Mandiant’s research indicated that the attackers were exploiting end-of-life Juniper MX routers running older versions of Junos OS and were able to bypass the operating system’s Veriexec security subsystem by injecting malicious code into legitimate system processes. Mandiant, a Google Cloud Security threat intelligence unit, uncovered a cyber espionage campaign, attributing it to a China-linked hacking group known as UNC3886, that targeted outdated Juniper routers by using sophisticated malware. Mandiant recommends that organizations upgrade all Juniper routers to supported versions with the latest security patches to prevent exploitation of known vulnerabilities. Juniper Networks has released security advisories JSA93446 and JSA5385 to address the vulnerability and provide guidance to users. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. It is important to note that the vulnerability is not exploitable through the Junos command-line interface (CLI), limiting the attack vector to those with significant system access. The Cybersecurity and Infrastructure Security Agency (CISA) has warned about an actively exploited zero-day vulnerability in Apple's WebKit browser engine, tracked as CVE-2025-24201. Binding Operational Directive (BOD) 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the specified due date to protect FCEB networks against active threats. The company recommends that users upgrade Junos OS to the releases detailed in JSA93446, which include patches for CVE-2025-21590 and updated anti-malware signatures. While the complete list of affected platforms is still being investigated, Juniper recommends restricting shell access to trusted users only. CISA has issued a warning regarding a newly discovered vulnerability affecting Juniper Networks’ Junos OS. CISA has added CVE-2025-21590 to its Known Exploited Vulnerabilities Catalog, emphasizing the significant risk it poses to the federal enterprise. The vulnerability stems from improperly imposed security restrictions within Junos OS.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 13 Mar 2025 16:35:11 +0000