Cyber Security Alerts & Threat Intelligence
Stay up to date with the latest security alerts and threat intelligence updates
Latest Alerts
Heightened Awareness for Iranian Cyber Activity
Original release date: December 3, 2020 Iranian cyber threat actors have been continuously improving their offensive cyber capabilities. They continue to engage in more conventional offensive cyber activities ranging from website defacement, distributed denial of service (DDoS) attacks, and theft of personally identifiable information (PII), to more advanced activities—including social media-driven influence operations, destructive malware, and, potentially, cyber-enabled kinetic attacks. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Joint Cybersecurity Advisory AA20-259A: Iran-Based Threat Actor Exploits VPN Vulnerabilities and Activity Alert AA20-133A: Top 10 Routinely Exploited Vulnerabilities for information on known Iranian advanced persistent threat…
NCSC Releases 2020 Annual Review
Original release date: December 3, 2020 The United Kingdom (UK) National Cyber Security Centre (NCSC) has released its Annual Review 2020, which focuses on its response to evolving and challenging cyber threats. Recognizing cybersecurity as a “team sport,” the publication includes highlights of NCSC’s collaboration with many partners, including the Cybersecurity and Infrastructure Security Agency (CISA). A few examples: Joint Advisory AA20-126A: APT Groups Target Healthcare and Essential Services, which warned of observed “large-scale ‘password spraying’ campaigns against healthcare bodies and medical research organizations” and provided mitigation advice for this threat. Joint Advisory AA20-245A: Technical Approaches to Uncovering and Remediating…
As Modern Mobile Enables Remote Work, It Also Demands Security
Lookout’s Hank Schless discusses accelerated threats to mobile endpoints in the age of COVID-19-sparked remote working.
Apple Releases Security Updates for iCloud for Windows
Original release date: December 3, 2020 Apple has released security updates to address vulnerabilities in iCloud for Windows. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apple security page for iCloud for Windows 11.5 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
Google Play Apps Remain Vulnerable to High-Severity Flaw
Patches for a flaw (CVE-2020-8913) in the Google Play Core Library have not been implemented by several popular Google Play apps, including Cisco Teams and Edge.
IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply Chain
Original release date: December 3, 2020 IBM X-Force has released a report on malicious cyber actors targeting the COVID-19 cold chain—an integral part of delivering and storing a vaccine at safe temperatures. Impersonating a biomedical company, cyber actors are sending phishing and spearphishing emails to executives and global organizations involved in vaccine storage and transport to harvest account credentials. The emails have been posed as requests for quotations for participation in a vaccine program. The Cybersecurity and Infrastructure Security Agency (CISA) encourages Operation Warp Speed (OWS) organizations and organizations involved in vaccine storage and transport to review the IBM X-Force…
Think-Tanks Under Attack by Foreign APTs, CISA Warns
The feds have seen ongoing cyberattacks on think-tanks (bent on espionage, malware delivery and more), using phishing and VPN exploits as primary attack vectors.
Xerox DocuShare Bugs Allows Data Leaks
CISA warns the leading enterprise document management platform is open to attack and urges companies to apply fixes.
Healthcare 2021: Cyberattacks to Center on COVID-19 Spying, Patient Data
The post-COVID-19 surge in the criticality level of medical infrastructure, coupled with across-the-board digitalization, will be big drivers for medical-sector cyberattacks next year.
Mozilla Releases Security Update for Thunderbird
Original release date: December 2, 2020 Mozilla has released a security update to address a vulnerability in Thunderbird. An attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisory for Thunderbird 78.5.1 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.
Xerox Releases Security Updates for DocuShare
Original release date: December 2, 2020 Xerox has released security updates for DocuShare 6.6.1, 7.0, and 7.5 to address a vulnerability that could allow an unauthenticated attacker to obtain sensitive information. The Cybersecurity and Infrastructure Security Agency (CISA) urges users and administrators review Xerox Mini Bulletin XRX20W and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
iPhone Bug Allowed for Complete Device Takeover Over the Air
Researcher Ian Beer from Google Project Zero took six months to figure out the radio-proximity exploit of a memory corruption bug that was patched in May.
Need Expert Cybersecurity Guidance?
Our US-based Security Operations Center is ready to help protect your organization.
