Cyber Security Alerts & Threat Intelligence
Stay up to date with the latest security alerts and threat intelligence updates
Latest Alerts
Vulnerability Summary for the Week of December 26, 2022
Original release date: January 4, 2023 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info dlink — dir-846_firmware D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function. 2022-12-23 9.9 CVE-2022-46641 MISC MISC dlink — dir-846_firmware D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function. 2022-12-23 9.9 CVE-2022-46642 MISC MISC usememos — memos Improper Authentication in GitHub repository usememos/memos prior to 0.9.0. 2022-12-23 9.8 CVE-2022-4686 MISC CONFIRM linux — linux_kernel An issue was discovered in…
Vulnerability Summary for the Week of December 19, 2022
Original release date: December 28, 2022 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info greenend — sftpserver ** DISPUTED ** A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is bf4032f34832ee11d79aa60a226cc018e7ec5eed. It is recommended to apply a patch to fix this issue. The identifier VDB-216205 was assigned to this vulnerability. NOTE: In some deployment…
Vulnerability Summary for the Week of December 12, 2022
Original release date: December 19, 2022 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info hp — futuresmart_5 A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products. 2022-12-12 9.8 CVE-2021-3821 MISC google — android In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
CISA Releases Forty-One Industrial Control Systems Advisories
Original release date: December 15, 2022 CISA has released forty-one (41) Industrial Control Systems (ICS) advisories on 15 December 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-349-01 Prosys OPC UA Simulation ICSA-22-349-02 Siemens SCALANCE X-200RNA Switch Devices ICSA-22-349-03 Siemens Multiple Denial of Service Vulnerabilities in Industrial Products ICSA-22-349-04 Siemens Multiple Vulnerabilities in SCALANCE Products ICSA-22-349-05 Siemens PLM Help Server ICSA-22-349-06 Siemens SIMATIC WinCC OA Ultralight Client ICSA-22-349-07 Siemens Simcenter STAR-CCM+ ICSA-22-349-08 Siemens Polarion ALM ICSA-22-349-09…
CISA Consolidates Twitter Accounts
Original release date: December 15, 2022 CISA has consolidated its social media presence on Twitter. Three accounts — @ICSCERT, @Cyber, and @CISAInfraSec — are no longer active. Additionally, the @USCERT_gov Twitter account is now renamed @CISACyber. The following current active Twitter accounts will include posts on content previously covered on the now-inactive accounts. @CISACyber will cover updates relevant to the industrial control systems community along with the latest vulnerability management info, threat analysis, and other info relevant to the cybersecurity community. @CISAgov will continue to provide agencywide content or non-urgent ICS updates. @CISAJen will continue to include posts across a…
Drupal Releases Security Updates to Address Vulnerabilities in H5P and File (Field) Paths
Original release date: December 15, 2022 Drupal has released security updates to address vulnerabilities affecting H5P and the File (Field) Paths modules for Drupal 7.x. An attacker could exploit these vulnerabilities to access sensitive information and remotely execute code. CISA encourages users and administrators to review Drupal’s security advisories SA-CONTRIB-2022-064 and SA-CONTRIB-2022-065 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.
Microsoft Releases December 2022 Security Updates
Original release date: December 13, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s December 2022 Security Update Guide and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
CISA Updates Advisory on #StopRansomware: Cuba Ransomware
Original release date: December 13, 2022 The Federal Bureau of Investigation (FBI) and CISA have updated joint Cybersecurity Advisory AA22-335A: #StopRansomware: Cuba Ransomware, originally released on December 01, 2022. The advisory has been updated to include additional indicators of compromise (IOCs). CISA encourages organizations to review the latest update to AA22-335A and apply the recommended mitigations. This product is provided subject to this Notification and this Privacy & Use policy.
Citrix Releases Security Updates for Citrix ADC, Citrix Gateway
Original release date: December 13, 2022 Citrix has released security updates to address a critical vulnerability (CVE-2022-27518) in Citrix ADC and Citrix Gateway. An attacker could exploit this vulnerability to take control of an affected system. This vulnerability has been exploited in the wild. CISA encourages users and administrators to review Citrix security bulletin CTX457836 and Citrix’s blog post for more information and to apply the necessary updates. Additionally, CISA urges organizations to review NSA’s advisory APT5: Citrix ADC Threat Hunting Guidance for detection and mitigation guidance against tools employed by a malicious actor targeting vulnerable Citrix ADC systems. This product is…
Vulnerability Summary for the Week of December 5, 2022
Original release date: December 12, 2022 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info activerecord_project — activerecord A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE. 2022-12-05 9.8 CVE-2022-32224 MISC MISC algan — prens_student_information_system Algan Yazılım Prens Student Information System product has an unauthenticated SQL Injection vulnerability. 2022-12-02 9.8 CVE-2022-2807 CONFIRM algan — prens_student_information_system Algan Yaz?l?m Prens…
Fortinet Releases Security Updates for FortiOS
Original release date: December 12, 2022 Fortinet has released security updates to address a heap-based buffer overflow vulnerability (CVE-2022-42475) in FortiOS. An attacker could exploit this vulnerability to take control of an affected system. This vulnerability has been exploited in the wild. CISA encourages users and administrators to review Fortinet security advisory FG-IR-22-368, apply the necessary updates, and validate systems against the IOCs listed in the advisory. This product is provided subject to this Notification and this Privacy & Use policy.
Cisco Releases Security Advisory for IP Phone 7800 and 8800 Series
Original release date: December 9, 2022 Cisco released a security advisory for a vulnerability affecting IP Phone 7800 and 8800 Series. A remote attacker could exploit this vulnerability to cause a denial-of-service condition. For more information, see the Cisco Security Advisories page. CISA encourages users and administrators to review Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol Stack Overflow Vulnerability and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
Need Expert Cybersecurity Guidance?
Our US-based Security Operations Center is ready to help protect your organization.
