A suspected Iranian hacker group exploited a Log4j vulnerability to breach the server of a US federal agency, accessing domain control and installing cryptomining software. The intrusion began in February 2022 and was detected two months later by the Cybersecurity and Infrastructure Security Agency. The affected agency, part of the Federal Civilian Executive Branch, has not been disclosed.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.