Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Attackers Actively Target Windows Installer Zero-Day

    Researcher discovered a “more powerful” variant of an elevation-of-privilege flaw for which Microsoft released a botched patch earlier this month.

  • Attackers Will Flock to Crypto Wallets, Linux in 2022: Podcast

    That’s just the start of what cyberattackers will zero in on as they pick up APT techniques to hurl more destructive ransomware & supply-chain attacks, says Fortinet’s Derek Manky.

  • Attackers Hijack Email Threads Using ProxyLogon/ProxyShell Flaws

    Exploiting Microsoft Exchange ProxyLogon & ProxyShell vulnerabilities, attackers are malspamming replies in existing threads and slipping past malicious-email filters.

  • Imunify360 Bug Leaves Linux Web Servers Open to Code Execution, Takeover

    CloudLinux’ security platform for Linux-based websites and web servers contains a high-severity PHP deserialization bug.

  • Vulnerability Summary for the Week of November 15, 2021

    Original release date: November 22, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adobe — after_effects Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability. 2021-11-18 9.3 CVE-2021-40759 MISC adobe — after_effects Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due…

  • Reminder for Critical Infrastructure to Stay Vigilant Against Threats During Holidays and Weekends

    Original release date: November 22, 2021 As Americans prepare to hit the highways and airports this Thanksgiving holiday, CISA and the Federal Bureau of Investigation (FBI) are reminding critical infrastructure partners that malicious cyber actors aren’t making the same holiday plans as you. Recent history tells us that this could be a time when these persistent cyber actors halfway across the world are looking for ways—big and small—to disrupt the critical networks and systems belonging to organizations, businesses, and critical infrastructure.  There are actions that executives, leaders, and workers in any organization can take proactively to protect themselves against cyberattacks,…

  • Updated: APT Exploitation of ManageEngine ADSelfService Plus Vulnerability

    Original release date: November 19, 2021 The Federal Bureau of Investigation (FBI), CISA, and Coast Guard Cyber Command (CGCYBER) have updated the Joint Cybersecurity Advisory (CSA) published on September 16, 2021, which details the active exploitation of an authentication bypass vulnerability (CVE-2021-40539) in Zoho ManageEngine ADSelfService Plus—a self-service password management and single sign-on solution. The update provides details on a suite of tools APT actors are using to enable this campaign:  Dropper: a dropper trojan that drops Godzilla webshell on a system  Godzilla: a Chinese language web shell  NGLite: a backdoor trojan written in Go  KdcSponge: a tool that targets…

  • NSA and CISA Release Guidance on Securing 5G Cloud Infrastructures

    Original release date: November 19, 2021 CISA has announced the joint National Security Agency (NSA) and CISA publication of the second of a four-part series, Security Guidance for 5G Cloud Infrastructures. Part II: Securely Isolate Network Resources examines threats to 5G container-centric or hybrid container/virtual network, also known as Pods. The guidance provides several aspects of pod security including limiting permissions on deployed containers, avoiding resource contention and denial-of-service attacks, and implementing real-time threat detection. This series is being published under the Enduring Security Framework (ESF), a public-private cross-sector working group led by NSA and CISA. CISA encourages 5G providers,…

  • 6M Sky Routers Left Exposed to Attack for Nearly 1.5 Years

    Pen Test Partners didn’t disclose the vulnerability after 90 days because it knew ISPs were struggling with a pandemic-increased network load as work from home became the new norm.

  • FBI: FatPipe VPN Zero-Day Exploited by APT for 6 Months

    The bureau’s flash alert said an APT has been exploiting the flaw to compromise FatPipe router clustering and load balancer products to breach targets’ networks.

  • NCSC Releases 2021 Annual Review

    Original release date: November 18, 2021 The United Kingdom (UK) National Cyber Security Centre (NCSC) has released its Annual Review 2021, which focuses on its response to evolving and challenging cyber threats. The publication contains highlights of NCSC’s collaboration with trusted cybersecurity partners, including CISA. Examples include: Joint Cybersecurity Advisory: Top Routinely Exploited Vulnerabilities Joint Cybersecurity Advisory NSA-CISA-NCSC-FBI Joint Cybersecurity Advisory on Russian GRU Brute Force Campaign Joint Cybersecurity Advisory: Further TTPs Associated with SVR Cyber Actors Joint Cybersecurity Advisory: Technical Approaches to Uncovering and Remediating Malicious Activity CISA encourages users to review NCSC’s Annual Review 2021 and learn more…

  • Decoding the Data Ocean: Security Threat Context & Natural Language Processing

    REGISTER TODAY! Join security researchers Erick Galinkin of Rapid7 and Izzy Lazerson of IntSights, as they discuss how non-experts can supercharge threat intelligence efforts in ways that were never before possible, with natural language processing.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.