the UK’s National Cyber Security Centre (NCSC) have released the joint cybersecurity advisory.

“ACSC is also aware this APT group has used the same Microsoft Exchange vulnerability in Australia,” it read.

The Iranian government-sponsored APT group has exploited Fortinet vulnerabilities since at least March 2021 and a Microsoft Exchange ProxyShell vulnerability since at least October 2021.

The APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors, including the transportation sector and the healthcare and public health sector, as well as Australian organisations.

ALSO READ: Iran reckons India’s role to help peace and stability is very important

“These Iranian government-sponsored APT actors can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware, and extortion,” the advisory read.

In April this year, the FBI and CISA issued warnings about the vulnerabilities in Fortinet gear being actively exploited.

Microsoft on Wednesday issued its own warning of six Iranian groups using vulnerabilities in the same pair of products to deploy ransomware.

Previous Story

Dragon’s trap choke Lanka

Next Story

India at UNSC meet calls for inclusive dispensation in Afghanistan

Latest from Arab News

Famine grips Gaza, WHO warns

WHO said Gaza’s population is facing acute food insecurity under the Integrated Food Security Phase Classification…reports Asian Lite News The World Health Organisation (WHO) has issued its starkest warning yet about the

Lifeline from UAE to Gaza

UAE’s Operation Chivalrous Knight 3 sustains Gaza’s collapsing health system with hospitals, treatment, aid, and vaccines, offering vital relief to thousands amid deepening crisis….reports Asian Lite News The United Arab Emirates has

More Nations Support Palestine State

UAE has hailed the intention of countries such as Malta, Canada, Australia, Andorra, Finland, Iceland, Luxembourg, New Zealand, Portugal, and San Marino to recognise Palestine….reports Asian Lite News The UAE has welcomed

Trump envoy in Israel as Gaza starves

Witkoff is expected to visit US-backed food distribution efforts in Gaza run by the Gaza Humanitarian Foundation (GHF). As the humanitarian catastrophe in Gaza worsens, US President Donald Trump’s special envoy Steve

UK PM, Oman’s Sultan agree to deepen ties

Sultan Haitham welcomes UK’s steps towards recognising Palestine, reaffirms Oman’s support for a two-state solution and lasting peace in the Middle East..reports Asian Lite News Prime Minister Keir Starmer and Oman’s Sultan
Go toTop

Don't Miss

Dubai offers $100 million for the world’s largest blue sapphire found in Sri Lanka

The owner of the stone recently said that one of

Protestors set fire to Australia’s Old Parliament House

Protesters on Thursday set fire to the Old Parliament House