Russian Foreign Intelligence Service Exploiting Five Publicly Known Vulnerabilities to Compromise U.S. and Allied Networks

Source: Federal Bureau of Investigation FBI Crime News

The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) jointly released a Cybersecurity Advisory, “Russian SVR Targets U.S. and Allied Networks,” today to expose ongoing Russian Foreign Intelligence Service (SVR) exploitation of five publicly known vulnerabilities. This advisory is being released alongside the U.S. government’s formal attribution of the SolarWinds supply chain compromise and related cyber espionage campaign. We are publishing this product to highlight additional tactics, techniques, and procedures being used by SVR so that network defenders can take action to mitigate against them.  

Mitigation against these vulnerabilities is critically important as U.S. and allied networks are constantly scanned, targeted, and exploited by Russian state-sponsored cyber actors. In addition to compromising the SolarWinds Orion software supply chain, recent SVR activities include targeting COVID-19 research facilities via WellMess malware and targeting networks through the VMware vulnerability disclosed by NSA. This was highlighted in NSA’s Cybersecurity Advisory, “Russian State-Sponsored Actors Exploiting Vulnerability in Workspace ONE Access Using Compromised Credentials.”

NSA, CISA, and FBI strongly encourage all cybersecurity stakeholders to check their networks for indicators of compromise related to all five vulnerabilities and the techniques detailed in the advisory and to urgently implement associated mitigations. NSA, CISA, and FBI also recognize all partners in the private and public sectors for comprehensive and collaborative efforts to respond to recent Russian activity in cyberspace.

NSA encourages its customers to mitigate against the following publicly known vulnerabilities:

  • CVE-2018-13379 Fortinet FortiGate VPN
  • CVE-2019-9670 Synacor Zimbra Collaboration Suite
  • CVE-2019-11510 Pulse Secure Pulse Connect Secure VPN
  • CVE-2019-19781 Citrix Application Delivery Controller and Gateway
  • CVE-2020-4006 VMware Workspace ONE Access

For more information, review the advisory or visit NSA.gov/cybersecurity-guidance.

View the infographic on understanding the threat and how to take action.

46-Year Fugitive Arrested Thanks to NTOC Tip

Source: Federal Bureau of Investigation FBI Crime News

When someone calls the FBI to report a tip, it’s the National Threat Operations Center staff who picks up the phone and receives that information. The center’s threat intake examiners also receive the online tips sent in through tips.fbi.gov.

Threat intake examiners work around the clock to assess and forward information to the Bureau’s field offices and other law enforcement partners.

Below are two recent examples of NTOC’s work.

Longtime Fugitive Arrested

In June 2020, NTOC received a call about a wanted fugitive who shot a police officer in the early 1970s. The subject was imprisoned after the shooting but escaped when he was transferred to a hospital in 1974.

The caller provided the fugitive’s current address, which was in New Mexico.

No Average Call

The FBI’s National Threat Operations Center works day and night to ensure each of the calls and electronic tips it receives is evaluated rapidly and handled appropriately.

National Park Service and FBI Seek Information Regarding Hot Springs National Park Homicide Investigation

Source: Federal Bureau of Investigation (FBI) State Crime News

On Saturday, March 27, 2021, Paige Autumn White’s body was found in the Hot Springs National Park near Whittington/Blacksnake Road. The National Park Service is leading the investigation, with assistance from the FBI, the Garland County Sheriff’s Office, Arkansas State Police, and the Hot Springs Police Department.

We are looking for the community’s help to find out what happened to her. While we cannot share everything we know at this time, we do know that Paige is the victim of a homicide. We are hoping to learn about the days leading up to Paige’s death and are eager to hear from family, friends, acquaintances, and anyone else who may have seen her recently.

There is a strong possibility the person who did this continues to work and/or live in our community. This individual likely has familiarity with the areas in which Paige was last seen and recovered. Individual(s) responsible for, or who have knowledge of, the death of Paige may have exhibited changes of behavior to include:

  • Altering of physical appearance (growth or removal of facial hair, change in hair color or cut, etc.)
  • Cleaning of vehicles
  • Change in normal routine, which might include missing work, classes, or previously scheduled appointments
  • Displays of anxiety, nervousness, or irritability
  • Intense interest in the investigation, a noticeable disinterest, or an unexplained knowledge of the situation
  • Unexplained injuries (cuts on hands, bruises, etc.) during the period Paige was last seen alive and then recovered

Every day we are gathering more information from the community to move this case forward, and the continued assistance is appreciated.

