Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Google Patches Critical Android RCE Bug

    Google’s June security bulletin addresses 90+ bugs in Android and Pixel devices.

  • Microsoft Releases June 2021 Security Updates

    Original release date: June 8, 2021 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker can exploit some of these vulnerabilities to take control of an affected system.  CISA encourages users and administrators to review Microsoft’s June 2021 Security Update Summary and Deployment Information and apply the necessary updates.  This product is provided subject to this Notification and this Privacy & Use policy.

  • Windows Container Malware Targets Kubernetes Clusters

    “Siloscape”, the first malware to target Windows containers, breaks out of Kubernetes clusters to plant backdoors and raid nodes for credentials.

  • Vulnerability Summary for the Week of May 31, 2021

    Original release date: June 7, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info gnome — gdk-pixbuf A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. 2021-05-28 8.3 CVE-2021-20240 MISC FEDORA FEDORA FEDORA ibm — cognos_analytics IBM Cognos Analytics 11.0…

  • Unpatched VMware vCenter Software

    Original release date: June 4, 2021 CISA is aware of the likelihood that cyber threat actors are attempting to exploit CVE-2021-21985, a remote code execution vulnerability in VMware vCenter Server and VMware Cloud Foundation. Although patches were made available on May 25, 2021, unpatched systems remain an attractive target and attackers can exploit this vulnerability to take control of an unpatched system. CISA encourages users and administrators to review VMware’s VMSA-2021-010, blogpost, and FAQ for more information about the vulnerability and apply the necessary updates as soon as possible, even if out-of-cycle work is required. If an organization cannot immediately apply…

  • ‘Battle for the Galaxy’ Mobile Game Leaks 6M Gamer Profiles

    Unprotected server exposes AMT Games user data containing user emails and purchase information.

  • Then and Now: Securing Privileged Access Within Healthcare Orgs

    Joseph Carson, chief security scientist and advisory CISO at ThycoticCentrify, discusses best practices for securing healthcare data against the modern threat landscape.

  • Exchange Servers Targeted by ‘Epsilon Red’ Malware

    REvil threat actors may be behind a set of PowerShell scripts developed for encryption and weaponized to exploit vulnerabilities in corporate networks, the ransom note suggests.

  • Podcast: The State of Ransomware

    In this Threatpost podcast, Fortinet’s top researcher sketches out the ransom landscape, with takeaways from the DarkSide attack on Colonial Pipeline.

  • CISA Releases Best Practices for Mapping to MITRE ATT&CK®

    Original release date: June 2, 2021 As part of an effort to encourage a common language in threat actor analysis, CISA has released Best Practices for MITRE ATT&CK® Mapping. The guide shows analysts—through instructions and examples—how to map adversary behavior to the MITRE ATT&CK framework. CISA created this guide in partnership with the Homeland Security Systems Engineering and Development Institute™ (HSSEDI), a DHS-owned R&D center operated by MITRE, which worked with the MITRE ATT&CK team. CISA and other organizations in the cybersecurity community use MITRE ATT&CK to identify and analyze threat actor behavior. This analysis enables them to produce a…

  • Where Bug Bounty Programs Fall Flat

    Some criminals package exploits into bundles to sell on cybercriminal forums years after they were zero days, while others say bounties aren’t enough .

  • Cyber-Insurance Fuels Ransomware Payment Surge

    Companies relying on their cyber-insurance policies to pay off ransomware criminals are being blamed for a recent uptick in ransomware attacks.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.