Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Two Active Directory Bugs Lead to Easy Windows Domain Takeover

    Microsoft is urging customers to patch two Active Directory domain controller bugs after a PoC tool was publicly released on Dec. 12.

  • FBI: Another Zoho ManageEngine Zero-Day Under Active Attack

    APT attackers are using a security vulnerability in ManageEngine Desktop Central to take over servers, deliver malware and establish network persistence.

  • Vulnerability Summary for the Week of December 13, 2021

    Original release date: December 21, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info abb — omnicore_c30_firmware A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port. 2021-12-13 9.3 CVE-2021-22279 MISC amazon — aws_opensearch The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. 2021-12-12 7.5 CVE-2021-44833 MISC MISC amd — amd_generic_encapsulated_software_architecture Improper handling of pointers in the System Management Mode (SMM) handling code…

  • Conti Ransomware Gang Has Full Log4Shell Attack Chain

    Conti has become the first professional-grade, sophisticated ransomware group to weaponize Log4j2, now with a full attack chain.

  • Third Log4J Bug Can Trigger DoS; Apache Issues Patch

    The new Log4j vulnerability is similar to Log4Shell in that it also affects the logging library, but this DoS flaw has to do with Context Map lookups, not JNDI.

  • Facebook Bans Spy-for-Hire Firms for Targeting 50K People

    Meta, Facebook’s parent company, said that the seven banned actors run fake accounts on its platforms to deceive users and plant malware on targets’ phones.

  • Brand-New Log4Shell Attack Vector Threatens Local Hosts

    The discovery, which affects services running as localhost that aren’t exposed to any network or the internet, vastly widens the scope of attack possibilities.

  • CISA Issues ED 22-02 Directing Federal Agencies to Mitigate Apache Log4j Vulnerabilities

    Original release date: December 17, 2021 CISA has issued Emergency Directive (ED) 22-02: Mitigate Apache Log4j Vulnerability], directing federal civilian executive branch (FCEB) agencies to address Log4j vulnerabilities—most notably, CVE-2021-44228. Although ED 22-02 applies to FCEB agencies, CISA strongly recommends that all organizations review ED 22-02 for mitigation guidance. For additional details, see CISA’s webpage Apache Log4j Vulnerability Guidance.   This product is provided subject to this Notification and this Privacy & Use policy.

  • NSA and CISA Release Final Part IV of Guidance on Securing 5G Cloud Infrastructures

    Original release date: December 16, 2021 CISA has announced the joint National Security Agency (NSA) and CISA publication of the final of a four-part series, Security Guidance for 5G Cloud Infrastructures. Part IV: Ensure Integrity of Cloud Infrastructure focuses on platform integrity, microservices infrastructure integrity, launch time integrity, and build time security to ensure that 5G cloud resources are not modified without authorization. This series was published under the Enduring Security Framework (ESF), a public-private cross-sector working group led by NSA and CISA. CISA encourages 5G providers, integrators, and network operators to review the guidance and consider the recommendations. See CISA’s 5G…

  • Relentless Log4j Attacks Include State Actors, Possible Worm

    More than 1.8 million attacks, against half of all corporate networks, have already launched to exploit Log4Shell.

  • CISA Adds Two Known Exploited Vulnerabilities to Catalog

    Original release date: December 15, 2021 CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise.   CVE Number CVE Title  Remediation Due Date CVE-2021-43890 Microsoft Windows AppX Installer Spoofing Vulnerability 12/29/2021 CVE-2021-4102 Google Chromium V8 Engine Use-After-Free Vulnerability 12/29/2021   Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities…

  • SAP Kicks Log4Shell Vulnerability Out of 20 Apps

    SAP’s still feverishly working to patch another 12 apps vulnerable to the Log4Shell flaw, while its Patch Tuesday release includes 21 other fixes, some rated at 9.9 criticality.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.