That is one reason why a joint Cybersecurity Advisory (CSA) shows the top Common Vulnerabilities and Exposures (CVEs) used since 2020 by People’s Republic of China (PRC) state-sponsored cyber actors. This top 20 list ended up assessed by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI).
NSA, CISA, and FBI continue to assess PRC state-sponsored cyber activities as being one of the largest and most dynamic threats to U.S. government and civilian networks.
Critical Infrastructure Targeted
PRC state-sponsored cyber actors continue to target government and critical infrastructure networks with an increasing array of new and adaptive techniques – some of which pose a significant risk to Information Technology Sector organizations (including telecommunications providers), Defense Industrial Base (DIB) Sector organizations, and other critical infrastructure organizations.
PRC state-sponsored cyber actors continue to exploit known vulnerabilities and use publicly available tools to target networks of interest. NSA, CISA, and FBI assess PRC state-sponsored cyber actors have actively targeted U.S. and allied networks as well as software and hardware companies to steal intellectual property and develop access into sensitive networks.
These state-sponsored actors continue to use virtual private networks (VPNs) to obfuscate their activities and target web-facing applications to establish initial access. Many of the CVEs allow the actors to surreptitiously gain unauthorized access into sensitive networks, after which they seek to establish persistence and move laterally to other internally connected networks.
“It might seem like deja vu, but the truth is, many state-sponsored threat actors including those linked to the People’s Republic of China continue to exploit legacy vulnerabilities to gain initial access to organizations,” said Satnam Narang, senior staff research engineer at Tenable. “If there’s one thing threat actors love, it’s legacy, unpatched vulnerabilities.
“Many of the vulnerabilities overlap with vulnerabilities used by other state-sponsored threat actors, including those with links to the Iranian Islamic Revolutionary Guard Corps (IRGC), along with several other joint cybersecurity advisories published by CISA over the years. The most common amongst all of the advisories are a number of flaws in VPNs like Citrix (CVE-2019-19781) and Pulse Secure (CVE-2019-11510), which, despite being patched over two years ago, remain a valuable asset for threat actors seeking to gain initial access.
“The advisory notes that CVE-2021-44228, also known as Log4Shell, has been exploited by these threat actors following its discovery in December 2021. Considering the widespread use of Apache Log4j, it’s no surprise that this flaw has been integrated into the playbooks of these attackers, as we know that Log4Shell is a legacy vulnerability that will remain a problem for years to come.”
Exploits Continue
But it doesn’t stop there as Narang said attackers continue to exploit issues with Microsoft.
“These state-sponsored threat actors are exploiting flaws in Microsoft Exchange Server, including ProxyLogon (CVE-2021-26855) and associated flaws that were first disclosed in early 2021,” Narang said. “ProxyLogon continues to be leveraged as part of attacks in the wild, along with a more recent set of Exchange Server bugs, known as ProxyShell. Recently, attackers were spotted exploiting a pair of Zero Day vulnerabilities in Exchange Server, which researchers have called ProxyNotShell. The researchers that discovered these actively exploited flaws believed they were being leveraged by Chinese threat actors, which underscores the high value in Exchange Server as a target for these types of threat actors. Patching Exchange Server is no simple task, which is a contributing factor in the continued exploitation of flaws like ProxyLogon. The added bonus of leveraging these flaws is the ability for threat actors to install web shells on compromised Exchange Servers, which enables repeated access even after patches have been applied.
“For organizations, these joint advisories provide a blueprint into the way these threat actors seek to gain access to targeted networks, so it is vital that organizations are able to identify vulnerable assets and patch them in a timely manner to cut off potential avenues of exploitation,” Narang said.
In terms of mitigations, NSA, CISA, and FBI urge organizations to apply these recommendations:
- Update and patch systems as soon as possible. Prioritize patching vulnerabilities identified in this CSA and other known exploited vulnerabilities.
- Utilize phishing-resistant multi-factor authentication whenever possible. Require all accounts with password logins to have strong, unique passwords, and change passwords immediately if there are indications that a password may have been compromised.
- Block obsolete or unused protocols at the network edge.
- Upgrade or replace end-of-life devices.
- Move toward the Zero Trust security model.
- Enable robust logging of Internet-facing systems and monitor the logs for anomalous activity.


