Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Google Patches Critical Wi-Fi and Audio Bugs in Android Handsets

    Google updates its mobile OS, fixing ten critical bugs, including one remote code execution flaw.

  • Theft of FireEye Red Team Tools

    Original release date: December 8, 2020<br/><p>FireEye has released a blog addressing unauthorized access to their Red Team’s tools by a highly sophisticated threat actor. Red Team tools are often used by cybersecurity organizations to evaluate the security posture of enterprise systems. Although the Cybersecurity and Infrastructure Security Agency (CISA) has not received reporting of these tools being maliciously used to date, unauthorized third-party users could abuse these tools to take control of targeted systems. The exposed tools do not contain zero-day exploits.</p> <p>CISA recommends cybersecurity practitioners review <a href=”https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html”>FireEye’s blog</a>&nbsp;for more information and <a href=”https://github.com/fireeye/red_team_tool_countermeasures”>FireEye’s GitHub repository</a>&nbsp;for detection countermeasures.</p> <div…

  • Critical, Unpatched Bugs Open GE Radiological Devices to Remote Code Execution

    A CISA alert is flagging a critical default credentials issue that affects 100+ types of devices found in hospitals, from MRI machines to surgical imaging.

  • Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays

    Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020.

  • Microsoft Releases December 2020 Security Updates

    Original release date: December 8, 2020 Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Microsoft’s December 2020 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Adobe Releases Security Updates for Multiple Products

    Original release date: December 8, 2020 Adobe has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the following Adobe Security Bulletins and apply the necessary updates. Acrobat and Reader APSB20-75 Lightroom APSB20-74 Experience Manager APSB20-72 Prelude APSB20-70 This product is provided subject to this Notification and this Privacy & Use policy.

  • CERT/CC Releases Information on Vulnerabilities Affecting Open-Source TCP/IP Stacks

    Original release date: December 8, 2020 The CERT Coordination Center (CERT/CC) has released information on 33 vulnerabilities, known as AMNESIA:33, affecting multiple embedded open-source Transmission Control Protocol/Internet Protocol (TCP/IP) stacks. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review CERT/CC Vulnerability Note VU #815128 and CISA Advisory ICSA-20-343-01 for more information and to apply the recommended mitigations. Refer to vendors for appropriate patches, when available. This product is provided subject to this Notification and this Privacy & Use policy.

  • Adobe Warns Windows, macOS Users of Critical-Severity Flaws

    Adobe fixed three critical-severity flaws in Adobe Prelude, Adobe Experience Manager and Adobe Lightroom.

  • Apache Releases Security Update for Apache Struts 2

    Original release date: December 8, 2020 The Apache Software Foundation has released a security update to address a vulnerability in Apache Struts versions 2.0.0 to 2.5.25. A remote attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Apache Security Bulletin S2-061 and apply the necessary update or workaround. This product is provided subject to this Notification and this Privacy & Use policy.

  • SAP Releases December 2020 Security Updates

    Original release date: December 8, 2020 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. These include a missing authentication check vulnerability affecting SAP NetWeaver AS JAVA (P2P Cluster Communication). The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the SAP Security Notes for December 2020 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • ‘Amnesia:33’ TCP/IP Flaws Affect Millions of IoT Devices

    A new set of vulnerabilities has been discovered affecting millions of routers and IoT and OT devices from more than 150 vendors, new research warns.

  • NSA Warns: Patched VMware Bug Under Active Attack

    Feds are warning that adversaries are exploiting a weeks-old bug in VMware’s Workspace One Access and VMware Identity Manager products.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.