Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Predicting the Next OWASP API Security Top 10

    API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

  • FBI Releases PIN on Attacks Using Significant Financial Events for Extortion

    Original release date: November 3, 2021 The Federal Bureau of Investigation (FBI) has released a Private Industry Notification (PIN) on ransomware actors using significant financial events, such as mergers and acquisitions, to target and leverage victim companies. CISA encourages users and administrators to review Ransomware Actors Use Significant Financial Events and Stock Valuation to Facilitate Targeting and Extortion of Victims and apply the recommended mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

  • CISA Issues BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities

    Original release date: November 3, 2021 CISA has issued Binding Operational Directive (BOD) 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities to addresses vulnerabilities that establishes specific timeframes for federal civilian agencies to remediate vulnerabilities that are being actively exploited by known adversaries. To support this Directive, CISA has established a catalog of relevant vulnerabilities. This catalog will be updated regularly, and organizations can sign up for notifications when new vulnerabilities are added.   CISA strongly recommends that private businesses, industry, and state, local, tribal and territorial (SLTT) governments prioritize mitigation of vulnerabilities in CISA’s Directive and sign up…

  • Android Patches Actively Exploited Zero-Day Kernel Bug

    Google’s Android November 2021 security updates plug 18 flaws in the framework and system components and 18 more in the kernel and vendor components.

  • Apple macOS Flaw Allows Kernel-Level Compromise

    ‘Shrootless’ allows bypass of System Integrity Protection IT security measures to install a malicious rootkit that goes undetected and performs arbitrary device operations.

  • Pirate Sports Streamer Gets Busted, Pivots to MLB Extortion

    An alleged sports content pirate is accused of not only hijacking leagues’ streams but also threatening to tell reporters how he accessed their systems.

  • ‘Trojan Source’ Hides Invisible Bugs in Source Code

    The old RLO trick of exploiting how Unicode handles script ordering and a related homoglyph attack can imperceptibly switch the real name of malware.

  • Vulnerability Summary for the Week of October 25, 2021

    Original release date: November 1, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info apache — storm An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4 2021-10-25 7.5 CVE-2021-40865 MISC MISC apache — storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and…

  • GoCD Authentication Vulnerability

    Original release date: October 29, 2021 GoCD has released a security update to address a critical authentication vulnerability in GoCD versions 20.6.0 through 21.2.0. GoCD is an open-source Continuous Integration and Continuous Delivery system. A remote attacker could exploit this vulnerability to obtain sensitive information. CISA encourages users and administrators to update to GoCD 21.3.0 or apply the necessary workarounds. For more information, see Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD. This product is provided subject to this Notification and this Privacy & Use policy.

  • NSA-CISA Series on Securing 5G Cloud Infrastructures

    Original release date: October 28, 2021 The National Security Agency (NSA) and CISA have published the first of a four-part series, Security Guidance for 5G Cloud Infrastructures. Security Guidance for 5G Cloud Infrastructures – Part I: Prevent and Detect Lateral Movement provides recommendations for mitigating lateral movement attempts by threat actors who have gained initial access to cloud infrastructures.  This guidance has been created by the Critical Infrastructure Partnership Advisory Council (CIPAC) Cross Sector Enduring Security Framework Working Group—a public-private working group that provides cybersecurity guidance addressing high-priority cyber threats to the nation’s critical infrastructure.  CISA encourages 5G providers, integrators,…

  • 2021 CWE Most Important Hardware Weaknesses

    Original release date: October 28, 2021 The Homeland Security Systems Engineering and Development Institute, sponsored by the Department of Homeland Security and operated by MITRE, has released the 2021 Common Weakness Enumeration (CWE) Most Important Hardware Weaknesses List. The 2021 Hardware List is a compilation of the most frequent and critical errors that can lead to serious vulnerabilities in hardware. An attacker can often exploit these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition.   CISA encourages users and administrators to review the Hardware Weaknesses List and evaluate recommended mitigations to determine those…

  • Ransomware Attacks Are Evolving. Your Security Strategy Should, Too

    Defending against ransomware will take a move to zero-trust, argues Daniel Spicer, CSO, Ivanti.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.