Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Cisco Releases Security Updates for RV Series Routers

    Original release date: February 3, 2022 Cisco has released security updates to address vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. CISA encourages users and administrators to review Cisco advisory cisco-sa-smb-mult-vuln-KA9PK6D and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • Supply-Chain Security Is Not a Problem…It’s a Predicament

    Despite what security vendors might say, there is no way to comprehensively solve our supply-chain security challenges, posits JupiterOne CISO Sounil Yu. We can only manage them.

  • KP Snacks Left with Crumbs After Ransomware Attack

    The Conti gang strikes again, disrupting the nom-merchant’s supply chain and threatening empty supermarket shelves lasting for weeks.

  • Thousands of Malicious npm Packages Threaten Web Apps

    Attackers increasingly are using malicious JavaScript packages to steal data, engage in cryptojacking and unleash botnets, offering a wide supply-chain attack surface for threat actors.

  • Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft

    Rising critical unpatched vulnerabilities and a lack of encryption leave medical device data defenseless, researcher warn.

  • Samba ‘Fruit’ Bug Allows RCE, Full Root User Access

    The issue in the file-sharing and interop platform also affects Red Hat, SUSE Linux and Ubuntu packages.

  • Public Exploit Released for Windows 10 Bug

    The vulnerability affects all unpatched Windows 10 versions following a messy Microsoft January update.

  • FBI Releases PIN on Potential Cyber Activities During the 2022 Beijing Winter Olympics and Paralympics

    Original release date: February 1, 2022 The Federal Bureau of Investigation (FBI) has released a Private Industry Notification (PIN) to warn entities associated with the February 2022 Beijing Winter Olympics and March 2022 Paralympics that malicious cyber actors could use a broad range of cyber activities to disrupt these events. These activities include distributed denial-of-service attacks, ransomware, malware, social engineering, data theft or leaks, phishing campaigns, disinformation campaigns, and insider threats. Additionally, the FBI PIN warns Olympic participants and travelers of potential threats associated with mobile applications developed by untrusted vendors. The FBI urges all athletes to keep their personal…

  • Vulnerability Summary for the Week of January 24, 2022

    Original release date: January 31, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info apache — shenyu Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. 2022-01-25 7.5 CVE-2021-45029 CONFIRM MLIST MLIST asus — vc65-c1_firmware ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service. 2022-01-21 7.2 CVE-2022-21933 CONFIRM budget_and_expense_tracker_system_project — budget_and_expense_tracker_system SQL injection vulnerability…

  • Apple Pays $100.5K Bug Bounty for Mac Webcam Hack

    The researcher found that he could gain unauthorized camera access via a shared iCloud document that could also “hack every website you’ve ever visited.”

  • CISA Adds Eight Known Exploited Vulnerabilities to Catalog

    Original release date: January 28, 2022 CISA has added eight new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise. CVE Number CVE Title Required Action Due Date CVE-2022-22587 Apple IOMobileFrameBuffer Memory Corruption Vulnerability 2/11/2022 CVE-2021-20038 SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability 2/11/2022 CVE-2014-7169 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability 7/28/2022 CVE-2014-6271 GNU Bourne-Again Shell (Bash) Arbitrary Code…

  • Zerodium Spikes Payout for Zero-Click Outlook Zero-Days

    The sweetened deal came on the same day that Trustwave SpiderLabs published a new way to bypass Outlook security to deliver malicious links to victims.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.