2024-04-22
MITRE Discloses R&D Network Breach
MITRE has disclosed that its Networked Experimentation, Research, and Virtualization Environment (NERVE) research, development, and prototyping collaborative network was compromised. Initial access to the unclassified system is believed to have been achieved through vulnerabilities in Ivanti Connect Secure VPN devices and conducted by a threat actor working on behalf of a nation-state. While the attack occurred in January, MITRE did not become aware of the incident until recently. MITRE took the affected network offline while investigating.
Editor's Note
The attackers leveraged CVE-20232-46805 and CVE-2024-21887 to bypass authentication and run arbitrary commands, then moved laterally to infiltrate their VMware infrastructure using a compromised administrator credential. MITRE is no different than the rest of us; we all need to keep an eye on both updating systems as well as credential strength. The attack was limited to this R&D network, not impacting their core enterprise network or partner systems. The question here is do you have networks you've deemed low risk and are you comfortable with your ability to secure and detect compromise there, to include publicity related to a compromise?
Lee Neely
Just a historical note: 35 years ago, Cliff Stoll's book The Cuckoos Egg: Tracking a Spy Through the Maze of Computer Espionage came out, detailing how German hackers broke into Mitre and accessed all kinds of information from there. Remote access that was not sufficiently protected was the problem back then, too.
John Pescatore
Given MITRE's position as a federally funded research and development center (FFRDC), this attack has garnered much attention. MITRE is to be applauded for communicating details of the attack. Let's hope they continue by fully explaining how the attackers got around its MFA system and were able to operate undetected for three months. There must be best practices that enhance enterprise security we can learn from those details.
Curtis Dukes
The question isn't when/how/who breached them as much as how they respond and what their outbound communications will be.
Moses Frost
Read more in
Medium: Advanced Cyber Threats Impact Even the Most Prepared
MITRE: MITRE Response to Cyber Attack in One of Its R&D Networks
Security Week: MITRE Hacked by State-Sponsored Group via Ivanti Zero-Days
SC Magazine: MITRE research and prototyping network breached via Ivanti zero-days
Bleeping Computer: MITRE says state hackers breached its network via Ivanti zero-days
Gov Infosecurity: Mitre Says Hackers Breached Unclassified R&D Network
The Hacker News: MITRE Corporation Breached by Nation-State Hackers Exploiting Ivanti Flaws