Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Next-Gen Maldocs & How to Solve the Human Vulnerability

    Malicious email attachments with macros are one of the most common ways hackers get in through the door. Huntress security researcher John Hammond discusses how threat hunters can fight back.

  • CISA Adds Thirteen Known Exploited Vulnerabilities to Catalog

    Original release date: December 10, 2021 CISA has added thirteen new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise.   CVE Number CVE Title Remediation Due Date CVE-2021-44228 Apache Log4j Remote Code Execution Vulnerability 12/24/2021 CVE-2021-44515 Zoho Corp. Desktop Central Authentication Bypass Vulnerability 12/24/2021 CVE-2021-44168 Fortinet FortiOS Arbitrary File Download 12/24/2021 CVE-2021-35394 Realtek Jungle SDK Remote Code Execution Vulnerability 12/24/2021 CVE-2020-8816…

  • Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack

    The Log4Shell vulnerability critically threatens anybody using the popular open-source Apache Struts framework and could lead to a “Mini internet meltdown soonish.”

  • Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation

    Original release date: December 10, 2021 The Apache Software Foundation has released a security advisory to address a remote code execution vulnerability (CVE-2021-44228) affecting Log4j versions 2.0-beta9 to 2.14.1. A remote attacker could exploit this vulnerability to take control of an affected system. Log4j is an open-source, Java-based logging utility widely used by enterprise applications and cloud services. CISA encourages users and administrators to review the Apache Log4j 2.15.0 Announcement and upgrade to Log4j 2.15.0 or apply the recommended mitigations immediately.   This product is provided subject to this Notification and this Privacy & Use policy.

  • Sprawling Active Attack Aims to Take Over 1.6M WordPress Sites

    Cyberattackers are targeting security vulnerabilities in four plugins plus Epsilon themes, to assign themselves administrative accounts.

  • CISA Releases Security Advisory for Hillrom Welch Allyn Cardiology Products

    Original release date: December 10, 2021 CISA has released an Industrial Controls Systems Medical Advisory (ICSMA) detailing a vulnerability in multiple Hillrom Welch Allyn cardiology products. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages technicians and administrators to review ICSMA-21-343-01: Hillrom Welch Allyn Cardio Products for more information and apply the necessary mitigations. This product is provided subject to this Notification and this Privacy & Use policy.

  • ‘Karakurt’ Extortion Threat Emerges, But Says No to Ransomware

    The threat group, first identified in June, focuses solely on data exfiltration and subsequent extortion, and has already targeted 40 victims since September.

  • Cisco Releases Security Advisory for Multiple Products Affected by Apache HTTP Server Vulnerabilities

    Original release date: December 9, 2021 Cisco has released a security advisory to address Cisco products affected by multiple vulnerabilities in Apache HTTP Server 2.4.48 and earlier releases. An unauthenticated remote attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review Cisco Advisory cisco-sa-apache-httpd-2.4.49-VWL69sWQ and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.

  • How MikroTik Routers Became a Cybercriminal Target

    The powerful devices leveraged by the Meris botnet have weaknesses that make them easy to exploit, yet complex for organizations to track and secure, researchers said.

  • CISA Releases Guidance on Protecting Organization-Run Social Media Accounts

    Original release date: December 9, 2021 CISA has released Capability Enhancement Guide (CEG): Social Media Account Protection, which details ways to protect the security of organization-run social media accounts. Malicious cyber actors that successfully compromise social media accounts—including accounts used by federal agencies—could spread false or sensitive information to a wide audience. The measures described in the CEG aim to reduce the risk of unauthorized access on platforms such as Twitter, Facebook, and Instagram.  CISA encourages social media account administrators to implement the protection measures described in CEG: Social Media Account Protection: Establish and maintain a social media policy Implement…

  • Not with a Bang but a Whisper: The Shift to Stealthy C2

    DoH! Nate Warfield, CTO of Prevailion, discusses new stealth tactics threat actors are using for C2, including Malleable C2 from Cobalt Strike’s arsenal.

  • Moobot Botnet Chews Up Hikvision Surveillance Systems

    Attackers are milking unpatched Hikvision video systems to drop a DDoS botnet, researchers warned.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.