Cyber Security Alerts & Threat Intelligence
Stay up to date with the latest security alerts and threat intelligence updates
Latest Alerts
Microsoft Releases Out-of-Band Security Updates for Exchange Server
Original release date: March 2, 2021 Microsoft has released out-of-band security updates to address vulnerabilities affecting Microsoft Exchange Server 2013, 2016, and 2019. A remote attacker can exploit three remote code execution vulnerabilities—CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065—to take control of an affected system and can exploit one vulnerability—CVE-2021-26855—to obtain access to sensitive information. These vulnerabilities are being actively exploited in the wild. CISA encourages users and administrators to review the Microsoft blog post and apply the necessary updates or workarounds. This product is provided subject to this Notification and this Privacy & Use policy.
Mobile Adware Booms, Online Banks Become Prime Target for Attacks
A snapshot of the 2020 mobile threat landscape reveals major shifts toward adware and threats to online banks.
Vulnerability Summary for the Week of February 22, 2021
Original release date: March 1, 2021 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info alleghenycreative — openrepeater OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. 2021-02-19 10 CVE-2019-25024 MISC MISC amaze_file_manager_project — amaze_file_manager Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. 2021-02-19 7.2 CVE-2020-36246 MISC MISC arubanetworks — clearpass_policy_manager A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management…
Firewall Vendor Patches Critical Auth Bypass Flaw
Cybersecurity firm Genua fixes a critical flaw in its GenuGate High Resistance Firewall, allowing attackers to log in as root users.
NSA Releases Guidance on Zero Trust Security Model
Original release date: February 26, 2021 The National Security Agency (NSA) has released Cybersecurity Information Sheet: Embracing a Zero Trust Security Model, which provides information about, and recommendations for, implementing Zero Trust within networks. The Zero Trust security model is a coordinated system management strategy that assumes breaches are inevitable or have already occurred. CISA encourages administrators and organizations review NSA’s guidance on Embracing a Zero Trust Security Model to help secure sensitive data, systems, and services. This product is provided subject to this Notification and this Privacy & Use policy.
Tax Season Ushers in Quickbooks Data-Theft Spike
Quickbooks malware targets tax data for attackers to sell and use in phishing scams.
Cisco Warns of Critical Auth-Bypass Security Flaw
Cisco also stomped out a critical security flaw affecting its Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches.
VMWare Patches Critical RCE Flaw in vCenter Server
The vulnerability, one of three patched by the company this week, could allow threat actors to breach the external perimeter of a data center or leverage backdoors already installed to take over a system.
Mozilla Releases Security Updates for Thunderbird, Firefox ESR, and Firefox
Original release date: February 24, 2021 Mozilla has released security updates to address multiple vulnerabilities in Thunderbird 78.8, Firefox ESR 78.8, and Firefox 86. An attacker could exploit these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Mozilla security advisories and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
VMware Releases Multiple Security Updates
Original release date: February 24, 2021 VMware has released security updates to address multiple vulnerabilities–CVE-2021-21972, CVE-2021-21973, CVE-2021-21974—ESXi, vCenter Server, and Cloud Foundation. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review VMware Security Advisory VMSA-2021-0002 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
Nvidia’s Anti-Cryptomining Chip May Not Discourage Attacks
The hotly anticipated ray-tracing, advanced gaming graphics chip will throttle Ethereum mining.
Daycare Webcam Service Exposes 12,000 User Accounts
NurseryCam suspends service across 40 daycare centers until a security fix is in place.
Need Expert Cybersecurity Guidance?
Our US-based Security Operations Center is ready to help protect your organization.
