Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • CISA Adds Four Known Exploited Vulnerabilities to Catalog

    Original release date: November 17, 2021 CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, which require remediation from federal civilian executive branch (FCEB) agencies by December 1, 2021. CISA has evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise.  CVE Number CVE Title Remediation Due Date CVE-2021-22204 Exiftool Remote Code Execution vulnerability 12/01/2021 CVE-2021-40449 Microsoft Win32k Elevation of Privilege     12/01/2021 CVE-2021-42292 Microsoft Excel Security Feature Bypass  …

  • Exchange, Fortinet Flaws Being Exploited by Iranian APT, CISA Warns

    Meanwhile, a Microsoft analysis that followed six Iranian threat actor groups for over a year found them increasingly sophisticated, adapting and thriving.

  • AA21-321A: Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities

    Original release date: November 17, 2021 Summary Actions to Take Today to Protect Against Iranian State-Sponsored Malicious Cyber Activity • Immediately patch software affected by the following vulnerabilities: CVE-2021-34473, 2018-13379, 2020-12812, and 2019-5591. • Implement multi-factor authentication. • Use strong, unique passwords. Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 10. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint cybersecurity advisory is the result of an analytic effort among the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre…

  • Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities

    Original release date: November 17, 2021 CISA, the Federal Bureau of Investigation (FBI), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC)  have released a joint Cybersecurity Advisory highlighting ongoing malicious cyber activity by an advanced persistent threat (APT) group that FBI, CISA, ACSC, and NCSC assess is associated with the government of Iran.  FBI and CISA have observed this Iranian government-sponsored APT exploit Fortinet and Microsoft Exchange ProxyShell vulnerabilities to gain initial access to systems in advance of follow-on operations, which include deploying ransomware. Joint Cybersecurity Advisory AA21-321A provides observed tactics and techniques, as well…

  • MosesStaff Locks Up Targets, with No Ransom Demand, No Decryption

    A politically motivated group is paralyzing Israeli entities with no financial goal — and no intention of handing over decryption keys.

  • New Federal Government Cybersecurity Incident and Vulnerability Response Playbooks

    Original release date: November 16, 2021 The White House, via Executive Order (EO) 14028: Improving the Nation’s Cybersecurity, tasked CISA, as the operational lead for federal cybersecurity, to “develop a standard set of operational procedures (i.e., playbook) to be used in planning and conducting cybersecurity vulnerability and incident response activity” for federal civilian agency information systems. In response, today, CISA published the Federal Government Cybersecurity Incident and Vulnerability Response Playbooks. The playbooks provide federal civilian executive branch (FCEB) agencies with operational procedures for planning and conducting cybersecurity incident and vulnerability response activities. The playbooks provide illustrated decision trees and detail…

  • High-Severity Intel Processor Bug Exposes Encryption Keys

    CVE-2021-0146, arising from a debugging functionality with excessive privileges, allows attackers to read encrypted files.

  • Vulnerability Summary for the Week of November 8, 2021

    Original release date: November 15, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info airangel — hsmx-app-25_firmware Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution. 2021-11-10 10 CVE-2021-40521 MISC MISC asgaros — asgaros_forum The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue 2021-11-08 7.5 CVE-2021-24827 CONFIRM MISC azeotech — daqfactory The affected application uses specific functions that could be abused through a crafted project file, which could…

  • Top 10 Cybersecurity Best Practices to Combat Ransomware

    Immutable storage and more: Sonya Duffin, data protection expert at Veritas Technologies, offers the Top 10 steps for building a multi-layer resilience profile.

  • Windows 10 Privilege-Escalation Zero-Day Gets an Unofficial Fix

    Researchers warn that CVE-2021-34484 can be exploited with a patch bypass for a bug originally addressed in August by Microsoft.

  • Mac Zero Day Targets Apple Devices in Hong Kong

    Google researchers have detailed a widespread watering-hole attack that installed a backdoor on Apple devices that visited Hong Kong-based media and pro-democracy sites.

  • VMware Releases Security Update for Tanzu Application Service for VMs

    Original release date: November 12, 2021 VMware has released a security update to address a vulnerability in Tanzu Application Service for VMs. A remote attacker could exploit this vulnerability to cause a denial-of-service condition. CISA encourages users and administrators to review VMware Security Advisory VMSA-2021-0026 and apply the necessary update. This product is provided subject to this Notification and this Privacy & Use policy.

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.