Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Will 2022 Be the Year of the Software Bill of Materials?

    Praise be & pass the recipe for the software soup: There’s too much scrambling to untangle vulnerabilities and dependencies, say a security experts roundtable.

  • CISA Adds 13 Known Exploited Vulnerabilities to Catalog

    Original release date: January 18, 2022 CISA has added 13 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise. CVE Number CVE Title Required Action Due Date CVE-2021-32648 October CMS Improper Authentication 2/1/2022 CVE-2021-21315 System Information Library for node.js Command Injection Vulnerability 2/1/2022 CVE-2021-21975 Server Side Request Forgery in vRealize Operations Manager API Vulnerability 2/1/2022 CVE-2021-22991 BIG-IP Traffic Microkernel Buffer Overflow…

  • Critical ManageEngine Desktop Server Bug Opens Orgs to Malware

    Zoho’s comprehensive endpoint-management platform suffers from an authentication-bypass bug (CVE-2021-44757) that could lead to remote code execution.

  • Organizations Face a ‘Losing Battle’ Against Vulnerabilities

    Companies must take more ‘innovative and proactive’ approaches to security in 2022 to combat threats that emerged last year, researchers said.

  • Vulnerability Summary for the Week of January 10, 2022

    Original release date: January 17, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info agoric — realms-shim All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. 2022-01-10 7.5 CVE-2021-23543 MISC MISC agoric — realms-shim All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. 2022-01-10 7.5 CVE-2021-23594 MISC MISC checkpoint — endpoint_security Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation…

  • Microsoft Warns of Destructive Malware Targeting Ukrainian Organizations

    Original release date: January 16, 2022 Microsoft has released a blog post on possible Master Boot Record (MBR) Wiper activity targeting Ukrainian organizations, including Ukrainian government agencies. According to Microsoft, powering down the victim device executes the malware, which overwrites the MBR with a ransom note; however, the ransom note is a ruse because the malware actually destroys the MBR and the targeted files.   CISA recommends network defenders review the Microsoft blog for tactics, techniques, and procedures, as well as indicators of compromise related to this activity. CISA additionally recommends network defenders review recent Cybersecurity Advisories and the CISA…

  • Real Big Phish: Mobile Phishing & Managing User Fallibility

    Phishing is more successful than ever. Daniel Spicer, CSO of Ivanti, discusses emerging trends in phishing, and using zero-trust security to patch the human vulnerabilities underpinning the spike.

  • Critical Cisco Contact Center Bug Threatens Customer-Service Havoc

    Attackers could access and modify agent resources, telephone queues and other customer-service systems – and access personal information on companies’ customers.

  • Ivanti Updates Log4j Advisory with Security Updates for Multiple Products  

    Original release date: January 14, 2022 Ivanti has updated its Log4j Advisory with security updates for multiple products to address CVE-2021-44228. An unauthenticated attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review the Ivanti security advisories pages for Avalanche; File Director; and MobileIron Core, MobileIron Sentry (Core/Cloud), and MobileIron Core Connector and apply the necessary updates and workarounds. This product is provided subject to this Notification and this Privacy & Use policy.

  • Three Plugins with Same Bug Put 84K WordPress Sites at Risk

    Researchers discovered vulnerabilities that can allow for full site takeover in login and e-commerce add-ons for the popular website-building platform.

  • Microsoft Yanks Buggy Windows Server Updates

    Since their release on Patch Tuesday, the updates have been breaking Windows, causing spontaneous boot loops on Windows domain controller servers, breaking Hyper-V and making ReFS volume systems unavailable.

  • US Military Ties Prolific MuddyWater Cyberespionage APT to Iran

    US Cyber Command linked the group to Iranian intelligence and detailed its multi-pronged, increasingly sophisticated suite of malware tools.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.