Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Citrix Releases Security Update for ShareFile Storage Zones Controller

    Original release date: August 10, 2021 Citrix has released a security update to address a vulnerability affecting Citrix ShareFile storage zones controller. An attacker can exploit this vulnerability to obtain access to sensitive information. CISA recommends users and administrators review Citrix Security Bulletin CTX322787 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

  • Microsoft Releases August 2021 Security Updates

    Original release date: August 10, 2021 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s August 2021 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • eCh0raix Ransomware Variant Targets QNAP, Synology NAS Devices

    Some bad actors are honing tools to go after small fry: This variant was refined to target not one, but two vendors’ devices that are common in SOHO setups.

  • Fuzz Off: How to Shake Up Code to Get It Right – Podcast

    Is fuzzing for the cybersec elite, or should it be accessible to all software developers? FuzzCon panelists say join the party as they share fuzzing wins & fails.

  • ‘Glowworm’ Attack Turns Power Light Flickers into Audio

    Researchers have found an entirely new attack vector for eavesdropping on Zoom and other virtual meetings.

  • Auth Bypass Bug Exploited, Affecting Millions of Routers

    A mere three days after disclosure, cyberattackers are hijacking home routers from 20 vendors & ISPs to add them to a Mirai-variant botnet used for carrying out DDoS attacks.

  • Vulnerability Summary for the Week of August 2, 2021

    Original release date: August 9, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info basic_shopping_cart_project — basic_shopping_cart A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. 2021-07-30 7.5 CVE-2021-34165 MISC ectouch — ectouch SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php.. 2021-07-30 7.5 CVE-2020-21806 MISC huawei — magic_ui There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause code injection. 2021-08-02 7.5 CVE-2021-22444 MISC huawei — magic_ui There is an Improper Control of…

  • Golang Cryptomining Worm Offers 15% Speed Boost

    The latest variants of the Monero-mining malware exploit known web server bugs and add efficiency to the mining process.

  • Amazon Kindle Vulnerable to Malicious EBooks

    Prior to a patch, a serious bug could have allowed attackers to take over Kindles and steal personal data.

  • Ivanti Releases Security Update for Pulse Connect Secure

    Original release date: August 6, 2021 Ivanti has released Pulse Connect Secure system software version 9.1R12 to address multiple vulnerabilities an attacker could exploit to take control of an affected system. CISA encourages users and administrators to review Ivanti’s Security Advisory SA44858 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

  • Critical Cisco Bug in VPN Routers Allows Remote Takeover

    Security researchers warned that at least 8,800 vulnerable systems are open to compromise.

  • Pulse Secure Releases Security Update for Pulse Secure Connect

    Original release date: August 6, 2021 Pulse Secure has released Pulse Secure Connect system software version 9.1R12 to address multiple vulnerabilities an attacker could exploit to take control of an affected system. CISA encourages users and administrators to review Pulse Secure’s Security Advisory SA44858 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.