Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Windows Hello Bypass Fools Biometrics Safeguards in PCs

    A Windows security bug would allow an attacker to fool a USB camera used in the biometric facial-recognition aspect of the system.

  • Citrix Releases Security Updates for Virtual Apps and Desktops

    Original release date: July 13, 2021 Citrix has released security updates to address a vulnerability in multiple versions of Virtual Apps and Desktops. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review Citrix Security Update CTX319750 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • SAP Releases July 2021 Security Updates

    Original release date: July 13, 2021 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.   CISA encourages users and administrators to review the SAP Security Notes for July 2021 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers

    The ‘ModiPwn’ bug lays open production lines, sensors, conveyor belts, elevators, HVACs and more that use Schneider Electric PLCs.

  • Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader

    Adobe July patch roundup includes fixes for its ubiquitous and free PDF reader Acrobat 2020 and other software such as Illustrator and Bridge.

  • Microsoft Releases July 2021 Security Updates

    Original release date: July 13, 2021 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s July 2021 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Kaseya Ransomware Attack: Guidance and Resources

    Original release date: July 13, 2021 CISA has created a webpage to provide information and guidance for the recent ransomware attack against Kaseya customers that include managed service providers (MSPs) and customers of those MSPs. CISA encourages affected organizations to review Kaseya Ransomware Attack: Guidance for Affected MSPs and their Customers for more information. This product is provided subject to this Notification and this Privacy & Use policy.

  • New CISA Director Confirmed, White House Gains Cyber-Director

    Jen Easterly, former NSA official and Morgan Stanley vet, will take up the lead at CISA as the ransomware scourge rages on.

  • WordPress File Management Plugin Riddled with Critical Bugs

    The bugs allow a range of attacks on websites, including deleting blog pages and remote code execution.

  • SolarWinds Issues Hotfix for Zero-Day Flaw Under Active Attack

    Microsoft alerted the company to a security vulnerability in its Serv-U Managed File Transfer and Secure FTP products that a cyberattacker is using to target a “limited” amount of customers.

  • Kaseya Provides Security Updates for VSA On-Premises Software Vulnerabilities

    Original release date: July 12, 2021 Kaseya has released VSA version 9.5.7a for their VSA On-Premises software. This version addresses vulnerabilities that enabled the ransomware attacks on Kaseya’s customers. CISA strongly urges Kaseya customers closely follow the instructions detailed in the Kaseya security notice and contact Kaseya should they require implementation assistance. Note: the Kaseya security notice includes Startup Runbooks and Hardening and Best Practice Guides for both VSA On-Premises and VSA SaaS. This product is provided subject to this Notification and this Privacy & Use policy.

  • Critical RCE Vulnerability in ForgeRock OpenAM Under Active Attack

    The attacks are enabled by an unpatched security vulnerability in ForgeRock’s Access Management, a popular platform that front-ends web apps and remote-access setups.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.