US Local Governments Targeted by Chinese Hackers
- Chinese-Speaking hackers exploited a high-severity vulnerability in Trimble's Cityworks software to breach US local government networks starting January 2025.
- The vulnerability CVE-2025-0994, tracked by CISA and Cisco Talos as a remote code execution flaw in Microsoft IIS servers, enabled attackers to deploy malware and gain administrative access.
- Attackers, identified as UAT-6382, used tools like Cobalt Strike, VShell, and malicious web shells to maintain long-term access and target systems related to utilities management.
- Trimble released patches in early February 2025, and advisory agencies urged immediate updates to mitigate risks to water, wastewater, energy, and critical infrastructure sectors.
- These intrusions highlight a shift to targeting critical infrastructure by Chinese threat actors, prompting increased cooperation between the National Guard, private utilities, and federal agencies to improve defenses.
14 Articles
14 Articles
National Guardsmen receive brief from Volt Typhoon utility victim at cyber exercise
For the first time at a New England-based cyber exercise, National Guardsmen recently received a threat briefing from a company that was compromised by a high-profile Chinese cyber actor. Cyber Yankee, now in its 11th year, is a one-of-a-kind exercise that acts as a dry run of sorts in which members of the Guard in the six New England states work side-by-side with the private sector, utilities and other entities to protect critical infrastructur…
The Dangers and Threats of Zero-Day Attacks
Zero-day threats are among the biggest risks in cybersecurity. They occur when a vulnerability—in this case meaning a security flaw or weak point in software or hardware that is unknown to the vendor or developers—is exploited to gain access. They are named as such because the vendor or developer has zero days to fix...
Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks
A Chinese threat actor exploited a zero-day vulnerability in Trimble Cityworks to hack local government entities in the US. The post Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks appeared first on SecurityWeek. This article has been… Read more → The post Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks appeared first on IT Security News.
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage