Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Adobe Snuffs Critical Bugs in Acrobat, Experience Manager

    Adobe releases security updates for 59 bugs affecting its core products, including Adobe Acrobat Reader, XMP Toolkit SDK and Photoshop.

  • SAP Releases September 2021 Security Updates 

    Original release date: September 14, 2021 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the SAP Security Notes for September 2021 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Microsoft Releases September 2021 Security Updates

    Original release date: September 14, 2021 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker can exploit some of these vulnerabilities to take control of an affected system.   CISA encourages users and administrators to review Microsoft’s September 2021 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Pair of Google Chrome Zero-Day Bugs Actively Exploited

    The security vulnerabilities bring the web behemoth up to 10 browser zero-days found so far this year.

  • CERT NZ Releases Ransomware Protection Guide for Businesses

    Original release date: September 14, 2021 The New Zealand Computer Emergency Response Team (CERT NZ) has released a guide on ransomware protection for businesses. The guide includes a pair of helpful diagrams that outline different ransomware attack pathways and illustrate where relevant security controls can work to protect or stop an attack.   CISA encourages users, administrators, and business leaders to review the CERT NZ guide, Protecting from ransomware, for more information as well as recommended prevention and mitigation measures.   For additional resources related to the prevention and mitigation of ransomware, see https://www.stopransomware.gov as well as the CISA-MS-ISAC Joint…

  • Unpatched Bugs Plague Databases; Your Data Is Probably Not Secure – Podcast

    Imperva’s Elad Erez discusses findings that 46 percent of on-prem databases are sitting ducks, unpatched and vulnerable to attack, each with an average of 26 flaws.

  • Apple Releases Security Updates to Address CVE-2021-30858 and CVE-2021-30860

    Original release date: September 13, 2021 Apple has released security updates to address vulnerabilities—CVE-2021-30858 and CVE-2021-30860—in multiple products.  An attacker could exploit these vulnerabilities to take control of an affected device. CISA is aware of public reporting that these vulnerabilities may have been exploited in the wild. CISA encourages users and administrators to review the security update pages for the following products and apply the necessary updates. macOS Big Sur 11.6 macOS Catalina watchOS 7.6.2 iOS 14.8 and iPadOS 14.8 Safari 14.1.2   This product is provided subject to this Notification and this Privacy & Use policy.

  • Apple Issues Emergency Fix for NSO Zero-Click Zero Day

    Citizen Lab urges Apple users to update immediately. The new zero-click zero-day ForcedEntry flaw affects all things Apple: iPhones, iPads, Macs and Watches.

  • Apple Releases Security Updates, iOS 14.8 and iPadOS 14.8

    Original release date: September 13, 2021 Apple has released security updates to address vulnerabilities—CVE-2021-30860, CVE-2021-30858—in iOS and iPadOS. An attacker could exploit these vulnerabilities to take control of an affected device. CISA is aware of public reporting that these vulnerabilities may have been exploited in the wild. CISA encourages users and administrators to review the iOS 14.8 and iPadOS 14.8 security update page and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • WooCommerce Multi Currency Bug Allows Shoppers to Change eCommerce Pricing

    The security vulnerability can be exploited with a malicious CSV file.

  • Vulnerability Summary for the Week of September 6, 2021

    Original release date: September 13, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adaptivescale — lxdui A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system. 2021-09-03 10 CVE-2021-40494 MISC arubanetworks — arubaos A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability. 2021-09-07 9 CVE-2021-37724 MISC arubanetworks — arubaos A remote arbitrary command execution vulnerability was discovered in…

  • CISA’s Annual National Cybersecurity Summit

    Original release date: September 13, 2021 CISA will host its fourth annual National Cybersecurity Summit on Wednesdays during the month of October. The 2021 Summit will be held as a series of four virtual events bringing stakeholders together in a forum for meaningful conversation: Oct. 6 – Assembly Required: The Pieces of the Vulnerability Management Ecosystem  Oct. 13 – Collaborating for the Collective Defense  Oct. 20 – Team Awesome: The Cyber Workforce  Oct. 27 – The Cyber/Physical Convergence Register for this free summit and read more about the presentations at CISA.gov/cybersummit2021. This product is provided subject to this Notification and…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.