Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of February 1, 2021

    Original release date: February 8, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info accel-ppp — accel-ppp Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution. 2021-02-01 7.5 CVE-2020-28194 MISC MISC adt — lifeshield_diy_hd_video_doorbell_firmware Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to…

  • Industrial Networks See Sharp Uptick in Hackable Security Holes

    Claroty reports that adversaries, CISOs and researchers have all turned their attention to finding critical security bugs in ICS networks.

  • Unpatched WordPress Plugin Code-Injection Bug Afflicts 50K Sites

    An CRSF-to-stored-XSS security bug plagues 50,000 ‘Contact Form 7’ Style users.

  • Google Chrome Zero-Day Afflicts Windows, Mac Users

    Google warns of a zero-day vulnerability in the V8 open-source engine that’s being actively exploited by attackers.

  • Cisco Releases Security Updates

    Original release date: February 4, 2021 Cisco has released security updates to address vulnerabilities in Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the following Cisco Advisories and apply the necessary updates. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities cisco-sa-rv160-260-rce-XZeFkNHf Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021 cisco-sa-sudo-privesc-jan2021-qnYQfcM Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability cisco-sa-xripv6-spJem78K Cisco Small Business…

  • Critical Cisco Flaws Open VPN Routers Up to RCE Attacks

    The vulnerabilities exist in Cisco’s RV160, RV160W, RV260, RV260P, and RV260W VPN routers for small businesses.

  • Second SolarWinds Attack Group Breaks into USDA Payroll — Report

    A second APT, potentially linked to the Chinese government, could be behind the Supernova malware.

  • New Malware Hijacks Kubernetes Clusters to Mine Monero

    Researchers warn that the Hildegard malware is part of ‘one of the most complicated attacks targeting Kubernetes.’

  • SolarWinds Orion Bug Allows Easy Remote-Code Execution and Takeover

    The by-now infamous company has issued patches for three security vulnerabilities in total.

  • Tiny Kobalos Malware Bedevils Supercomputers to Steal Logins

    The sophisticated backdoor steals SSH credentials for servers in academic and scientific high-performance computing clusters.

  • Apple Releases Security Updates

    Original release date: February 2, 2021 Apple has released security updates to address vulnerabilities in macOS Big Sur 11.0.1, macOS Catalina 10.15.7, and macOS Mojave 10.14.6. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Apple security update and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Sudo Heap-Based Buffer Overflow Vulnerability — CVE-2021-3156

    Original release date: February 2, 2021 Sudo has released an advisory addressing a heap-based buffer overflow vulnerability—CVE-2021-3156—affecting sudo legacy versions 1.8.2 through 1.8.31p2 and stable versions 1.9.0 through 1.9.5p1. Sudo is a utility included in many Unix- and Linux-based operating systems that allows a user to run programs with the security privileges of another user. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to update to sudo version 1.9.5p2, refer to vendors for available patches, and review the following resources for additional information. Sudo Advisory Qualys Blog This product is…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.