Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Keep Attackers Out of VPNs: Feds Offer Guidance

    The NSA and CISA issued recommendations on choosing and hardening VPNs to prevent nation-state APTs from weaponizing flaws & CVEs to break into protected networks.

  • Apple AirTag Zero-Day Weaponizes Trackers

    Apple’s personal item-tracker devices can be used to deliver malware, slurp credentials, steal tokens and more thanks to XSS.

  • CISA and NSA Release Guidance on Selecting and Hardening VPNs

    Original release date: September 28, 2021 The National Security Agency (NSA) and CISA have released the cybersecurity information sheet Selecting and Hardening Standards-based Remote Access VPN Solutions to address the potential security risks associated with using Virtual Private Networks (VPNs). Remote-access VPN servers allow off-site users to tunnel into protected networks, making these entry points vulnerable to exploitation by malicious cyber actors. Exploitation of these devices can enable: Credential harvesting Remote code execution on the VPN device Cryptographic weakening of encrypted traffic sessions Hijacking of encrypted traffic sessions Arbitrary reads of sensitive data (e.g., configurations, credentials, keys) from the device The…

  • RCE Vulnerability in Hikvision Cameras (CVE-2021-36260)

    Original release date: September 28, 2021 Hikvision has released updates to mitigate a command injection vulnerability—CVE-2021-36260—in Hikvision cameras that use a web server service. A remote attacker could exploit this vulnerability to take control of an affected device.   CISA encourages users and administrators to review Hikvision’s Security Advisory HSRC-202109-01 and apply the latest firmware updates. See security researcher Watchful IP’s technical blogpost for more information. This product is provided subject to this Notification and this Privacy & Use policy.

  • Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw

    The unredacted RCE exploit allows unauthenticated, remote attackers to upload files to the vCenter Server analytics service.

  • 5 Steps to Securing Your Network Perimeter

    Ekaterina Kilyusheva, head of the Information Security Analytics Research Group at Positive Technologies, offers a blueprint for locking up the fortress.

  • Vulnerability Summary for the Week of September 20, 2021

    Original release date: September 27, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info ffmpeg — ffmpeg Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. 2021-09-20 6.8 CVE-2020-20891 MISC MISC ffmpeg — ffmpeg Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service…

  • VMware vCenter Server Vulnerability CVE-2021-22005 Under Active Exploit

    Original release date: September 24, 2021 On September 21, 2021, VMware disclosed that its vCenter Server is affected by an arbitrary file upload vulnerability—CVE-2021-22005—in the Analytics service. A malicious cyber actor with network access to port 443 can exploit this vulnerability to execute code on vCenter Server. On September 24, 2021, VMware confirmed reports that CVE-2021-22005 is being exploited in the wild. Security researchers are also reporting mass scanning for vulnerable vCenter Servers and publicly available exploit code. Due to the availability of exploit code, CISA expects widespread exploitation of this vulnerability. To mitigate CVE-2021-22005, CISA strongly urges critical infrastructure…

  • Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

    Hundreds of thousands of email credentials, many of which double as Active Directory domain credentials, came through to credential-trapping domains in clear text.

  • Critical Cisco Bugs Allow Code Execution on Wireless, SD-WAN

    Unauthenticated cyberattackers can also wreak havoc on networking device configurations.

  • Apple Patches 3 More Zero-Days Under Active Attack

    One of the bugs, which affects macOS as well as older versions of iPhones, could allow an attacker to execute arbitrary code with kernel privileges.

  • 5 Tips for Achieving Better Cybersecurity Risk Management

    Casey Ellis, founder, CTO and chairman of Bugcrowd, discusses a roadmap for lowering risk from cyberattacks most effectively.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.