Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • AA21-055A: Exploitation of Accellion File Transfer Appliance

    Original release date: February 24, 2021 Summary This joint advisory is the result of a collaborative effort by the cybersecurity authorities of Australia,[1] New Zealand,[2] Singapore,[3] the United Kingdom,[4] and the United States.[5][6] These authorities are aware of cyber actors exploiting vulnerabilities in Accellion File Transfer Appliance (FTA).[7] This activity has impacted organizations globally, including those in Australia, New Zealand, Singapore, the United Kingdom, and the United States. Worldwide, actors have exploited the vulnerabilities to attack multiple federal and state, local, tribal, and territorial (SLTT) government organizations as well as private industry organizations including those in the medical, legal, telecommunications,…

  • CISA Releases Joint Cybersecurity Advisory on Exploitation of Accellion File Transfer Appliance

    Original release date: February 24, 2021 The cybersecurity authorities of Australia, New Zealand, Singapore, the United Kingdom, and the United States have released Joint Cybersecurity Advisory AA21-055A: Exploitation of Accellion File Transfer Appliance. Cyber actors worldwide have exploited vulnerabilities in Accellion File Transfer Appliance to attack multiple federal, and state, local, tribal, and territorial government organizations as well as private industry organizations in the medical, legal, telecommunications, finance, and energy fields. In some instances, the attacker extorted money from victim organizations to prevent public release of information exfiltrated from a compromised Accellion appliance. CISA encourages users and administrators to review…

  • IBM Squashes Critical Remote Code-Execution Flaw

    A critical-severity buffer-overflow flaw that affects IBM Integration Designer could allow remote attackers to execute code.

  • SonicWall Releases Additional Patches

    Original release date: February 23, 2021 SonicWall has released firmware patches for SMA 100 series products in an update to its previous alert from February 3, 2021. A remote attacker could exploit a vulnerability in versions of SMA 10 prior to 10.2.0.5-29sv to take control of an affected system. CISA encourages users and administrators to review the updated SonicWall alert and apply the necessary patches as soon as possible. This product is provided subject to this Notification and this Privacy & Use policy.

  • Accellion FTA Zero-Day Attacks Show Ties to Clop Ransomware, FIN11

    The threat actors stole data and used Clop’s leaks site to demand money in an extortion scheme, though no ransomware was deployed.

  • Vulnerability Summary for the Week of February 15, 2021

    Original release date: February 22, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info accellion — fta Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. 2021-02-16 7.2 CVE-2021-27102 MISC MISC accellion — fta Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later. 2021-02-16 10 CVE-2021-27104 MISC MISC accellion — fta Accellion FTA 9_12_411 and earlier is affected by SSRF…

  • Microsoft: SolarWinds Attackers Downloaded Azure, Exchange Code

    However, internal products and systems were not leveraged to attack others during the massive supply-chain incident, the tech giant said upon completion of its Solorigate investigation.

  • Cisco Releases Security Updates for AnyConnect Secure Mobility Client

    Original release date: February 18, 2021 Cisco has released security updates to address a vulnerability in Cisco AnyConnect Secure Mobility Client. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review Cisco Security Advisory cisco-sa-anyconnect-dll-hijac-JrcTOQMC and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Stolen Jones Day Law Firm Files Posted on Dark Web

    Jones Day, which represented Trump, said the breach is part of the Accellion attack from December.

  • SDK Bug Lets Attackers Spy on User’s Video Calls Across Dating, Healthcare Apps

    Apps like eHarmony and MeetMe are affected by a flaw in the Agora toolkit that went unpatched for eight months, researchers discovered.

  • Ninja Forms WordPress Plugin Bug Opens Websites to Hacks

    The popular plugin is installed on more than 1 million websites, and has four flaws that allow various kinds of serious attacks, including site takeover and email hijacking.

  • Complaint Blasts TikTok’s ‘Misleading’ Privacy Policies

    TikTok is again in hot water for how the popular video-sharing app collects and shares data – particularly from its underage userbase.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.