Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Details Tied to Safari Browser-based ‘ScamClub’ Campaign Revealed

    Public disclosure of a privilege escalation attack details how a cybergang bypassed browser iframe sandboxing with malicious PostMessage popups.

  • AA21-048A: AppleJeus: Analysis of North Korea’s Cryptocurrency Malware

    Original release date: February 17, 2021 Summary This Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint advisory is the result of analytic efforts among the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury (Treasury) to highlight the cyber threat to cryptocurrency posed by North Korea, formally known as the Democratic People’s Republic of Korea (DPRK), and provide mitigation recommendations. Working with U.S. government partners, FBI, CISA, and Treasury assess that Lazarus Group—which…

  • North Korean Malicious Cyber Activity: AppleJeus

    Original release date: February 17, 2021 CISA, the Federal Bureau of Investigation, and the Department of the Treasury have released a Joint Cybersecurity Advisory and seven Malware Analysis Reports (MARs) on the North Korean government’s dissemination of malware that facilitates the theft of cryptocurrency—referred to by the U.S. Government as “AppleJeus.” The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDEN COBRA. CISA encourages users and administrators to review the following resources for more information. Joint Cybersecurity Advisory: AppleJeus: Analysis of North Korea’s Cryptocurrency Malware MAR-10322463-1.v1: AppleJeus – Celas Trade Pro MAR-10322463-2.v1: AppleJeus – JMT Trading…

  • Misconfigured Baby Monitors Allow Unauthorized Viewing

    Hundreds of thousands of individuals are potentially affected by this vulnerability.

  • Microsoft Pulls Bad Windows Update After Patch Tuesday Headaches

    Microsoft released a new servicing stack update (KB5001078) after an older one caused problems for Windows users installing Patch Tuesday security updates.

  • Unpatched Android App with 1 Billion Downloads Threatens Spying, Malware

    Attackers can exploit SHAREit permissions to execute malicious code through vulnerabilities that remain unpatched three months after app makers were informed.

  • Vulnerability Summary for the Week of February 8, 2021

    Original release date: February 15, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adobe — acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Write vulnerability when parsing a crafted jpeg file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 2021-02-11 9.3 CVE-2021-21044 MISC adobe — acrobat Acrobat Reader DC versions versions 2020.013.20074…

  • mHealth Apps Expose Millions to Cyberattacks

    Researcher testing of 30 mobile health apps for clinicians found that all of them had vulnerable APIs.

  • Singtel Suffers Zero-Day Cyberattack, Damage Unknown

    The Tier 1 telecom giant was caught up in a coordinated, wide-ranging attack using unpatched security bugs in the Accellion legacy file-transfer platform.

  • VMware Releases Security Update

    Original release date: February 12, 2021 VMware has released a security update to address a vulnerability in vSphere Replication. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review VMware Security Advisory VMSA-2021-0001 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

  • Compromise of U.S. Water Treatment Facility

    Original release date: February 11, 2021 In response to recent events where unidentified cyber actors obtained unauthorized access to the supervisory control and data acquisition (SCADA) system at a U.S. drinking water treatment facility, CISA, the Federal Bureau of Investigation, the Environmental Protection Agency, and the Multi-State Information Sharing and Analysis Center have released joint Cybersecurity Advisory AA21-042A: Compromise of U.S. Water Treatment Facility. This advisory outlines how cyber criminals exploit desktop sharing software and end-of-life operating systems to gain unauthorized access to systems. This product is provided subject to this Notification and this Privacy & Use policy.

  • AA21-042A: Compromise of U.S. Water Treatment Facility

    Original release date: February 11, 2021 Summary On February 5, 2021, unidentified cyber actors obtained unauthorized access to the supervisory control and data acquisition (SCADA) system at a U.S. drinking water treatment plant. The unidentified actors used the SCADA system’s software to increase the amount of sodium hydroxide, also known as lye, a caustic chemical, as part of the water treatment process. Water treatment plant personnel immediately noticed the change in dosing amounts and corrected the issue before the SCADA system’s software detected the manipulation and alarmed due to the unauthorized change. As a result, the water treatment process remained…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.