Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Microsoft Releases February 2022 Security Updates

    Original release date: February 8, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s February 2022 Security Update Summary and Deployment Information and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Vulnerability Summary for the Week of January 31, 2022

    Original release date: February 7, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info advantech — deviceon/iedge A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability. 2022-01-28 9.3 CVE-2021-40389 MISC advantech — deviceon/iservice A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An…

  • CISA Orders Federal Agencies to Fix Actively Exploited Windows Bug

    Feb. 18 is the deadline to patch a bug that affects all unpatched versions of Windows 10 and requires zero user interaction to exploit.

  • LockBit, BlackCat, Swissport, Oh My! Ransomware Activity Stays Strong

    However, groups are rebranding and recalibrating their profiles and tactics to respond to law enforcement and the security community’s focus on stopping ransomware attacks.

  • QuaDream, 2nd Israeli Spyware Firm, Weaponizes iPhone Bug

    The now-patched flaw that led to the ForcedEntry exploit of iPhones was exploited by both NSO Group and a different, newly detailed surveillance vendor.

  • FBI Releases Indicators of Compromise Associated with LockBit 2.0 Ransomware

    Original release date: February 7, 2022 The Federal Bureau of Investigation (FBI) has released a Flash report detailing indicators of compromise (IOCs) associated with attacks, using LockBit 2.0, a Ransomware-as-a-Service that employs a wide variety of tactics, techniques, and procedures, creating significant challenges for defense and mitigation. CISA encourages users and administrators to review the IOCs and technical details in FBI Flash CU-000162-MW and apply the recommend mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

  • ‘Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet

    The ubiquitous Log4j bug will be with us for years. John Hammond, senior security researcher at Huntress, discusses what’s next.

  • Argo CD Security Bug Opens Kubernetes Cloud Apps to Attackers

    The popular continuous-delivery platform has a path-traversal bug (CVE-2022-24348) that could allow cyberattackers to hop from one application ecosystem to another.

  • CISA Adds One Known Exploited Vulnerability to Catalog

    Original release date: February 4, 2022 CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise. CVE Number CVE Title Required Action Due Date CVE-2022-21882 Microsoft Win32k Privilege Escalation Vulnerability 02/18/2022   Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known CVEs that…

  • Critical Cisco Bugs Open VPN Routers to Cyberattacks

    The company’s RV line of small-business routers contains 15 different security vulnerabilities that could enable everything from RCE to corporate network access and denial-of-service – and many have exploits circulating.

  • Wormhole Crypto Platform: ‘Funds Are Safe’ After $314M Heist

    The popular bridge, which connects Ethereum, Solana blockchain & more, was shelled out by it’s-not-saying. Wormhole is trying to negotiate with the attacker.

  • CISA Releases Security Advisory for Airspan Networks Mimosa

    Original release date: February 3, 2022 CISA has released an Industrial Controls Systems Advisory (ICSA) that details vulnerabilities in the Airspan Networks Mimosa product line. An attacker could exploit these vulnerabilities to achieve remote code execution, create a denial-of-service condition, or obtain sensitive information. CISA encourages users and administrators to review ICSA-22-034-02: Airspan Networks Mimosa for more information and apply the necessary mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.