Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Verify Your Valentine

    Original release date: February 11, 2021 This Valentine’s Day, before you go looking for love in all the wrong chat rooms, CISA reminds users to be wary of internet romance scams. At first, cyber criminals promise the reward of romance after adopting an alias to appear as a potential partner. Once your heart is hooked on hope, they turn the tables. The scammer with the illusive identity will ask for money, making promises of phony matrimony, as they finagle funds from you as a fake fiancée. If you don’t know who you are doting on when you are dating, be…

  • Military, Nuclear Entities Under Target By Novel Android Malware

    The two malware families have sophisticated capabilities to exfiltrate SMS messages, WhatsApp messaging content and geolocation.

  • SAP Commerce Critical Security Bug Allows RCE

    The critical SAP cybersecurity flaw could allow for the compromise of an application used by e-commerce businesses.

  • Microsoft Launches Phase 2 Mitigation for Netlogon Remote Code Execution Vulnerability (CVE-2020-1472)

    Original release date: February 10, 2021 Microsoft addressed a critical remote code execution vulnerability affecting the Netlogon protocol (CVE-2020-1472) on August 11, 2020. Beginning with the February 9, 2021 Security Update release, Domain Controllers will be placed in enforcement mode. This will require all Windows and non-Windows devices to use secure Remote Procedure Call (RPC) with Netlogon secure channel or to explicitly allow the account by adding an exception for any non-compliant device. CISA encourages users and administrators to review the Microsoft security update and apply the necessary updates. This product is provided subject to this Notification and this Privacy…

  • Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple

    Ethical hacker Alex Birsan developed a way to inject malicious code into open-source developer tools to exploit dependencies in organizations internal applications.

  • Intel Squashes High-Severity Graphics Driver Flaws

    Intel is warning on security bugs across its graphics drivers, server boards, compute modules and modems.

  • Actively Exploited Windows Kernel EoP Bug Allows Takeover

    Microsoft addressed 56 security vulnerabilities for February Patch Tuesday — including 11 critical and six publicly known. And, it continued to address the Zerologon bug.

  • Attackers Exploit Critical Adobe Flaw to Target Windows Users

    A critical vulnerability in Adobe Reader has been exploited in “limited attacks.”

  • Microsoft Releases February 2021 Security Updates

    Original release date: February 9, 2021 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s February 2021 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Microsoft Warns of Windows Win32k Privilege Escalation

    Original release date: February 9, 2021 Microsoft has released a security advisory to address an escalation of privileges vulnerability, CVE-2021-1732, in Microsoft Win32k. A local attacker can exploit this vulnerability to take control of an affected system. This vulnerability was detected in exploits in the wild. CISA encourages users and administrators to review Microsoft Advisory for CVE-2021-1732 and apply the necessary patch to Windows 10 and Windows 2019 servers. This product is provided subject to this Notification and this Privacy & Use policy.

  • Critical WordPress Plugin Flaw Allows Site Takeover

    A patch in the NextGen Gallery WordPress plugin fixes critical and high-severity cross-site request forgery flaws.

  • Mozilla Releases Security Updates for Firefox and Firefox ESR

    Original release date: February 8, 2021 Mozilla has released security updates addressing a vulnerability affecting Firefox and Firefox ESR. An attacker can take advantage of this vulnerability to take control of an affected system.   CISA encourages users and administrators to review the Mozilla security advisory for Firefox 85.0.1 and Firefox ESR 78.7.1 and apply the necessary updates.   This product is provided subject to this Notification and this Privacy & Use policy.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.