Category: alerts

Category Added in a WPeMatico Campaign

  • AA21-265A: Conti Ransomware

    Original release date: September 22, 2021 Summary Immediate Actions You Can Take Now to Protect Against Conti Ransomware • Use multi-factor authentication. • Segment and segregate networks and functions. • Update your operating system and software. Note: This Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 9. See the ATT&CK Read more

  • CISA, FBI, and NSA Release Joint Cybersecurity Advisory on Conti Ransomware 

    Original release date: September 22, 2021 CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) alerting organizations of increased Conti ransomware attacks. Malicious cyber actors use Conti ransomware to steal sensitive files from domestic and international organizations, encrypt the targeted organizations’ servers and workstations, Read more

  • TikTok, GitHub, Facebook Join Open-Source Bug Bounty

    The initiative, run by HackerOne, aims to uncover dangerous code repository bugs that end up going viral across the application supply-chain. Read more

  • NETGEAR Releases Security Updates for RCE Vulnerability

    Original release date: September 21, 2021 NETGEAR has released security updates to address a remote code execution vulnerability—CVE-2021-40847—in multiple NETGEAR routers. A remote attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review NETGEAR’s Security Advisory and update to the latest firmware. Given the increase in telework, Read more

  • Payment API Bungling Exposes Millions of Users’ Payment Data

    Misconfigured APIs make any app risky, but when you’re talking about financial apps, you’re talking about handing ne’er-do-wells the power to turn your pockets inside-out. Read more

  • Vulnerability Summary for the Week of September 13, 2021

    Original release date: September 20, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info zohocorp — manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. 2021-09-10 7.5 CVE-2021-37422 MISC zohocorp — manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 6111 and prior is Read more

  • Porn Problem: Adult Ads Persist on US Gov’t, Military Sites

    Cities, states, federal and military agencies should patch the Laserfiche CMS post-haste, said the security researcher whose jaw dropped at 50 sites hosting porn and Viagra spam. Read more

  • Microsoft MSHTML Flaw Exploited by Ryuk Ransomware Gang

    Microsoft and RiskIQ researchers have identified several campaigns using the recently patched zero-day, reiterating a call for organizations to update affected systems. Read more

  • CISA, FBI: State-Backed APTs May Be Exploiting Critical Zoho Bug

    The newly identified bug in a Zoho single sign-on and password management tool has been under active attack since early August. Read more

  • ACSC Releases Annual Cyber Threat Report

    Original release date: September 16, 2021 The Australian Cyber Security Centre (ACSC) has released its annual report on key cyber security threats and trends for the 2020–21 financial year.     The report lists the exploitation of the pandemic environment, the disruption of essential services and critical infrastructure, ransomware, the rapid exploitation of security vulnerabilities, Read more