Intelligence View
Accellion's Failure to Warn RBNZ of Security Flaws Led to Hack
The Reserve Bank of New Zealand was hacked after Accellion failed to post a warning about an actively exploited vulnerability with available patches in its File Transfer Appliance (FTA), according to Itnews. While Accellion had updates a…
While Accellion had updates available for its FTA product in December 2020 and was alerted to the vulnerability by security vendor FireEye as early as the 16th of the same month, the RBNZ was not notified of the issue.
KPMG found in a commissioned post-mortem that Accellion's email tool failed to send notices and therefore, the bank was not notified until January 6, 2021.
The theft occurred on Christmas Day 2020, and the RBNZ made the data breach public on January 11, stating that it involved comme...
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Accellion's Failure to Warn RBNZ of Security Flaws Led to Hack
id: 04ea0c44-6c63-426c-9e28-626bd461b95f
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "Accellion\'s Failure to Warn RB" ascii wide
condition:
any of them
}tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Accellion's Failure to Warn RBNZ of Secu.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
SOCIAL SHARE CARD GENERATOR