Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Cisco Releases Security Advisory for Vulnerability in AnyConnect Software

    Original release date: December 7, 2020 Cisco has released a security advisory on an Arbitrary Code Execution vulnerability—CVE-2020-3556—affecting Cisco AnyConnect Secure Mobility Client devices. A remote attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Cisco Security Advisory and apply the necessary updates or workarounds. This product is provided subject to this Notification and this Privacy & Use policy.

  • NSA Releases Advisory on Russian State-Sponsored Malicious Cyber Actors Exploiting CVE-2020-4006

    Original release date: December 7, 2020 The National Security Agency (NSA) has released a Cybersecurity Advisory on Russian state-sponsored actors exploiting CVE-2020-4006, a command-injection vulnerability in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. The actors were found exploiting this vulnerability to access protected data on affected systems. The NSA advisory provides mitigation and detection guidance. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the following resources and apply the necessary updates and detection guidance. NSA Cybersecurity Advisory Russian State-Sponsored Actors Exploiting Vulnerability in VMware Workspace ONEAccess Using Compromised Credentials VMware…

  • Vulnerability Summary for the Week of November 30, 2020

    Original release date: December 7, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available.   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info 74cms — 74cms PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution. 2020-12-02 7.5 CVE-2020-29279 MISC MISC bloodx_project — bloodx SQL injection vulnerability in BloodX 1.0…

  • Insider Report: Healthcare Security Woes Balloon in COVID-Era

    As hackers put a bullseye on healthcare, Threatpost spotlights how hospitals, researchers and patients have been affected and how the sector is bolstering their cyber defenses.

  • Healthcare in Crisis: Diagnosing Cybersecurity Shortcomings in Unprecedented Times

    In the early fog of the COVID-19 pandemic, cybersecurity took a back seat to keeping patients alive. Lost in the chaos was IT security.

  • QNAP High-Severity Flaws Plague NAS Systems

    The high-severity cross-site scripting flaws could allow remote-code injection on QNAP NAS systems.

  • High-Severity Chrome Bugs Allow Browser Hacks

    Desktop versions of the browser received a total of eight fixes, half rated high-severity.

  • Novel Online Shopping Malware Hides in Social-Media Buttons

    The skimmer steals credit-card data, using steganography to hide in plain sight in seemingly benign images.

  • Apache Releases Security Advisory for Apache Tomcat

    Original release date: December 4, 2020 The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An attacker could exploit this vulnerability to cause a denial-of-service condition. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apache security advisory for CVE-2020-17527 upgrade to the appropriate version. This product is provided subject to this Notification and this Privacy & Use policy.

  • VMware Rolls a Fix for Formerly Critical Zero-Day Bug

    VMware has issued a full patch and revised the severity level of the NSA-reported vulnerability to “important.”

  • VMware Releases Security Updates to Address CVE-2020-4006

    Original release date: December 3, 2020 VMware has released security updates to address a vulnerability—CVE-2020-4006—in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker could exploit this vulnerability to take control of an affected system.  The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory VMSA-2020-0027.2 and apply the necessary updates.  This product is provided subject to this Notification and this Privacy & Use policy.

  • TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions

    A new “TrickBoot” module scans for vulnerable firmware and has the ability to read, write and erase it on devices.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.