Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • New Critical RCE Bug Found in Adobe Commerce, Magento

    Adobe updated its recent out-of-band security advisory to add another critical bug, while researchers put out a PoC for the one it emergency-fixed last weekend.

  • CISA Compiles Free Cybersecurity Services and Tools for Network Defenders

    Original release date: February 18, 2022 CISA has compiled and published a list of free cybersecurity services and tools to help organizations reduce cybersecurity risk and strengthen resiliency. This non-exhaustive living repository includes services provided by CISA, widely used open source tools, and free tools and services offered by private and public sector organizations across the cybersecurity community. Before turning to the free offerings, CISA strongly recommends organizations take certain foundational measures to implement a strong cybersecurity program: Fix known security flaws in software. Implement multifactor authentication. Take steps to halt bad practices, including the use of end-of-life software products and systems…

  • Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups

    An oversight in a WordPress plug-in exposes PII and authentication data to malicious insiders.

  • NSA Best Practices for Selecting Cisco Password Types

    Original release date: February 17, 2022 The National Security Agency (NSA) has released a Cybersecurity Information (CSI) sheet with guidance on securing network infrastructure devices and credentials. Cisco devices are used globally to secure network infrastructure devices, including across the Department of Defense, National Security Systems, and the Defense Industrial Base. Credentials within Cisco configuration files could be at risk of compromise if strong password types are not used. The CSI reviews Cisco’s password type options, the difficulty to crack each password type, and its vulnerability severity and provides recommendations for use. CISA encourages administrators to review NSA’s CSI: Cisco…

  • Cisco Releases Security Updates for Email Security Appliance

    Original release date: February 17, 2022 Cisco has released security updates to address a vulnerability affecting Cisco Email Security Appliance. A remote attacker could exploit this vulnerability to cause a denial-of-service condition. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. CISA encourages users and administrators to review Cisco Advisory cisco-sa-esa-dos-MxZvGtgU and apply the necessary updates or workarounds. This product is provided subject to this Notification and this Privacy & Use policy.

  • TrickBot Ravages Customers of Amazon, PayPal and Other Top Brands

    The resurgent trojan has targeted 60 top companies to harvest credentials for a wide range of applications, with an eye to virulent follow-on attacks.

  • High-Severity RCE Bug Found in Popular Apache Cassandra Database

    On the plus side, only instances with non-standard not recommended configurations are vulnerable. On the downside, those configurations aren’t easy to track down, and it’s easy as pie to exploit.

  • AA22-047A: Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology

    Original release date: February 16, 2022 Summary Actions to Help Protect Against Russian State-Sponsored Malicious Cyber Activity: • Enforce multifactor authentication. • Enforce strong, unique passwords. • Enable M365 Unified Audit Logs. • Implement endpoint detection and response tools. From at least January 2020, through February 2022, the Federal Bureau of Investigation (FBI), National Security Agency (NSA), and Cybersecurity and Infrastructure Security Agency (CISA) have observed regular targeting of U.S. cleared defense contractors (CDCs) by Russian state-sponsored cyber actors. The actors have targeted both large and small CDCs and subcontractors with varying levels of cybersecurity protocols and resources. These CDCs…

  • Russian State-Sponsored Actors Target Cleared Defense Contractor Networks

    Original release date: February 16, 2022 CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) highlighting regular targeting of U.S. cleared defense contractors (CDCs) by Russian state-sponsored cyber actors. These CDCs support contracts for the U.S. Department of Defense and Intelligence Community. The CSA provides incident response and remediation recommendations as well as mitigations to reduce the risk of compromise. CISA encourages all critical infrastructure organizations to review the joint CSA: Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology and…

  • Critical VMware Bugs Open ESXi, Fusion & Workstation to Attackers

    A group of five security vulnerabilities could lead to a range of bad outcomes for virtual-machine enthusiasts, including command execution and DoS.

  • CISA Adds Nine Known Exploited Vulnerabilities to Catalog

    Original release date: February 15, 2022 CISA has added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise. CVE Number CVE Title Remediation Due Date CVE-2022-24086 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability 3/1/2022 CVE-2022-0609 Google Chrome Use-After-Free Vulnerability 3/1/2022 CVE-2019-0752 Microsoft Internet Explorer Type Confusion Vulnerability 8/15/2022 CVE-2018-8174 Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability 8/15/2022…

  • SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming

    Researchers have never before seen SquirrelWaffle attackers use typosquatting to keep sending spam once a targeted Exchange server has been patched for ProxyLogon/ProxyShell.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.