Site navigation

European Governments Targeted in Zero-Day Attacks

Elizabeth Greenberg

,

zero-day attacks europe
The European Commission, two Dutch authorities, and a Finnish authority have released notices of data breaches.

The Europen Commission has revealed it is investigating a potential data breach into its central mobile device managing infrastrcuture, which could have exposed thousands of users’ personal details.

The incident occurred on 30 January but was concainted within nine hours, according to the Commission.

“The Commission takes seriously the security and resilience of its internal systems and data and will continue to monitor the situation. It will take all necessary measures to ensure the security of its systems,” it said.

“The incident will be thoroughly reviewed and will inform the Commission’s ongoing efforts to enhance its cybersecurity capabilities.”

The Commission also said that mobile device compromise was not detected in its review of the breach.

The Commission first released a statement on the breach on 6 February, which coincided with notificications from two Dutch authorities that had experienced a similar incident.

These incidents took place on 29 January, affecting the Dutch Council for the Judiciary and the Dutch Data Protection Authority. The 6 February notification said that the Dutch cybersecurity authority was told by Ivanti, the IT service management company, about vulnerabilities in its Endpoint Manager Mobile (EPMM) service.

Further, the Finnish government’s information technology centre said that it discovered a breach targeting its “mobile device management service” on 30 January. As many as 50,000 government workers may have had their data exposed in this breach, the Finnish authority said.

So far, only the Dutch authorities have referenced Ivanti in relation to the breaches.

On 29 January, Ivanti released two zero-day bug patches in EPMM, saying: “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.”

The notice warned that successful exploitation of the vulnerabilities “coudl lead to unathenticated remote code execution.”

“While the European Commission haven’t reported any substantial impacts from this breach, it does beg a number of worrying questions surrounding current EPMM deployments,” David Neeson, Deputy SOC Team Lead at Barrier Networks:

“Ivanti have not released a full set of fixes for the EPMM flaws, instead issuing patches while they work on a comprehensive fix in the coming months. It’s not clear whether these had been applied to the EC’s EPMM deployments, and it’s worrying if not, given the patches wouldn’t have required downtime to apply.


Recommended reading


“However, the security patches issued by Ivanti will revert when updating to different versions of the software, and customers also require different patches in order to target different versions of EPMM. This may be technically required and a necessary expedient, but it’s a fragmented approach to fixing such severe flaws and arguably leaves customers at substantial risk, much more than a comprehensive update would. Ivanti says that it’s working on such an update, but fixes for these issues alone should warrant something more immediate.

“This form of attack ultimately relies on speed, and on catching targets off-guard. It may be the case that patching was in progress on the EC’s systems, but not applied across all the organisation’s devices, in which case attackers would have been able to access at least some systems.

“The attack also appears highly targeted, affecting only a small number of Ivanti’s customers; the targeting of bodies like the EC could indicate the threat actors are working for political ends. The attackers are no doubt highly motivated, and any other government agencies currently using EPMM, both in the EU and abroad, should ensure their deployments are patched immediately.

“Ivanti have also issued an RPM tool designed to aid in the detection of EPMM breaches, which the company recommends customers run alongside normal security protocols. While this isn’t a preventative, it should at least give a firm indication of specific signals related to the exploitation of these flaws, and customers should make use of this if they suspect a breach has occurred.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data