Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • U.S. DoD Weapons Programs Lack ‘Key’ Cybersecurity Measures

    The lack of cybersecurity requirements in weapons contracts from the Department of Defense opens the door for dangerous cyberattacks.

  • D-Link, IoT Devices Under Attack By Tor-Based Gafgyt Variant

    A new variant of the Gafgyt botnet – that’s actively targeting vulnerable D-Link and Internet of Things devices – is the first variant of the malware to rely on Tor communications, researchers say.

  • Massive Supply-Chain Cyberattack Breaches Several Airlines

    The cyberattack on SITA, a nearly ubiquitous airline service provider, has compromised frequent-flyer data across many carriers.

  • Microsoft, FireEye Unmask More Malware Linked to SolarWinds Attackers

    Researchers with Microsoft and FireEye found three new malware families, which they said are used by the threat group behind the SolarWinds attack.

  • Update to Alert on Mitigating Microsoft Exchange Server Vulnerabilities

    Original release date: March 4, 2021 CISA is aware of threat actors using open source tools to search for vulnerable Microsoft Exchange Servers and advises entities to investigate for signs of a compromise from at least September 1, 2020. CISA has updated the Alert on the Microsoft Exchange server vulnerabilities with additional detailed mitigations.    CISA encourages administrators to review the updated Alert and the Microsoft Security Update and apply the necessary updates as soon as possible or disconnect vulnerable Exchange servers from the internet until the necessary patch is made available. This product is provided subject to this Notification and this Privacy…

  • Joint NSA and CISA Guidance on Strengthening Cyber Defense Through Protective DNS

    Original release date: March 4, 2021 The National Security Agency (NSA) and CISA have released a Joint Cybersecurity Information (CSI) sheet with guidance on selecting a protective Domain Name System (PDNS) service as a key defense against malicious cyber activity. Protective DNS can greatly reduce the effectiveness of ransomware, phishing, botnet, and malware campaigns by blocking known-malicious domains. Additionally organizations can use DNS query logs for incident response and threat hunting activities. CISA encourages users and administrators to consider the benefits of using a protective DNS service and review NSA and CISA’s CSI sheet on Selecting a Protective DNS Service…

  • CISA Orders Federal Agencies to Patch Exchange Servers

    Espionage attacks exploiting the just-patched remote code-execution security bugs in Microsoft Exchange servers are quickly spreading.

  • Unpatched Bug in WiFi Mouse App Opens PCs to Attack

    Wireless mouse-utility lacks proper authentication and opens Windows systems to attack.

  • AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities

    Original release date: March 3, 2021 Summary Cybersecurity and Infrastructure Security (CISA) partners have observed active exploitation of vulnerabilities in Microsoft Exchange Server products. Successful exploitation of these vulnerabilities allows an unauthenticated attacker to execute arbitrary code on vulnerable Exchange Servers, enabling the attacker to gain persistent system access, as well as access to files and mailboxes on the server and to credentials stored on that system. Successful exploitation may additionally enable the attacker to compromise trust and identity in a vulnerable network. Microsoft released out-of-band patches to address vulnerabilities in Microsoft Exchange Server. The vulnerabilities impact on-premises Microsoft Exchange…

  • CISA Issues Emergency Directive and Alert on Microsoft Exchange Vulnerabilities

    Original release date: March 3, 2021 CISA has issued Emergency Directive (ED) 21-02 and Alert AA21-062 addressing critical vulnerabilities in Microsoft Exchange products. Successful exploitation of these vulnerabilities allows an attacker to access on-premises Exchange servers, enabling them to gain persistent system access and control of an enterprise network.  CISA strongly recommends organizations examine their systems to detect any malicious activity detailed in Alert AA21-062A. Review the following resources for more information: CISA Emergency Directive 21-02: Mitigate Microsoft Exchange On-Premises Product Vulnerabilities AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities Microsoft Security Blog Post: Multiple Security Updates Released for Exchange Server This…

  • Malicious Code Bombs Target Amazon, Lyft, Slack, Zillow

    Attackers have weaponized code dependency confusion to target internal apps at tech giants.

  • Microsoft Exchange Zero-Day Attackers Spy on U.S. Targets

    Full dumps of email boxes, lateral movement and backdoors characterize sophisticated attacks on civil-society targets by a Chinese APT.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.