Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • CISA Releases Security Advisory for Honeywell Experion and ACE Controllers

    Original release date: October 5, 2021 CISA has released an Industrial Controls Systems (ICS) advisory detailing multiple vulnerabilities affecting all versions of Honeywell Experion Process Knowledge System C200, C200E, C300, and ACE controllers. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review ICS advisory ICSA-21-278-04 Honeywell Experion and ACE Controllers as well as Experion Network and Security Planning Guide and Honeywell Support document SN2021-02-22-01 for more information and apply the necessary mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

  • IP Surveillance Bugs in Axis Gear Allow RCE, Data Theft

    Three security vulnerabilities in Axis video products could open up the door to a bevy of different cyberattacks on businesses.

  • How to Build an Incident-Response Plan, Before Security Disaster Strikes

    Joseph Carson, Chief Security Scientist at ThycoticCentrify, offers a 7-step practical IR checklist for ensuring a swift recovery from a cyberattack.

  • Apache Web Server Zero-Day Exposes Sensitive Data

    The open-source project has rolled out a security fix for CVE-2021-41773, for which public cyberattack exploit code is circulating.

  • Be Cyber Smart During Cybersecurity Awareness Month

    Original release date: October 5, 2021 CISA and the National Cybersecurity Alliance (NCSA) remind users to continue to “Do Your Part. #BeCyberSmart.” during October—2021’s Cybersecurity Awareness Month!   In 2021, CISA and NCSA will focus on different outreach themes each week to include:   Be Cyber Smart Phight the Phish! Explore. Experience. Share. – Cybersecurity Career Awareness Week Cybersecurity First  As part of the STOP.THINK.CONNECT.™ national public awareness campaign, CISA is also sharing Cybersecurity Awareness Month Resources to reduce cybersecurity risks and protect you online. CISA reminds users that cybersecurity is a proactive responsibility, and individuals and organizations should implement…

  • Vulnerability Summary for the Week of September 27, 2021

    Original release date: October 4, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adobe — digital_editions Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability in that a user must open a maliciously crafted .epub file. 2021-09-27 9.3 CVE-2021-39826 MISC adobe — photoshop_2020 Adobe Photoshop versions 21.2.11 (and earlier) and 22.5 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted SVG file. An…

  • MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed

    Coinbase suspects phishing led to attackers getting personal details needed to access wallets but also blamed a flaw in its SMS-based 2FA.

  • Google Emergency Update Fixes Two Chrome Zero Days

    This is the second pair of zero days that Google’s fixed this month, all four of which have been actively exploited in the wild.

  • New APT ChamelGang Targets Russian Energy, Aviation Orgs

    First appearing in March, the group has been leveraging ProxyShell against targets in 10 countries and employs a variety of malware to steal data from compromised networks.

  • Tips & Tricks for Unmasking Ghoulish API Behavior

    Jason Kent, hacker-in-residence at Cequence Security, discusses how to track user-agent connections to mobile and desktop APIs, to spot malicious activity.

  • Thousands of University Wi-Fi Networks Expose Log-In Credentials

    Multiple configuration flaws in a free Wi-Fi network used by numerous universities can allow access to usernames and passwords of students and faculty who connect to the system from Android and Windows devices, researchers have found. A research team from WizCase, led by researcher Ata Hakçıl, reviewed 3,100 configurations of Eduroam at universities throughout Europe, finding that more than half of them have issues that can be exploited by threat actors. The misconfiguration danger could extend to other organizations globally as well, they added. Eduroam provides free Wi-Fi connections at participating institutions. It assigns students, researchers and faculty members log-in…

  • Apple Pay with Visa Hacked to Make Payments via Unlocked iPhones

    Researchers have demonstrated that someone could use a stolen, unlocked iPhone to pay for thousands of dollars of goods or services, no authentication needed.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.