Story perspectives
China-Linked Breach Exposes U.S. Agency for Weeks
9/24/2025
38 7
1 of 1
Story summary
- The Cybersecurity and Infrastructure Security Agency (CISA) reports a U.S. agency breach exploited GeoServer CVE-2024-36401, enabling access to servers and web shells for over three weeks.
- The intrusion remained undetected until July 31, 2024, despite endpoint detection and response (EDR).
- CISA cites patch delays, untested incident plans, and weak EDR monitoring.
- The attack used China-linked techniques. No group was identified.
