Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of August 30, 2021

    Original release date: September 6, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info atlassian — confluence In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an authenticated user, and in some instances an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if ‘Allow people to sign up to create their account’ is enabled. To check whether this is enabled go to COG > User Management…

  • The State of Incident Response: Measuring Risk and Evaluating Your Preparedness

    Grant Oviatt, director of incident-response engagements at Red Canary, provides advice and best practices on how to get there faster.

  • CISA Insights on Risk Considerations for Managed Service Provider Customers

    Original release date: September 3, 2021 CISA has released a new CISA Insights, Risk Considerations for Managed Service Provider Customers (MSPs), which provides Managed Service Provider (MSP) customers a framework for reducing risk. This framework is designed for government and private sector organizations of all sizes, and it suggests considerations for IT management planning, best practices, and tools for reducing overall risk. This resource divides guidance across these areas: (1) senior executives and boards of directors (strategic decision-making); (2) procurement professionals (operational decision-making); and (3) network administrators, systems administrators, and front-line cybersecurity staff (tactical decision-making). Read CISA’s latest blog, visit:…

  • Atlassian Releases Security Updates for Confluence Server and Data Center

    Original release date: September 3, 2021 On August 25, 2021, Atlassian released security updates to address a remote code execution vulnerability (CVE-2021-26084) affecting Confluence Server and Data Center. Recently, CVE-2021-26084 has been detected in exploits in the wild. A remote attacker could exploit this vulnerability to take control of an affected system. CISA urges users and administrators to review Atlassian Security Advisory 2021-08-25 and immediately apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Bluetooth Bugs Open Billions of Devices to DoS, Code Execution

    The BrakTooth set of security vulnerabilities impacts at least 11 vendors’ chipsets.

  • Cisco Releases Security Updates for Cisco Enterprise NFVIS

    Original release date: September 2, 2021 Cisco has released security updates to address a critical vulnerability affecting Cisco Enterprise Network Function Virtualization Infrastructure Software (NFVIS) Release 4.5.1. A remote attacker could exploit this vulnerability to take control of an affected system. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. CISA encourages users and administrators to review Cisco advisory cisco-sa-nfvis-g2DMVVh and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

  • Google Play Sign-Ins Allow Covert Location-Tracking

    A design flaw involving Google Timeline could allow someone to track another device without installing a stalkerware app.

  • Cisco Patches Critical Authentication Bug With Public Exploit

    There’s proof-of-concept code out for the near-maximum critical – rated at 9.8 – authentication bypass bug, but Cisco hasn’t seen any malicious exploit yet.

  • WhatsApp Photo Filter Bug Allows Sensitive Info to Be Lifted

    Users should be careful whose pics they view and should, of course, update their apps.

  • Comcast RF Attack Leveraged Remotes for Surveillance

    IoT vulnerabilities turn remote into listening device, researchers find, which impacted 18 million Xfinity customers.

  • Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites

    Two vulnerabilities in the site-building plugin could be useful tools in the hands of a skilled attacker, researchers warned.

  • Proxyware Services Open Orgs to Abuse – Report

    Services that let consumers resell their bandwidth for money are ripe for abuse, researchers warn.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.