Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Critical Juniper Bug Allows DoS, RCE Against Carrier Networks

    Telecom providers, including wireless carriers, are at risk of disruption of network service if the bug in SBR Carrier is exploited.

  • Windows 0-Days Used Against Dissidents in Israeli Broker’s Spyware

    Candiru, aka Sourgum, allegedly sells the DevilsTongue surveillance malware to governments around the world.

  • Microsoft: New Unpatched Bug in Windows Print Spooler           

    Another vulnerability separate from PrintNightmare allows for local elevation of privilege and system takeover.

  • Zero-Day Attacks on Critical WooCommerce Bug Threaten Databases

    The popular e-commerce platform for WordPress has started deploying emergency patches.

  • Ransomware Risk in Unpatched, EOL SonicWall SRA and SMA 8.x Products

    Original release date: July 15, 2021 CISA is aware of threat actors actively targeting a known, previously patched, vulnerability in SonicWall Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running unpatched and end-of-life (EOL) 8.x firmware. Threat actors can exploit this vulnerability to initiate a targeted ransomware attack. CISA encourages users and administrators to review the SonicWall security advisory and upgrade to the newest firmware or disconnect EOL appliances as soon as possible. Review the CISA Bad Practices webpage to learn more about bad cybersecurity practices, such as using EOL software, that are especially dangerous for organizations supporting…

  • Juniper Networks Releases Security Updates for Multiple Products

    Original release date: July 15, 2021 Juniper Networks has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Juniper Networks security advisories page and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • SonicWall Warns Firewall Hardware Bugs Under Attack

    SonicWall issued an urgent security alert warning customers that some of its current and legacy firewall appliances were under active attack.

  • Safari Zero-Day Used in Malicious LinkedIn Campaign

    Researchers shed light on how attackers exploited Apple web browser vulnerabilities to target government officials in Western Europe.

  • Apps Built Better: Why DevSecOps is Your Security Team’s Silver Bullet

    Phil Richards, vice president and CSO at Ivanti, explains how organizations can design DevOps processes and systems to thwart cyberattacks.

  • New StopRansomware.gov website – The U.S. Government’s One-Stop Location to Stop Ransomware

    Original release date: July 15, 2021 The U.S. Government launched a new website to help public and private organizations defend against the rise in ransomware cases. StopRansomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts. We encourage organizations to use this new website to understand the threat of ransomware, mitigate risk, and in the event of an attack, know what steps to take next. The StopRansomware.gov webpage is an interagency resource that provides our partners and stakeholders with ransomware protection, detection, and response guidance that they can use on a single website. This includes…

  • CISA Insights: Guidance for MSPs and Small- and Mid-sized Businesses

    Original release date: July 14, 2021 CISA has released CISA Insights: Guidance for Managed Service Providers (MSPs) and Small- and Mid-sized Businesses, which provides mitigation and hardening guidance to help these organizations strengthen their defenses against cyberattacks. Many small- and mid-sized businesses use MSPs to manage IT systems, store data, or support sensitive processes, making MSPs valuable targets for malicious cyber actors. Compromises of MSPs—such as with the recent Kaseya ransomware attack—can have globally cascading effects and introduce significant risk to MSP customers. CISA strongly recommends MSPs and small- and mid-sized businesses follow the guidance provided in the CISA Insights…

  • Microsoft Crushes 116 Bugs, Three Actively Exploited

    Microsoft tackles 12 critical bugs, part of its July 2021 Patch Tuesday roundup, capping a ‘PrintNightmare’ month of headaches for system admins.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.