Oddbean new post about | logout
 Joint US and Japanese security advisory warn of attacks from a Chinese APT named BlackTech that likes to compromise routers at subsidiaries and then pivot to main corporate US/JP headquarters

The group has a craving for Cisco routers... nom nom nom

https://www.cisa.gov/news-events/alerts/2023/09/27/nsa-fbi-cisa-and-japanese-partners-release-advisory-prc-linked-cyber-actors 
 Cisco has responded to the joint US-JP security advisory that Chinese APT BlackTech is replacing Cisco router firmware in attacks:

"The most prevalent initial access vector in these attacks involves stolen or weak administrative credentials. As outlined in the report, certain configuration changes, such as disabling logging and downloading firmware, require administrative credentials. There is no indication that any Cisco vulnerabilities were exploited."

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023