#Beyondtrust
New recent victims:

-Elastic
-Nutanix
-CyberArk
-Cato Networks
-Bugcrowd
-JFrog
-BeyondTrust
-Rubrik
September 7, 2025 at 7:18 PM
when i see white writers in my industry covering this anti-“DEI” stuff w/o explicitly describing it as a white supremacist campaign at this point i just mentally add little asterisk next their name so i can remember not to associate with them at any point.
January 2, 2025 at 9:43 PM
Ooof RCE in BeyondTrust Remote Support (née Bomgar): www.resillion.com/la...
BeyondTrust Remote Support: How template injection can lead to remote code execution
The vulnerability was disclosed to BeyondTrust through their Responsible Disclosure program on 6 May 2025. A couple of weeks later,
www.resillion.com
June 18, 2025 at 1:35 PM
NEW: #China gov hackers breached #TreasuryDept...

How?

STEP 1:Targeted Treasury security vendor #BeyondTrust

STEP 2: Stole BT's key for a remote support platform

STEP3: Platform became the backdoor on Treasury machines

Ouch.

By @raphae.li @ajvicens.bsky.social
www.reuters.com/technology/c...
December 30, 2024 at 10:59 PM
LMAO BeyondTrust is a Privileged Access Management solution. It has ONE JOB and that job is to secure your most privileged accounts.
December 30, 2024 at 9:32 PM
59. Farmers Insurance
60. TransUnion
61. LVMH
62. Kering
63. Salesloft
64. Cloudflare
65. Zscaler
66. Palo Alto Networks
67. Tenable
68. CyberArk
69. Elastic
70. BeyondTrust
71. Proofpoint
72. JFrog
73. Rubrik
74. Cato Networks
75. Workiva
76. UK Legal Aid Agency*
77. Jaguar Land Rover
78. Toyota
September 24, 2026 at 2:41 AM
Dang:

“The dept was notified on Dec. 8 by a third-party software provider, BeyondTrust, that a hacker had secured access to a security key, which allowed the intruder to override certain security protocols & gain access to some Treasury Department office workstations...”

🎁: wapo.st/4j0bi3V
U.S. Treasury says it was hacked by China-backed actor
The department was notified on Dec. 8 by a third-party software provider, BeyondTrust, that a hacker had secured access to a security key, which allowed the intruder to override certain security proto...
wapo.st
December 30, 2024 at 9:42 PM
The Treasury Department has sanctioned Yin Kecheng, who allegedly hacked Treasury through its contractor BeyondTrust, and Sichuan Juxinhe Network Technology Co., which supported China's Salt Typhoon telecom hacks. home.treasury.gov/news/press-r...
January 17, 2025 at 3:52 PM
U.S. CISA adds BeyondTrust software flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds BeyondTrust software flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds BeyondTrust PRA and RS Command Injection flaw to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
December 20, 2024 at 11:46 AM
So which BeyondTrust product did threat actors abuse in the Treasury breach? Based on the description, seems like it was either Remote Support or Privileged Remote Access.

Neither is great, but the latter seems a LOT worse. 1/2
December 31, 2024 at 12:19 AM
I haven’t heard anything yet from BeyondTrust but this timeline of a recent security incident there is interesting:

www.beyondtrust.com/remote-suppo...
BeyondTrust Remote Support SaaS Service Security… | BeyondTrust
BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen credentials, and misused privileges
www.beyondtrust.com
December 30, 2024 at 9:38 PM
U.S. Treasury says it was hacked by China who gained access to government workstations and unclassified documents
U.S. Treasury says it was hacked by China-backed actor
The department was notified on Dec. 8 by a third-party software provider, BeyondTrust, that a hacker had secured access to a security key, which allowed the intruder to override certain security proto...
www.washingtonpost.com
December 30, 2024 at 9:35 PM
Musím poděkovat BeyondTrust za nejhorší SW, který jsem kdy měl na firemním PC nainstalovaný a velké díky firmě, že si ho zvolila.
October 22, 2025 at 6:45 AM
New: “Major incident” at U.S. Treasury after alleged Chinese hackers steal a cryptographic key used by vendor BeyondTrust. Government workstations breached.

www.reuters.com/technology/c...
US Treasury says Chinese hackers stole documents in 'major incident'
Chinese state-sponsored hackers broke into the U.S. Treasury Department earlier this month and stole documents from its workstations, according to a letter to lawmakers that was provided to Reuters on Monday.
www.reuters.com
December 30, 2024 at 9:01 PM
PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks
PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks
thehackernews.com
February 14, 2025 at 5:38 AM
U.S. Treasury says its computers were hacked by a Chinese 'threat actor' in a 'major incident' www.nbcnews.com/tech/securit...
U.S. Treasury says its computers were hacked by a Chinese 'threat actor' in 'major incident'
The "threat actor" was able to access the workstations via a compromised third-party cybersecurity service provider called BeyondTrust, the Treasury department said.
www.nbcnews.com
December 30, 2024 at 9:55 PM
🚨 CISA has added a critical BeyondTrust vulnerability to its exploited list! Stay informed and secure your systems. Read more here: https://innovirtuoso.com/cybersecurity/cisa-adds-critical-beyondtrust-vulnerability-to-exploited-list/ #Cybersecurity #VulnerabilityAlert 🔒💻
CISA Adds Critical BeyondTrust Vuln to Exploited List
Learn about the CVE-2024-12356 vulnerability recently added to CISA's Known Exploited Vulnerabilities list. This critical flaw in BeyondTrust products
innovirtuoso.com
January 5, 2025 at 9:29 PM
BeyondTrust has released security updates to fix a high-severity flaw in its Remote Support (RS) and Privileged Remote Access (PRA) solutions that can let unauthenticated attackers gain remote code execution on vulnerable servers.
BeyondTrust warns of pre-auth RCE in Remote Support software
BeyondTrust has released security updates to fix a high-severity flaw in its Remote Support (RS) and Privileged Remote Access (PRA) solutions that can let unauthenticated attackers gain remote code execution on vulnerable servers.
www.bleepingcomputer.com
June 18, 2025 at 10:10 AM
BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key
BeyondTrust Zero-Day Breach Exposed 17 SaaS Customers via Compromised API Key
thehackernews.com
February 1, 2025 at 7:11 AM
CISA ordered U.S. government agencies on Friday to secure their BeyondTrust Remote Support instances against an actively exploited vulnerability within three days.
CISA gives feds 3 days to patch actively exploited BeyondTrust flaw
CISA ordered U.S. government agencies on Friday to secure their BeyondTrust Remote Support instances against an actively exploited vulnerability within three days.
www.bleepingcomputer.com
February 16, 2026 at 12:33 PM
The U.S. Treasury announced a major cyberattack linked to a compromised API key from its contractor, BeyondTrust. Cyber operators ('Hackers') accessed Treasury workstations and unclassified documents by exploiting the vendor's remote support service. s3.documentcloud.org/documents/25...
December 31, 2024 at 8:00 AM