Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Critical RCE Vulnerability in Discourse 

    Original release date: October 24, 2021 Discourse—an open source discussion platform—has released a security advisory to address a critical remote code execution (RCE) vulnerability (CVE-2021-41163) in Discourse versions 2.7.8 and earlier.  CISA urges developers to update to patched versions 2.7.9 or later or apply the necessary workarounds.  For more information, see RCE via malicious SNS subscription payload. This product is provided subject to this Notification and this Privacy & Use policy.

  • Malware Discovered in Popular NPM Package, ua-parser-js

    Original release date: October 22, 2021 Versions of a popular NPM package named ua-parser-js was found to contain malicious software. ua-parser-js is used in apps and websites to discover the type of device or browser a person is using from User-Agent data. A computer or device with the affected software installed or running could allow a remote attacker to obtain sensitive information or take control of the system.  CISA urges users and administers using compromised ua-parser-js versions 0.7.29, 0.8.0, and 1.0.0 to update to the respective patched versions: 0.7.30, 0.8.1, 1.0.1    For more information, see Embedded malware in ua-parser-js.…

  • Cisco SD-WAN Security Bug Allows Root Code Execution

    The high-severity bug, tracked as CVE-2021-1529, is an OS command-injection flaw.

  • GPS Daemon (GPSD) Rollover Bug

    Original release date: October 21, 2021 Critical Infrastructure (CI) owners and operators, and other users who obtain Coordinated Universal Time (UTC) from Global Positioning System (GPS) devices, should be aware of a GPS Daemon (GPSD) bug in GPSD versions 3.20 (released December 31, 2019) through 3.22 (released January 8, 2021).    On October 24, 2021, Network Time Protocol (NTP) servers using bugged GPSD versions 3.20-3.22 may rollback the date 1,024 weeks—to March 2002—which may cause systems and services to become unavailable or unresponsive.     CISA urges affected CI owners and operators to ensure systems—that use GPSD to obtain timing…

  • U.S. Ban on Sales of Cyberattack Tools Is Anemic, Experts Warn

    Meanwhile, Zerodium’s quest to buy VPN exploits is problematic, researchers said.

  • Cisco Releases Security Updates for IOS XE SD-WAN Software

    Original release date: October 21, 2021 Cisco has released security updates to address a vulnerability in IOS XE SD-WAN Software. An authenticated local attacker could exploit this vulnerability to take control of an affected system. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. CISA encourages users and administrators to review Cisco Advisory cisco-sa-sd-wan-rhpbE34A and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Why is Cybersecurity Failing Against Ransomware?

    Hardly a week goes by without another major company falling victim to a ransomware attack. Nate Warfield, CTO at Prevailion, discusses the immense challenges in changing that status quo.

  • VPN Exposes Data for 1M Users, Leading to Researcher Questioning

    Experts warn that virtual private networks are increasingly vulnerable to leaks and attack.

  • Squirrel Bug Lets Attackers Execute Code in Games, Cloud Services

    The out-of-bounds read vulnerability enables an attacker to escape a Squirrel VM in games with millions of monthly players – such as Counter-Strike: Global Offensive and Portal 2 – and in cloud services such as Twilio Electric Imp.

  • Geriatric Microsoft Bug Exploited by APT Using Commodity RATs

    Disguised as an IT firm, the APT is hitting targets in Afghanistan & India, exploiting a 20-year-old+ Microsoft Office bug that’s as potent as it is ancient.

  • Oracle Releases October 2021 Critical Patch Update

    Original release date: October 19, 2021 Oracle has released its Critical Patch Update for October 2021 to address 419 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.  CISA encourages users and administrators to review the Oracle October 2021 Critical Patch Update and apply the necessary updates.  This product is provided subject to this Notification and this Privacy & Use policy.

  • Time to Build Accountability Back into Cybersecurity

    Chris Hass, director of information security and research at Automox, discusses how to assign security responsibility, punishment for poor cyber-hygiene and IDing ‘security champions’ to help small businesses.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.