Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • CISA Releases Five Pulse Secure-Related MARs

    Original release date: August 24, 2021 As part of CISA’s ongoing response to Pulse Secure compromises, CISA has analyzed five malware samples related to exploited Pulse Secure devices. CISA encourages users and administrators to review the following five malware analysis reports (MARs) for threat actor tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), and review CISA’s Alert, Exploitation of Pulse Connect Secure Vulnerabilities, for more information. MAR-10333243-3.v1: Pulse Connect Secure  MAR-10334057-3.v1: Pulse Connect Secure  MAR-10336935-2.v1: Pulse Connect Secure  MAR-10338401-2.v1: Pulse Connect Secure MAR-10339606-1.v1: Pulse Connect Secure This product is provided subject to this Notification and this Privacy &…

  • ProxyShell Attacks Pummel Unpatched Exchange Servers

    CISA is warning about a surge of ProxyShell attacks, as Huntress discovered 140 webshells launched against 1,900 unpatched Microsoft Exchange servers.

  • Vulnerability Summary for the Week of August 16, 2021

    Original release date: August 23, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info cisco — application_extension_platform A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow…

  • Windows 10 Admin Rights Gobbled by Razer Devices

    So much for Windows 10’s security: a zero-day in the device installer software grants admin rights just by plugging in a mouse or other compatible device.

  • Attackers Actively Exploiting Realtek SDK Flaws

    Multiple vulnerabilities in software used by 65 vendors under active attack.

  • Hurricane-Related Scams

    Original release date: August 21, 2021 CISA warns users to remain on alert for malicious cyber activity targeting potential disaster victims and charitable donors following a hurricane. Fraudulent emails—often containing malicious links or attachments—are common after major natural disasters. Exercise caution in handling emails with hurricane-related subject lines, attachments, or hyperlinks. In addition, be wary of social media pleas, texts, or door-to-door solicitations relating to severe weather events. To avoid becoming victims of malicious activity, users and administrators should review the following resources and take preventative measures. Staying Alert to Disaster-related Scams Before Giving to a Charity Staying Safe on…

  • Hurricane-Related Scams

    Original release date: August 21, 2021 The Cybersecurity and Infrastructure Security Agency (CISA) warns users to remain on alert for malicious cyber activity targeting potential disaster victims and charitable donors following a hurricane. Fraudulent emails—often containing malicious links or attachments—are common after major natural disasters. Exercise caution in handling emails with hurricane-related subject lines, attachments, or hyperlinks. In addition, be wary of social media pleas, texts, or door-to-door solicitations relating to severe weather events. To avoid becoming victims of malicious activity, users and administrators should review the following resources and take preventative measures. Staying Alert to Disaster-related Scams Before Giving…

  • Urgent: Protect Against Active Exploitation of ProxyShell Vulnerabilities

    Original release date: August 21, 2021 Malicious cyber actors are actively exploiting the following ProxyShell vulnerabilities: CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. An attacker exploiting these vulnerabilities could execute arbitrary code on a vulnerable machine. CISA strongly urges organizations to identify vulnerable systems on their networks and immediately apply Microsoft’s Security Update from May 2021—which remediates all three ProxyShell vulnerabilities—to protect against these attacks. Review the following resources for additional information: CISA Alert AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities CISA web page: Remediating Microsoft Exchange Vulnerabilities     This product is provided subject to this Notification and this Privacy & Use policy.

  • Web Censorship Systems Can Facilitate Massive DDoS Attacks

    Systems are ripe for abuse by attackers who can abuse systems to launch DDoS attacks.

  • How Ready Are You for a Ransomware Attack?

    Oliver Tavakoli, CTO at Vectra, lays out the different layers of ransomware defense all companies should implement.

  • Critical Cisco Bug in Small Business Routers to Remain Unpatched

    The issue affects a range of Cisco Wireless-N and Wireless-AC VPN routers that have reached end-of-life.

  • Windows EoP Bug Detailed by Google Project Zero

    Microsoft first dismissed the elevation of privilege flaw but decided yesterday that attackers injecting malicious code is worthy of attention.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.