Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of May 24, 2021

    Original release date: May 31, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info aioseo — all_in_one_seo The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with “aioseo_tools_settings” privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin’s configuration by uploading a backup .ini file in the section “Tool > Import/Export”. However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to…

  • HPE Fixes Critical Zero-Day in Server Management Software

    The bug in HPE SIM makes it easy as pie for attackers to remotely trigger code, no user interaction necessary.

  • Joint CISA-FBI Cybersecurity Advisory on Sophisticated Spearphishing Campaign

    Original release date: May 28, 2021 CISA and the Federal Bureau of Investigation (FBI) are responding to an ongoing spearphishing campaign targeting government organizations, intergovernmental organizations, and non-governmental organizations. A sophisticated cyber threat actor leveraged a compromised end-user account from Constant Contact—a legitimate email marketing software company—to spoof a U.S. government organization and distribute links to malicious URLs. In response, CISA and FBI have released Joint Cybersecurity Advisory AA21-148A: Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs and Malware Analysis Report MAR-10339794-1.v1, providing tactics, techniques, and procedures (TTPs); downloadable indicators of compromise (IOCs); and recommended mitigations. CISA strongly encourages organizations…

  • AA21-148A: Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs

    Original release date: May 28, 2021 Summary The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are responding to a spearphishing campaign targeting government organizations, intergovernmental organizations (IGOs), and non-governmental organizations (NGOs). A sophisticated cyber threat actor leveraged a compromised end-user account from Constant Contact, a legitimate email marketing software company, to spoof a U.S.-based government organization and distribute links to malicious URLs.[1] Note: CISA and FBI acknowledge open-source reporting attributing the activity discussed in the report to APT29 (also known as Nobelium, The Dukes, and Cozy Bear).[2,3] However, CISA and FBI are investigating this…

  • FBI Update on Exploitation of Fortinet FortiOS Vulnerabilities

    Original release date: May 28, 2021 The Federal Bureau of Investigation (FBI) has released an FBI FLASH, APT Actors Exploiting Fortinet Vulnerabilities to Gain Access for Malicious Activity, which describes advanced persistent threat (APT) actors exploiting known Fortinet FortiOS vulnerabilities. APT actors may exploit these vulnerabilities to gain initial access to multiple government, commercial, and technology services to conduct future attacks. This is a follow up to the FBI-CISA Joint Cybersecurity Advisory AA21-092A: APT Actors Exploit Vulnerabilities to Gain Initial Access for Future Attack, originally published April 2, and provides indicators of compromise (IOCs) and additional recommended mitigations. CISA encourages…

  • Building Multilayered Security for Modern Threats

    Justin Jett, director of audit and compliance for Plixer, discusses the elements of a successful advanced security posture.

  • Targeted AnyDesk Ads on Google Served Up Weaponized App

    Malicious ad campaign was able to rank higher in searches than legitimate AnyDesk ads.

  • Microsoft Announces New Campaign from NOBELIUM

    Original release date: May 27, 2021 The Microsoft Threat Intelligence Center (MSTIC) has released information on the uncovering of a widespread malicious email campaign undertaken by the activity group that Microsoft tracks as NOBELIUM. NOBELIUM was initially identified in November 2020, during an intrusion at a major cybersecurity organization. Microsoft security researchers identify NOBELIUM as the actor responsible for the 2020 compromise of the SolarWinds Orion platform, and subsequent activity targeting other Microsoft customer networks and cloud assets. CISA encourages users and administrators to review MSTIC’s blog post New sophisticated email-based attack from NOBELIUM and apply the necessary mitigations. This product is provided subject…

  • Updates to Alert on Pulse Connect Secure

    Original release date: May 27, 2021 CISA has updated Alert AA21-110A: Exploitation of Pulse Connect Secure Vulnerabilities to include new threat actor techniques, tactics, and procedures (TTPs), indicators of compromise (IOCs), and updated mitigations.   CISA encourages users and administrators to review AA21-110A and the following resources for more information: •    Re-Checking Your Pulse •    Ivanti KB44755 – Pulse Connect Secure (PCS) Integrity Assurance •    Ivanti Security Advisory SA44784 •    Emergency Directive 21-03: Mitigate Pulse Connect Secure Product Vulnerabilities   This product is provided subject to this Notification and this Privacy & Use policy.

  • Biden’s Cybersecurity Executive Order Puts Emphasis on the Wrong Issues

    David Wolpoff, CTO at Randori, argues that the call for rapid cloud transition Is a dangerous proposition: “Mistakes will be made, creating opportunities for our adversaries.

  • A Peek Inside the Underground Ransomware Economy

    Threat hunters weigh in on how the business of ransomware, the complex relationships between cybercriminals, and how they work together and hawk their wares on the Dark Web.

  • PDF Feature ‘Certified’ Widely Vulnerable to Attack

    Researchers found flaws most of the ‘popular’ PDF applications tested.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.