Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of June 7, 2021

    Original release date: June 14, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info aomedia — aomedia aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. 2021-06-04 7.5 CVE-2021-30475 MISC MISC broadcom — sannav Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF). 2021-06-09 7.5 CVE-2020-15377 MISC chiyu-tech — bf-430_firmware An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc…

  • Utilities ‘Concerningly’ at Risk from Active Exploits

    Utilities’ vulnerability to application exploits goes from bad to worse in just weeks.  

  • Moobot Milks Tenda Router Bugs for Propagation

    An analysis of the campaign revealed Cyberium, an active Mirai-variant malware hosting site.

  • CISA Releases Advisory on ZOLL Defibrillator Dashboard

    Original release date: June 14, 2021 CISA has released an Industrial Controls Systems (ICS) Medical Advisory on multiple vulnerabilities in the ZOLL Defibrillator Dashboard. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the ICS Medical Advisory ICSMA-21-161-01 and apply the recommended mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

  • Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC

    A trio of security flaws open the door to remote-code execution and a malware tsunami.

  • Critical Chrome Browser Bug Under Active Attack

    Google has patched its Chrome browser, fixing one critical cache issue and a second bug being actively exploited in the wild.

  • STEM Audio Table Rife with Business-Threatening Bugs

    The desktop conferencing IoT gadget allows remote attackers to install all kinds of malware and move laterally to other parts of enterprise networks.

  • JBS Paid $11M to REvil Gang Even After Restoring Operations

    The decision to pay the ransom demanded by the cybercriminal group was to avoid any further issues or potential problems for its customers, according to the company’s CEO.

  • CISA Addresses the Rise in Ransomware Targeting Operational Technology Assets

    Original release date: June 9, 2021 CISA has published the Rising Ransomware Threat to OT Assets fact sheet in response to the recent increase in ransomware attacks targeting operational technology (OT) assets and control systems. The guidance: provides steps to prepare for, mitigate against, and respond to attacks; details how the dependencies between an entity’s IT and OT systems can provide a path for attackers; and explains how to reduce the risk of severe business degradation if affected by ransomware. CISA encourages critical infrastructure (CI) owners and operators to review the Rising Ransomware Threat to OT Assets fact sheet as…

  • Intel Plugs 29 Holes in CPUs, Bluetooth, Security

    The higher-rated advisories focus on privilege-escalation bugs in CPU firmware: Tough to patch, hard to exploit, tempting to a savvy attacker.

  • SAP Releases June 2021 Security Updates

    Original release date: June 8, 2021 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the SAP Security Notes for June 2021 and apply the necessary updates.  This product is provided subject to this Notification and this Privacy & Use policy.

  • Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws

    Researchers discovered a highly targeted malware campaign launched in April, in which a new, unknown threat actor used two of the vulnerabilities that Microsoft said are under active attack.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.