Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • VMware Releases Security Updates for Carbon Black App Control

    Original release date: February 23, 2023 VMware has released security updates to address a vulnerability in Carbon Black App Control. A remote attacker could exploit this vulnerability to take control of an affected system. For updates addressing lower severity vulnerabilities, see the VMware Security Advisories page. CISA encourages users and administrators to review VMware Security Advisory VMSA-2023-0004and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Vulnerability Summary for the Week of February 13, 2023

    Original release date: February 23, 2023   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info baicells — neutrino_430_firmware Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. 2023-02-11 10 CVE-2023-0776 MISC webbuildersgroup…

  • Mozilla Releases Security Updates for Thunderbird 102.8

    Original release date: February 17, 2023 Mozilla has released security updates to address vulnerabilities in Thunderbird 102.8. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Mozilla’s security advisory for Thunderbird 102.8 for more information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • CISA Releases Fifteen Industrial Control Systems Advisories

    Original release date: February 16, 2023 CISA released fifteen (15) Industrial Control Systems (ICS) advisories on February 16, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-23-047-01 Siemens Solid Edge ICSA-23-047-02 Siemens SCALANCE X-200 IRT ICSA-23-047-03 Siemens Brownfield Connectivity Client ICSA-23-047-04 Siemens Brownfield Connectivity Gateway ICSA-23-047-05 Siemens SiPass integrated AC5102/ACC-G2 and ACC-AP ICSA-23-047-06 Siemens Simcenter Femap ICSA-23-047-07 Siemens TIA Project Server ICSA-23-047-08 Siemens RUGGEDCOM APE1808 ICSA-23-047-09 Siemens SIMATIC Industrial Products ICSA-23-047-10 Siemens COMOS ICSA-23-047-11 Siemens Mendix…

  • Mozilla Releases Security Updates for Firefox 110 and Firefox ESR

    Original release date: February 14, 2023 Mozilla has released security updates to address vulnerabilities in Firefox 110 and Firefox ESR. An attacker could exploit these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Mozilla’s security advisories for Firefox 110 and Firefox ESR 102.8 for more information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Citrix Releases Security Updates for Workspace Apps, Virtual Apps and Desktops

    Original release date: February 14, 2023 Citrix has released security updates to address high-severity vulnerabilities (CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483) in Citrix Workspace Apps, Virtual Apps and Desktops. A local user could exploit these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Citrix security bulletins CTX477618, CTX477617, and CTX477616 for more information and to apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Vulnerability Summary for the Week of February 6, 2023

    Original release date: February 14, 2023   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info webfinance_project — webfinance A vulnerability has been found in fanzila WebFinance 0.5 and classified as critical. This vulnerability affects unknown code of the file htdocs/admin/save_Contract_Signer_Role.php. The manipulation of the argument n/v leads to sql injection. The name of the patch is abad81af614a9ceef3f29ab22ca6bae517619e06. It is recommended to apply a patch to fix this issue. VDB-220054 is the identifier assigned to this vulnerability. 2023-02-03 9.8 CVE-2013-10015 MISC MISC MISC webfinance_project — webfinance A vulnerability was found in fanzila WebFinance 0.5 and…

  • AA23-040A: #StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities

    Original release date: February 9, 2023 Summary Note: This Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and various ransomware threat actors. These #StopRansomware advisories detail historically and recently observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn about other ransomware threats and no-cost resources. The United States National Security Agency (NSA), the U.S. Federal Bureau of Investigation (FBI), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.S.…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.