Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of July 5, 2021

    Original release date: July 12, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info artware_cms_project — artware_cms ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly. 2021-07-07 7.5 CVE-2021-32538 CONFIRM beardev — joomsport The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does…

  • Kaseya Patches Zero-Days Used in REvil Attacks

    The security update addresses three VSA vulnerabilities used by the ransomware gang to launch a worldwide supply-chain attack on MSPs and their customers.

  • Critical ForgeRock Access Management Vulnerability

    Original release date: July 12, 2021 Malicious cyber actors are actively exploiting a pre-authorization remote code execution vulnerability (CVE-2021-35464) in ForgeRock Access Management—a commercial open access management solution that is based on OpenAM, an open-source access management solution. An attacker exploiting this vulnerability can execute commands in the context of the current user. The vulnerability affects Access Management versions 6.0.0.x, 6.5.0.x, 6.5.1, 6.5.2.x and 6.5.3 and older unsupported versions. CISA recommends Access Management users: Review the ForgeRock Security Advisory and the Australian Cyber Security Centre Alert; Check for vulnerable instances of the Access Management software (see ForgeRock’s Technical Impact Assessment); and…

  • Cisco BPA, WSA Bugs Allow Remote Cyberattacks

    The high-severity security vulnerabilities allow elevation of privileges, leading to data theft and more.

  • Microsoft Office Users Warned on New Malware-Protection Bypass

    Word and Excel documents are enlisted to disable Office macro warnings, so the Zloader banking malware can be downloaded onto systems without security tools flagging it.

  • Coursera Flunks API Security Test in Researchers’ Exam

    The problem APIs included numero uno on the OWASP API Security Top 10: a Broken Object Level Authorization (BOLA) issue that could have exposed personal data.

  • CISA Releases Analysis of FY20 Risk and Vulnerability Assessments

    Original release date: July 8, 2021 CISA has released an analysis and infographic detailing the findings from the Risk and Vulnerability Assessments (RVAs) conducted in Fiscal Year (FY) 2020 across multiple sectors. The analysis details a sample attack path a cyber threat actor could take to compromise an organization with weaknesses that are representative of those CISA observed in FY20 RVAs. The infographic provides a high-level snapshot of five potential attack paths and breaks out the most successful techniques for each tactic that the RVAs documented. Both the analysis and the infographic map threat actor behavior to the MITRE ATT&CK®…

  • MacOS Targeted in WildPressure APT Malware Campaign

    Threat actors enlist compromised WordPress websites in campaign targeting macOS users.

  • Critical Sage X3 RCE Bug Allows Full System Takeovers

    Security vulnerabilities in the ERP platform could allow attackers to tamper with or sabotage victims’ business-critical processes and to intercept data.

  • Why I Love (Breaking Into) Your Security Appliances

    David “moose” Wolpoff, CTO at Randori, discusses security appliances and VPNs and how attackers only have to “pick one lock” to invade an enterprise through them.

  • Microsoft Releases Emergency Patch for PrintNightmare Bugs

    The fix doesn’t cover the entire problem nor all affected systems however, so the company also is offering workarounds and plans to release further remedies at a later date.

  • Microsoft Releases Out-of-Band Security Updates for PrintNightmare

    Original release date: July 6, 2021 Microsoft has released out-of-band security updates to address a remote code execution (RCE) vulnerability—known as PrintNightmare (CVE-2021-34527)—in the Windows Print spooler service. According to the CERT Coordination Center (CERT/CC), “The Microsoft Windows Print Spooler service fails to restrict access to functionality that allows users to add printers and related drivers, which can allow a remote authenticated attacker to execute arbitrary code with SYSTEM privileges on a vulnerable system.” The updates are cumulative and contain all previous fixes as well as protections for CVE-2021-1675. The updates do not include Windows 10 version 1607, Windows Server…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.