Eligible Receiver 97: Historic Cyber Exercise Reveals Vulnerabilities
Article Content
- •Eligible Receiver 97 simulated cyber attacks on critical infrastructure.
- •The NSA Red Team gained root access to over 35 government networks.
- •ER97 highlighted significant vulnerabilities in U.S. military and civilian systems.
Eligible Receiver 97 (ER97), a pivotal Defense Department cybersecurity exercise conducted in June 1997, simulated attacks on critical infrastructure, including power grids and emergency systems in eight U.S. cities. The NSA Red Team, simulating hostile forces, demonstrated significant vulnerabilities in U.S. military and civilian systems, gaining root access to over 35 government networks. The exercise was a wake-up call for the Department of Defense, highlighting the need for improved cybersecurity measures. Despite its historical significance, many details of ER97 remain classified. The exercise has been referenced in discussions about modern cybersecurity threats, particularly in light of recent incidents like the SolarWinds breach, which underscored ongoing vulnerabilities. The findings from ER97 informed the establishment of U.S. Cyber Command and shaped national cybersecurity policy.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Department of Defense in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems were affected during ER97?
What was the significance of ER97?
Are there any current threats related to ER97 findings?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…