Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • CISA Adds Six Known Exploited Vulnerabilities to Catalog

    Original release date: October 24, 2022 CISA has added six vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: to view the newly added vulnerabilities in the catalog, click on the arrow in the “Date Added to Catalog” column, which will sort by descending dates.       Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known CVEs that carry significant risk…

  • Vulnerability Summary for the Week of October 17, 2022

    Original release date: October 24, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info 74cms — 74cmsse An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file. 2022-10-17 9.8 CVE-2022-42154 MISC acer — altos_w2000h-w570h_f4_firmware Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable. 2022-10-19 9.8 CVE-2022-41415 MISC MISC MISC adobe — acrobat_reader_dc Adobe Acrobat…

  • #StopRansomware: Daixin Team

    Original release date: October 21, 2022 CISA, the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS) have released a joint Cybersecurity Advisory (CSA), #StopRansomware: Daixin Team to provide information on the “Daixin Team,” a cybercrime group actively targeting U.S. businesses, predominantly in the Healthcare and Public Health (HPH) Sector, with ransomware and data extortion operations. This joint CSA provides Daixin actors’ tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) obtained from FBI threat response activities and third-party reporting. CISA encourages HPH Sector organizations to review #StopRansomware: Daixin Team and to apply the recommended…

  • AA22-294A: #StopRansomware: Daixin Team

    Original release date: October 21, 2022 Summary Actions to take today to mitigate cyber threats from ransomware: • Install updates for operating systems, software, and firmware as soon as they are released. • Require phishing-resistant MFA for as many services as possible. • Train users to recognize and report phishing attempts. Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations…

  • Cisco Releases Security Update for Cisco Identity Services Engine 

    Original release date: October 21, 2022 Cisco has released a security update to address vulnerabilities affecting Cisco Identity Services Engine (ISE). A remote attacker could exploit some of these vulnerabilities to take control of an affected system. For updates addressing high and low severity vulnerabilities, see the Cisco Security Advisories page.  CISA encourages users and administrators to review Cisco Advisory cisco-sa-ise-path-trav-Dz5dpzyM and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Vulnerability Summary for the Week of October 10, 2022

    Original release date: October 17, 2022 | Last revised: October 18, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adobe — acrobat_reader Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 2022-10-14 7.8 CVE-2022-42339 MISC adobe — acrobat_reader Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by…

  • CISA Releases RedEye: Red Team Campaign Visualization and Reporting Tool

    Original release date: October 14, 2022 CISA has released RedEye, an interactive open-source analytic tool to visualize and report Red Team command and control activities. RedEye allows an operator to quickly assess complex data, evaluate mitigation strategies, and enable effective decision making. For more information, CISA encourages users to review RedEye on GitHub and watch CISA’s RedEye tool overview video. This product is provided subject to this Notification and this Privacy & Use policy.

  • CISA Releases Twenty-Five Industrial Control Systems Advisories

    Original release date: October 13, 2022 CISA has released twenty-five (25) Industrial Control Systems (ICS) advisories on October 13, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: •    ICSA-22-286-01 Siemens LOGO! •    ICSA-22-286-02 Siemens Industrial Edge Management •    ICSA-22-286-03 Siemens Solid Edge •    ICSA-22-286-04 Siemens SIMATIC S7-1200 and S7-1500 CPU Families •    ICSA-22-286-05 Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service •    ICSA-22-286-06 Siemens Desigo PXM Devices Webserver •    ICSA-22-286-07 Siemens Nucleus RTOS FTP…

  • Microsoft Releases October 2022 Security Updates

    Original release date: October 11, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s October 2022 Security Update Summary and Deployment Information and apply the necessary updates.   This product is provided subject to this Notification and this Privacy & Use policy.

  • Vulnerability Summary for the Week of October 3, 2022

    Original release date: October 11, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info actian — psql If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database. 2022-09-30 8.8 CVE-2022-40756 MISC MISC apache — airflow In Apache Airflow, prior to version 2.4.1,…

  • FBI and CISA Publish a PSA on Information Manipulation Tactics for 2022 Midterm Elections

    Original release date: October 7, 2022 Title: FBI and CISA Publish a PSA on Information Manipulation Tactics for 2022 Midterm Elections   Content: The Federal Bureau of Investigation (FBI) and CISA have published a joint public service announcement that: Describes methods that foreign actors use to spread and amplify false information—including reports of alleged malicious cyber activity—in attempts to undermine trust in election infrastructure. Confirms “the FBI and CISA have no information suggesting any cyber activity against U.S. election infrastructure has impacted the accuracy of voter registration information, prevented a registered voter from casting a ballot, or compromised the integrity of any ballots…

  • Top CVEs Actively Exploited by People’s Republic of China State-Sponsored Cyber Actors   

    Original release date: October 6, 2022 CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) providing the top Common Vulnerabilities and Exposures (CVEs) used since 2020 by People’s Republic of China (PRC) state-sponsored cyber actors. PRC state-sponsored cyber actors continue to exploit known vulnerabilities to actively target U.S. and allied networks, including software and hardware companies to illegally obtain intellectual property and develop access into sensitive networks. CISA, the FBI, and the NSA urge U.S. and allied governments, critical infrastructure, and private sector organizations to apply the recommendations listed…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.