Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Cisco Releases Security Updates for Enterprise NFV Infrastructure Software

    Original release date: May 5, 2022 Cisco has released security updates to address multiple vulnerabilities in Enterprise NFV Infrastructure Software. An attacker could exploit these vulnerabilities to take control of an affected system.   CISA encourages users and administrators to review Cisco advisory cisco-sa-NFVIS-MUL-7DySRX9 and apply the necessary updates. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page.  This product is provided subject to this Notification and this Privacy & Use policy.

  • F5 Warns of Critical Bug Allowing Remote Code Execution in BIG-IP Systems

    The vulnerability is ‘critical’ with a CVSS severity rating of 9.8 out of 10.

  • F5 Releases Security Advisories Addressing Multiple Vulnerabilities

    Original release date: May 4, 2022 F5 has released security advisories on vulnerabilities affecting multiple products, including various versions of BIG-IP. Included in the release is an advisory for CVE-2022-1388, which allows undisclosed requests to bypass the iControl REST authentication in BIG-IP. An attacker could exploit CVE-2022-1388 to take control of an affected system. CISA encourages users and administrators to review the F5 webpage, Overview of F5 vulnerabilities (May 2022), and apply the necessary updates or workarounds. This product is provided subject to this Notification and this Privacy & Use policy.

  • Unpatched DNS Bug Puts Millions of Routers, IoT Devices at Risk

    A flaw in all versions of the popular C standard libraries uClibe and uClibe-ng can allow for DNS poisoning attacks against target devices.

  • Vulnerability Summary for the Week of April 25, 2022

    Original release date: May 2, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info jfinalcms_project — jfinalcms JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. 2022-04-22 7.5 CVE-2022-27341 MISC link-admin_project — link-admin Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult(). 2022-04-22 7.5 CVE-2022-27342 MISC Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info ibm — cognos_analytics IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an…

  • Deep Dive: Protecting Against Container Threats in the Cloud

    A deep dive into securing containerized environments and understanding how they present unique security challenges.

  • Security Turbulence in the Cloud: Survey Says…

    Exclusive Threatpost research examines organizations’ top cloud security concerns, attitudes towards zero-trust and DevSecOps.

  • CISA and FBI Update Advisory on Destructive Malware Targeting Organizations in Ukraine

    Original release date: April 28, 2022 CISA and the Federal Bureau of Investigation (FBI) have updated joint Cybersecurity Advisory AA22-057A: Destructive Malware Targeting Organizations in Ukraine, originally released February 26, 2022. The advisory has been updated to include additional indicators of compromise for WhisperGate and technical details for HermeticWiper, IsaacWiper, HermeticWizard, and CaddyWiper destructive malware. CISA and the FBI encourage organizations to review the update to AA22-057A as well as the Shields Up Technical Guidance webpage for ways to identify, respond to, and mitigate disruptive cyber activity.  This product is provided subject to this Notification and this Privacy & Use policy.

  • Attacker Breach ‘Dozens’ of GitHub Repos Using Stolen OAuth Tokens

    GitHub shared the timeline of breaches in April 2022, this timeline encompasses the information related to when a threat actor gained access and stole private repositories belonging to dozens of organizations.

  • Emotet is Back From ‘Spring Break’ With New Nasty Tricks

    The Botnet appears to use a new delivery method for compromising Windows systems after Microsoft disables VBA macros by default.

  • 2021 Top Routinely Exploited Vulnerabilities

    Original release date: April 27, 2022 CISA, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), and the United Kingdom’s National Cyber Security Centre (NCSC-UK)  have released a joint Cybersecurity Advisory that provides details on the top 15 Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors in 2021, as well as other CVEs frequently exploited. CISA encourages users and administrators to review joint Cybersecurity Advisory: 2021 Top Routinely Exploited Vulnerabilities  and apply the recommended…

  • AA22-117A: 2021 Top Routinely Exploited Vulnerabilities

    Original release date: April 27, 2022 Summary This joint Cybersecurity Advisory (CSA) was coauthored by cybersecurity authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom: the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), New Zealand National Cyber Security Centre (NZ NCSC), and United Kingdom’s National Cyber Security Centre (NCSC-UK). This advisory provides details on the top 15 Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors in 2021, as well as other CVEs frequently exploited.…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.