Blog | G5 Cyber Security

Mandiant: Heartbleed Leads to Attack

Breach detection firm Mandiant: Attackers exploited Heartbleed flaw one day after its disclosure. Canadian authorities arrested a teenager this week for his alleged role in exploiting the vulnerability to steal data from the Canada Revenue Agency website. Attack bypassed multi-factor authentication as well as the VPN client software used to validate that systems connecting to the VPN are owned by the corporation and running specific security software. Attackers sent malformed “heartbeat” requests to the secure Web server running on the VPN device, which used a vulnerable version of OpenSSL.”]

Source: https://www.govinfosecurity.com/mandiant-heartbleed-leads-to-attack-a-6766

Exit mobile version