Security News > 2023 > June > CISA orders govt agencies to patch bugs exploited by Russian hackers

Three of them were exploited by Russian APT28 cyberspies to hack into Roundcube email servers belonging to Ukrainian government organizations.
While the KEV catalog's primary focus is alerting federal agencies of exploited vulnerabilities that must be patched as soon as possible, it is also highly advised that private companies worldwide prioritize addressing these bugs.
Earlier this month, the cybersecurity agency ordered U.S. federal agencies to patch a MOVEit vulnerability exploited by the Clop cybercrime gang for data theft.
Russian APT28 hackers breach Ukrainian govt email servers.
Hackers use fake 'Windows Update' guides to target Ukrainian govt.
Ukrainian hackers take down service provider for Russian banks.
News URL
Related news
- SonicWall firewall exploit lets hackers hijack VPN sessions, patch now (source)
- Russian military hackers deploy malicious Windows activators in Ukraine (source)
- Microsoft: Russian-Linked Hackers Using 'Device Code Phishing' to Hijack Accounts (source)
- DHS says CISA will not stop monitoring Russian cyber threats (source)
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp (source)