Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Microsoft MSHTML Flaw Exploited by Ryuk Ransomware Gang

    Microsoft and RiskIQ researchers have identified several campaigns using the recently patched zero-day, reiterating a call for organizations to update affected systems.

  • CISA, FBI: State-Backed APTs May Be Exploiting Critical Zoho Bug

    The newly identified bug in a Zoho single sign-on and password management tool has been under active attack since early August.

  • ACSC Releases Annual Cyber Threat Report

    Original release date: September 16, 2021 The Australian Cyber Security Centre (ACSC) has released its annual report on key cyber security threats and trends for the 2020–21 financial year.     The report lists the exploitation of the pandemic environment, the disruption of essential services and critical infrastructure, ransomware, the rapid exploitation of security vulnerabilities, and the compromise of business email  as last year’s most significant threats.      CISA encourages users and administrators to review ACSC’s Annual Cyber Threat Report July 2020 to June 2021 and CISA’s Stop Ransomware webpage for more information.  This product is provided subject to this Notification…

  • FBI-CISA-CGCYBER Advisory on APT Exploitation of ManageEngine ADSelfService Plus Vulnerability

    Original release date: September 16, 2021 The Federal Bureau of Investigation (FBI), CISA, and Coast Guard Cyber Command (CGCYBER) have released a Joint Cybersecurity Advisory (CSA) detailing the active exploitation of an authentication bypass vulnerability (CVE-2021-40539) in Zoho ManageEngine ADSelfService Plus—a self-service password management and single sign-on solution. The FBI, CISA, and CGCYBER assess that advanced persistent threat (APT) cyber actors are likely among those exploiting the vulnerability. The exploitation of this vulnerability poses a serious risk to critical infrastructure companies, U.S.-cleared defense contractors, academic institutions, and other entities that use the software. CISA strongly encourages users and administrators to…

  • AA21-259A: APT Actors Exploiting Newly Identified Vulnerability in ManageEngine ADSelfService Plus

    Original release date: September 16, 2021 Summary This Joint Cybersecurity Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, Version 8. See the ATT&CK for Enterprise for  referenced threat actor tactics and for techniques. This joint advisory is the result of analytic efforts between the Federal Bureau of Investigation (FBI), United States Coast Guard Cyber Command (CGCYBER), and the Cybersecurity and Infrastructure Security Agency (CISA) to highlight the cyber threat associated with active exploitation of a newly identified vulnerability (CVE-2021-40539) in ManageEngine ADSelfService Plus—a self-service password management and single sign-on solution. CVE-2021-40539, rated critical by the Common…

  • Microsoft Releases Security Update for Azure Linux Open Management Infrastructure

    Original release date: September 16, 2021 Microsoft has released an update to address a remote code execution vulnerability in Azure Linux Open Management Infrastructure (OMI). An attacker could use this vulnerability to take control of an affected system. CISA encourages users and administrators to review the Microsoft Security Advisory to apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

  • Drupal Releases Multiple Security Updates

    Original release date: September 16, 2021 Drupal has released security updates to address multiple vulnerabilities affecting Drupal 8.9, 9.1, and 9.2. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the following Drupal security advisories and apply the necessary updates. SA-CORE-2021-006 SA-CORE-2021-007 SA-CORE-2021-008 SA-CORE-2021-009 SA-CORE-2021-010 This product is provided subject to this Notification and this Privacy & Use policy.

  • No Patch for High-Severity Bug in Legacy IBM System X Servers

    Two of IBM’s aging flagship server models, retired in 2020, won’t be patched for a command-injection flaw.

  • HP Omen Hub Exposes Millions of Gamers to Cyberattack

    A driver privilege-escalation bug gives attackers kernel-mode access to millions of PCs used for gaming.

  • Azure Zero-Day Flaws Highlight Lurking Supply-Chain Risk

    Dubbed OMIGOD, a series of vulnerabilities in the Open Management Infrastructure used in Azure on Linux demonstrate hidden security threats, researchers said.

  • 2021’s Most Dangerous Software Weaknesses

    Saryu Nayyar, CEO at Gurucul, peeks into Mitre’s list of dangerous software bug types, highlighting that the oldies are still the goodies for attackers.

  • Microsoft Patches Actively Exploited Windows Zero-Day Bug

    On Patch Tuesday, Microsoft fixed 66 CVEs, including an RCE bug in MSHTML under active attack as threat actors passed around guides for the drop-dead simple exploit.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.