Cyber Security Alerts & Threat Intelligence
Stay up to date with the latest security alerts and threat intelligence updates
Latest Alerts
Security Bug Allows Attackers to Brick Kubernetes Clusters
The vulnerability is triggered when a cloud container pulls a malicious image from a registry.
Ransomware Attack Creates Cheese Shortages in Netherlands
Not a Gouda situation: An attack on a logistics firm is suspected to be related to Microsoft Exchange server flaw.
NSA-CISA-FBI Joint Advisory on Russian SVR Targeting U.S. and Allied Networks
Original release date: April 15, 2021 CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) have released a Joint Cybersecurity Advisory (CSA) on Russian Foreign Intelligence Service (SVR) actors scanning for and exploiting vulnerabilities to compromise U.S. and allied networks, including national security and government-related systems. Specifically, SVR actors are targeting and exploiting the following vulnerabilities: CVE-2018-13379 Fortinet FortiGate VPN CVE-2019-9670 Synacor Zimbra Collaboration Suite CVE-2019-11510 Pulse Secure Pulse Connect Secure VPN CVE-2019-19781 Citrix Application Delivery Controller and Gateway CVE-2020-4006 VMware Workspace ONE Access Additionally the White House has released a statement formally attributing this activity…
FBI Clears ProxyLogon Web Shells from Hundreds of Orgs
In a veritable cyber-SWAT action, the Feds remotely removed the infections without warning businesses beforehand.
Microsoft Has Busy April Patch Tuesday with Zero-Days, Exchange Fixes
Microsoft fixes 110 vulnerabilities, with 19 classified as critical and another flaw under active attack.
Threat Actors Targeting Cybersecurity Researchers
Original release date: April 14, 2021 Google and Microsoft recently published reports on advanced persistent threat (APT) actors targeting cybersecurity researchers. The APT actors are using fake social media profiles and legitimate-looking websites to lure security researchers into visiting malicious websites to steal information, including exploits and zero-day vulnerabilities. APT groups often use elaborate social engineering and spear phishing schemes to trick victims into running malicious code through malicious links and websites. CISA recommends cybersecurity practitioners to guard against this specific APT activity and review the following reports for more information: Google – Update on campaign targeting security researchers, published…
SAP Releases April 2021 Security Updates
Original release date: April 13, 2021 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the SAP Security Notes for April 2021 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
How the NAME:WRECK Bugs Impact Consumers, Businesses
How this class of vulnerabilities will impact millions connected devices and potentially wreck the day of IT security professionals.
Apply Microsoft April 2021 Security Update to Mitigate Newly Disclosed Microsoft Exchange Vulnerabilities
Original release date: April 13, 2021 Microsoft’s April 2021 Security Update mitigates significant vulnerabilities affecting on-premises Exchange Server 2016 and 2019. An attacker could exploit these vulnerabilities to gain access and maintain persistence on the target host. CISA strongly urges organizations to apply Microsoft’s April 2021 Security Update to mitigate against these newly disclosed vulnerabilities. Note: the Microsoft security updates released in March 2021 do not remediate against these vulnerabilities. In response to these the newly disclosed vulnerabilities, CISA has issued Supplemental Direction Version 2 to Emergency Directive (ED) 21-02: Mitigate Microsoft Exchange On-Premises Product Vulnerabilities. ED 20-02 Supplemental Direction V2…
Adobe Patches Slew of Critical Security Bugs in Bridge, Photoshop
The security bugs could open the door for arbitrary code-execution and full takeover of targeted machines.
Chrome Zero-Day Exploit Posted on Twitter
An update to Google’s browser that fixes the flaw is expected to be released on Tuesday.
Vulnerability Summary for the Week of April 5, 2021
Original release date: April 12, 2021 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info apple — ipad_os An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. 2021-04-02 7.5 CVE-2021-1794 MISC apple — ipad_os An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. 2021-04-02 7.5 CVE-2021-1796 MISC apple — ipad_os A logic…
Need Expert Cybersecurity Guidance?
Our US-based Security Operations Center is ready to help protect your organization.