Sometimes people who may have knowledge do not initially come forward because of their relationships to people involved, concerns for their safety, or they may not realize information they have is important. If you feel you have information regarding Paige and her death, no matter how insignificant you think it may be, please share it with the National Park Service by calling their tip line at 888-653-0009, reporting online at nps.gov/ISB, or emailing nps_isb@nps.gov. You may remain anonymous when reporting to the National Park Service.

For more information about this case, please visit: https://www.nps.gov/orgs/1563/isb-hosp-rfi.htm.

FBI Little Rock Seeks Safe Return of Luis Davila

Source: Federal Bureau of Investigation (FBI) State Crime News

Press release available in both English and Spanish.

LITTLE ROCK, AR— The FBI’s Little Rock Field Office is seeking information from the public about an Arkansas resident who went to Mexico to visit his girlfriend and has not been seen since March 29, 2021.

Luis Davila is a 31-year-old U.S. citizen who is approximately 5’10” in height, approximately 190 pounds, with brown eyes and black hair. Davila is from Bentonville, Arkansas, and was in Mexico visiting his girlfriend near Monterrey.

Luis was last seen near Monterrey, Mexico, on March 29, 2021, wearing a white shirt and jeans. He was driving a silver 2016 Nissan Maxima (Arkansas License Plate 936-VET).

Although the whereabouts of Davila are unknown at this time, it is believed he may still be in Mexico, possibly near Nuevo Laredo, Tamaulipas. Davila may be the victim of a kidnapping.

The public is urged to call the FBI at 1-800-CALL-FBI (225-5324) with any information. Tips can also be submitted online at tips.fbi.gov. Individuals who provide information may remain anonymous.


El FBI En Little Rock Procura El Retorno a Salvo De Luis Dávila

LITTLE ROCK, AR—La Oficina Regional del FBI en Little Rock solicita información del público sobre un residente de Arkansas quien fue a México a visitar a su novia, y el cual no ha sido visto desde el día 29 de marzo de 2021.

Luis Dávila es un ciudadano de los EE. UU. de 31 años de edad, de 5’10” (1.78 metros) de estatura aproximadamente, y de 190 libras de peso (86.1 kilogramos) aproximadamente, de ojos café, y de pelo negro. Dávila es de Bentonville, AR, y se encontraba en México visitando a su novia cerca de Monterrey.

Luis fue visto por última vez cerca de Monterrey, México, el día 29 de marzo de 2021, vestido con una camisa blanca y con un pantalón de mezclilla. Conducía un vehículo Nissan Máxima de color plateado y del año 2016 (Matrícula 936-VET de Arkansas).

Aunque el paradero de Dávila se desconoce en este momento, se cree que todavía pueda estar en México, posiblemente cerca de Nuevo Laredo, Tamaulipas. Es posible que Dávila sea la víctima de un secuestro.

Se insta a que el público llame al FBI al número 1-800-CALL-FBI (225-5324) con cualquier información. También se pueden proveer pistas en línea en tips.fbi.gov. Las personas que provean información pueden permanecer anónimas.

FBI Offers $20,000 Reward for Information on Arson and Possession of a Destructive Device

Source: Federal Bureau of Investigation (FBI) State Crime News

SEATTLE, WA—The FBI’s Seattle Field Office, ATF, and the Seattle Police Department are investigating an arson which occurred on August 24, 2020, at 11 p.m., in the SODO region of Seattle, Washington. The FBI is offering a reward of up to $20,000 for information leading to the identification, arrest, and conviction of the individual(s) responsible. See poster for more information.

Two suspects were observed scouting the area around the Seattle Police Officer’s Guild building in the hour before the attack. The suspects changed into all black clothing and returned to the building, where they ignited and threw three Molotov cocktails at the structure and then fled the area on foot.

Suspect #1 is described as a White female between 5’8” and 5’10”, weighing approximately 120 pounds with dirty blonde/purple hair. Suspect #2 is described as a Black person between 5’5” and 5’7”, weighing approximately 120 pounds.

Anyone with information regarding these incidents should contact the FBI’s Seattle Field Office at 206-622-0460 or tips.fbi.gov.