Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • CISA Releases Capacity Enhancement Guide to Strengthen Agency Resilience to DDoS Attack

    CISA has released actionable guidance for Federal Civilian Executive Branch (FCEB) agencies to help them evaluate and mitigate the risk of volumetric distributed denial-of-service (DDoS) attacks against their websites and related web services. The Capacity Enhancement Guide: Volumetric DDoS Against Web Services Technical Guidance:   Helps agencies prioritize DDoS mitigations based on mission and reputational impact.  Describes DDoS mitigation services so agencies can make risk-informed tradeoff decisions on how to use available resources most effectively.  CISA encourages FCEB agencies to review the guidance and apply the recommendations. Visit Capacity Enhancement Guides for Federal Agencies for more ways to reduce cybersecurity risk. 

  • VMware Releases Security Update for Tools

    VMware has released a security update to address a vulnerability in VMware Tools. A cyber threat actor can exploit this vulnerability to obtain sensitive information. CISA encourages users and administrators to review VMware Security Advisory VMSA-2023-0019 and apply the necessary update.

  • CISA and International Partners Release Malware Analysis Report on Infamous Chisel Mobile Malware

    Today, the United Kingdom’s National Cyber Security Centre (NCSC-UK), the United States’ Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI), New Zealand’s National Cyber Security Centre (NCSC-NZ), Canadian Centre for Cyber Security (CCCS), and the Australian Signals Directorate (ASD) published a joint Malware Analysis Report (MAR), on Infamous Chisel a new mobile malware targeting Android devices with capabilities to enable unauthorized access to compromised devices, scan files, monitor traffic, and periodically steal sensitive information. Infamous Chisel mobile malware has been used in a malware campaign targeting Android devices in use by the…

  • Identification and Disruption of QakBot Infrastructure

    SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to disseminate QakBot infrastructure indicators of compromise (IOCs) identified through FBI investigations as of August 2023. On August 25, FBI and international partners executed a coordinated operation to disrupt QakBot infrastructure worldwide. Disruption operations targeting QakBot infrastructure resulted in the botnet takeover, which severed the connection between victim computers and QakBot command and control (C2) servers. The FBI is working closely with industry partners to share information about the malware to maximize detection, remediation, and prevention measures for network…

  • Juniper Networks Releases Security Advisory for Junos OS and Junos OS Evolved

    Juniper Networks has released a security advisory to address a vulnerability for Junos OS and Junos OS Evolved. A cyber threat actor could exploit this vulnerability to cause a denial-of-service condition. CISA encourages users and administrators to review Juniper’s Support Portal and apply the necessary update.

  • Vulnerability Summary for the Week of August 21, 2023

      High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info qemu — qemu The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. 2023-08-22 10 CVE-2022-36648MISC c-ares — c-ares Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. 2023-08-22 9.8 CVE-2020-22217MISC flac_project — flac Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to…

  • CISA’s VDP Platform 2022 Annual Report Showcases Success

    Today, the Cybersecurity and Infrastructure Security Agency (CISA) released its inaugural Vulnerability Disclosure Policy (VDP) Platform 2022 Annual Report, highlighting the service’s progress supporting vulnerability awareness and remediation across the Federal Civilian Executive Branch (FCEB). This report showcases how agencies have used the VDP Platform—launched in July 2021—to safeguard the FCEB and support risk reduction. The VDP platform gives federal agencies a single, user-friendly interface to intake vulnerability information and to collaborate with the public researcher community for vulnerability awareness and remediation. CISA urges FCEB agencies to review the VDP Platform 2022 Annual Report and encourages use of the platform to promote good-faith…

  • Vulnerability Summary for the Week of August 14, 2023

    High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info foldingathome — client_advanced_control An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py. 2023-08-11 9.8 CVE-2020-27544MISC sourcecodester — school_faculty_scheduling_system SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php. 2023-08-11 9.8 CVE-2020-36034MISCMISCMISC bloofox — bloofoxcms File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers…

  • Juniper Releases Security Advisory for Multiple Vulnerabilities in Junos OS

    Juniper has released a security advisory to address vulnerabilities in Junos OS on SRX Series and EX Series. A remote cyber threat actor could exploit these vulnerabilities to cause a denial-of service condition. CISA encourages users and administrators to review Juniper’s Support Portal and apply the necessary updates.

  • Atlassian Releases Security Update for Confluence Server and Data Center

    Atlassian has released its security bulletin for August 2023 to address a vulnerability in Confluence Server and Data Center, CVE-2023-28709. A remote attacker can exploit this vulnerability to cause a denial-of-service condition. CISA encourages users and administrators to review Atlassian’s August 2003 Security Bulletin and apply the necessary update.

  • Vulnerability Summary for the Week of August 7, 2023

      High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info phoenixcontact — wp_6xxx_series   In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device. 2023-08-08 9.9 CVE-2023-3572MISC qualcomm_inc. — snapdragon Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. 2023-08-08 9.8 CVE-2022-40510MISC microsoft — exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 2023-08-08 9.8 CVE-2023-21709MISC…

  • CISA Releases Twelve Industrial Control Systems Advisories

    CISA released twelve Industrial Control Systems (ICS) advisories on August 10, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.  ICSA-23-222-01 Siemens Solid Edge, JT2Go and Teamcenter Visualization ICSA-23-222-02 Siemens Parasolid Installer ICSA-23-222-03 Siemens JT Open, JT Utilities, and Parasolid ICSA-23-222-04 Siemens Software Center ICSA-23-222-05 Siemens RUGGEDCOM CROSSBOW ICSA-23-222-06 Siemens Parasolid and Teamcenter Visualization ICSA-22-222-07 Siemens Address Processing in SIMATIC ICSA-23-222-08 Resource Allocation in Siemens RUGGEDCOM ICSA-23-222-09 Siemens OpenSSL RSA Decryption in SIMATIC ICSA-23-222-10 Siemens SICAM TOOLBOX II ICSA-23-222-11 Siemens Solid Edge SE2023 ICSA-23-222-12 Network Mirroring in Siemens RUGGEDCOM CISA encourages users and administrators…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.