Suspected Chinese state-sponsored hackers used vulnerabilities in Pulse Secure VPN appliances to infiltrate dozens of U.S. government agencies, defense contractors, and private companies, according to FireEye.

In a report released late Tuesday, FireEye, the cybersecurity firm that originally discovered the Russia-linked SolarWinds attack, said hacking groups took advantage of several flaws to bypass authentication on Pulse Secure VPN devices as early as August 2020. The hackers then maintained access to the compromised networks using webshells.

FireEye said it suspects that at least one of the hacking groups works for the Chinese government.

Pulse Secure Latest High-Profile Hack

This latest attack follows another China-linked group, Hafnium, that earlier this year hacked Microsoft Exchange email servers. And just days before FireEye published its Pulse Secure report, the FBI, National Security Agency (NSA), and Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory warning that Russian hacking group APT29 or Cozy Bear, the attackers behind the SolarWinds breach, were exploiting several software vulnerabilities including the Pulse Secure bug.

Pulse Secure’s parent company, Ivanti, released mitigations for three of the vulnerabilities that the attackers used. These were originally patched in 2019 and 2020. However, a new flaw, discovered this month, “impacted a very limited number of customers,” according to a Pulse Secure blog post. The vendor said it will issue a final patch to address this vulnerability in early May. It also issued a Pulse Connect Secure Integrity Tool for customers to determine if their systems are impacted.

CISA also issued a warning about the Pulse Secure vulnerabilities, and urged organizations to run the Integrity Tool, update their software, and report any malicious activity. And the U.S. Department of Homeland Security (DHS) ordered all federal agencies to run the Integrity Tool and report back to CISA by Friday.

The cyberattacks come as the Biden administration takes steps to shore up the United States’ cybersecurity posture — and punish nation states for attacking critical infrastructure and private networks. Late last week the administration issued new economic sanctions against Russia for the SolarWinds breach, interfering in U.S. elections, and other “malicious cyber activities.”

DOE, CISA Secure Energy Sector

And on Tuesday, the U.S. Department of Energy (DOE) launched an effort to secure the energy sector against cyberattacks. The so-called “100-day plan,” a coordinated effort between the DOE, the electricity industry, and CISA, calls on the energy industry to improve its threat detection and mitigation tools across IT and operational technology systems.

“We’ve gotten to the point where the industry fully recognizes, for the most part, what the security best practices are for protecting the grid,” said Tobias Whitney, VP of energy security solutions for Fortress Information Security. Fortress secures about 30% of the U.S. power grid, and before joining the security vendor Whiney spent several years at the North American Electric Reliability Corporation (NERC).

“But, the challenge we are starting to see now much more so than 10 years ago, is the dependency on the OEM manufacturer community to supply technologies and products that are secure upon implementation,” he added. And this opens up a whole new set of security challenges to utility owners and operators.

“The utilities that buy those technologies have a very good understanding of how to configure them, how to make sure that they’re hardened before they’re actually implemented, and understand what vulnerabilities may potentially exist not only within those systems but in the networks that currently operate those systems,” Whitney said.

In most cases, the suppliers don’t face the same level of regulatory scrutiny, he added. So while the electric companies rely on their vendors to provide software patches and updates, “the asset owners and operators are the ones that have to comply with these regulations,” Whitney said. “The manufacturers don’t have to deal with the up to $1 million-a-day fine.”

And as evidenced by the SolarWinds hack, supply chain flaws can render the entire ecosystem vulnerable to attack. “These information technology systems and networks do bleed into the grid systems and networks, and we do need to make sure that we continue to secure those systems that can very easily be used as an access point into those environments.”