CISA Releases IOCs Associated with Malicious Barracuda Activity

CISA Releases IOCs Associated with Malicious Barracuda Activity 08/29/2023 08:00 AM EDT CISA has released additional indicators of compromise (IOCs) associated with exploitation of CVE-2023-2868. CVE-2023-2868 is a remote command injection vulnerability affecting Barracuda Email Security Gateway (ESG) Appliance, versions 5.1.3.001-9.2.0.006. Malicious threat actors exploited this vulnerability as a zero day as early as October …

FBI and CISA Publish a PSA on Malicious Cyber Activity Against Election Infrastructure

FBI and CISA Publish a PSA on Malicious Cyber Activity Against Election Infrastructure 10/05/2022 09:21 AM EDT Original release date: October 5, 2022 The Federal Bureau of Investigation (FBI) and CISA have published a joint public service announcement that: Assesses malicious cyber activity aiming to compromise election infrastructure is unlikely to result in large-scale disruptions or prevent voting. …

CISA and NSA Publish Joint Cybersecurity Advisory on Control System Defense

CISA and NSA Publish Joint Cybersecurity Advisory on Control System Defense 09/22/2022 10:59 AM EDT Original release date: September 22, 2022 CISA and the National Security Agency (NSA) have published a joint cybersecurity advisory about control system defense for operational technology (OT) and industrial control systems (ICSs). Control System Defense: Know the Opponent is intended …

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems 06/23/2022 02:00 PM EDT Original release date: June 23, 2022 CISA and the United States Coast Guard Cyber Command (CGCYBER) have released a joint Cybersecurity Advisory (CSA) to warn network defenders that cyber threat actors, including state-sponsored advanced persistent threat (APT) actors, have continued …

Keeping PowerShell: Measures to Use and Embrace

Keeping PowerShell: Measures to Use and Embrace 06/22/2022 09:00 AM EDT Original release date: June 22, 2022 Cybersecurity authorities from the United States, New Zealand, and the United Kingdom have released a joint Cybersecurity Information Sheet (CIS) on PowerShell. The CIS provides recommendations for proper configuration and monitoring of PowerShell, as opposed to removing or …

CISA Joins Partners to Release Advisory on Protecting MSPs and their Customers

CISA Joins Partners to Release Advisory on Protecting MSPs and their Customers 05/11/2022 07:00 AM EDT Original release date: May 11, 2022 The cybersecurity authorities of the United Kingdom, Australia, Canada, New Zealand, and the United States have released joint Cybersecurity Advisory (CSA), Protecting Against Cyber Threats to Managed Service Providers and their Customers, to …

U.S. Government Attributes Cyberattacks on SATCOM Networks to Russian State-Sponsored Malicious Cyber Actors

U.S. Government Attributes Cyberattacks on SATCOM Networks to Russian State-Sponsored Malicious Cyber Actors 05/10/2022 09:27 AM EDT Original release date: May 10, 2022 CISA and the Federal Bureau of Investigation (FBI) have updated the joint cybersecurity advisory, Strengthening Cybersecurity of SATCOM Network Providers and Customers, originally released March 17, 2022, with U.S. government attribution to …

2021 Top Routinely Exploited Vulnerabilities

2021 Top Routinely Exploited Vulnerabilities 04/27/2022 10:00 AM EDT Original release date: April 27, 2022 CISA, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), and the United Kingdom’s National Cyber …

Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations

Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations 02/24/2022 11:00 AM EST Original release date: February 24, 2022 CISA, the Federal Bureau of Investigation (FBI), U.S. Cyber Command Cyber National Mission Force (CNMF), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the National Security Agency (NSA) have issued a joint Cybersecurity Advisory (CSA) detailing malicious …

Vulnerability Summary for the Week of February 14, 2022

Vulnerability Summary for the Week of February 14, 2022 02/21/2022 09:20 AM EST Original release date: February 21, 2022   High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source & Patch Info accel-ppp — accel-ppp The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a …