Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • VMware Sounds Ransomware Alarm Over Critical Severity Bug

    VMware’s virtualization management platform, vCenter Server, has a critical severity bug the company is urging customers to patch “as soon as possible”.

  • Trend Micro Bugs Threaten Home Network Security

    The security vendor’s network management and threat protection station can open the door to code execution, DoS and potential PC takeovers.

  • Combatting Insider Threats with Keyboard Security

    Dale Ludwig, business development manager at Cherry Americas, discusses advances in hardware-based security that can enhance modern cyber-defenses.

  • Pulse Secure VPNs Get Quick Fix for Critical RCE

    One of the workaround XML files automatically deactivates protection from an earlier workaround: a potential path to older vulnerabilities being opened again.

  • Restaurant Reservation System Patches Easy-to-Exploit XSS Bug

    A WordPress reservation plugin has a vulnerability that allows unauthenticated hackers to access reservation data stored by site owners.

  • Vulnerability Summary for the Week of May 17, 2021

    Original release date: May 24, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info cars-seller-auto-classifieds-script_project — cars-seller-auto-classifieds-script The request_list_request AJAX call of the Car Seller – Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue. 2021-05-14 7.5 CVE-2021-24285 MISC CONFIRM kaswara_project — kaswara The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the ‘uploadFontIcon’ AJAX action. The supplied zipfile…

  • WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites

    The plugin, installed on hundreds of thousands of sites, allows anyone to filch database info without having to be logged in.

  • Four Android Bugs Being Exploited in the Wild

    On Wednesday, Google quietly slipped updates into its May 3 Android security bulletin for bugs that its Project Zero group has confirmed are zero-days.

  • Apple Exec Calls Level of Mac Malware ‘Unacceptable’

    Company is using threat of attacks as defense in case brought against it by Epic Games after Fortnite was booted from the App Store for trying to circumvent developer fees.

  • Update to CISA-FBI Joint Cybersecurity Advisory on DarkSide Ransomware

    Original release date: May 19, 2021 CISA and the Federal Bureau of Investigation (FBI) have updated Joint Cybersecurity Advisory AA21-131A: DarkSide Ransomware: Best Practices for Preventing Disruption from Ransomware Attacks, originally released May 11, 2021. This update provides a downloadable STIX file of indicators of compromise (IOCs) to help network defenders find and mitigate activity associated with DarkSide ransomware. These IOCs were shared with critical infrastructure partners and network defenders on May 10, 2021. CISA encourages users and administrators to review AA21-131A for more information.   This product is provided subject to this Notification and this Privacy & Use policy.

  • Can Nanotech Secure IoT Devices From the Inside-Out?

    Work’s being done with uber-lightweight nanoagents on every IoT device to stop malicious behavior, such as a scourge of botnet attacks, among other threats.

  • Keksec Cybergang Debuts Simps Botnet for Gaming DDoS

    The newly discovered malware infects IoT devices in tandem with the prolific Gafgyt botnet, using known security vulnerabilities.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.