Author: DEFENDEDGE

  • CISA Releases Three Industrial Systems Control Advisories

    Original release date: January 5, 2023 CISA released three Industrial Control Systems (ICS) advisories on January 5 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-23-005-01 Hitachi Energy UNEM ICSA-23-005-02 Hitachi… Read more

  • Fortinet Releases Security Updates for FortiADC

    Original release date: January 4, 2023 Fortinet has released a security advisory to address a vulnerability in multiple versions of FortiADC. This vulnerability may allow a remote attacker “to execute unauthorized code or commands via specifically crafted HTTP requests.” CISA encourages users and administrators to review Fortinet security advisory FG-IR-22-061 and apply the recommended updates. This… Read more

  • Vulnerability Summary for the Week of December 26, 2022

    Original release date: January 4, 2023   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info dlink — dir-846_firmware D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function. 2022-12-23 9.9 CVE-2022-46641 MISC MISC dlink — dir-846_firmware D-Link DIR-846 A1_FW100A43 was… Read more

  • Vulnerability Summary for the Week of December 19, 2022

    Original release date: December 28, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info greenend — sftpserver ** DISPUTED ** A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads… Read more

  • Vulnerability Summary for the Week of December 12, 2022

    Original release date: December 19, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info hp — futuresmart_5 A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products. 2022-12-12… Read more

  • CISA Releases Forty-One Industrial Control Systems Advisories

    Original release date: December 15, 2022 CISA has released forty-one (41) Industrial Control Systems (ICS) advisories on 15 December 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-349-01 Prosys OPC UA… Read more

  • CISA Consolidates Twitter Accounts

    Original release date: December 15, 2022 CISA has consolidated its social media presence on Twitter. Three accounts — @ICSCERT, @Cyber, and @CISAInfraSec — are no longer active. Additionally, the @USCERT_gov Twitter account is now renamed @CISACyber. The following current active Twitter accounts will include posts on content previously covered on the now-inactive accounts. @CISACyber will… Read more

  • Drupal Releases Security Updates to Address Vulnerabilities in H5P and File (Field) Paths

    Original release date: December 15, 2022 Drupal has released security updates to address vulnerabilities affecting H5P and the File (Field) Paths modules for Drupal 7.x. An attacker could exploit these vulnerabilities to access sensitive information and remotely execute code. CISA encourages users and administrators to review Drupal’s security advisories SA-CONTRIB-2022-064 and SA-CONTRIB-2022-065 and apply the necessary update.… Read more

  • Microsoft Releases December 2022 Security Updates

    Original release date: December 13, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s December 2022 Security Update Guide and Deployment Information and apply the necessary updates. This product is provided… Read more

  • CISA Updates Advisory on #StopRansomware: Cuba Ransomware

    Original release date: December 13, 2022 The Federal Bureau of Investigation (FBI) and CISA have updated joint Cybersecurity Advisory AA22-335A: #StopRansomware: Cuba Ransomware, originally released on December 01, 2022. The advisory has been updated to include additional indicators of compromise (IOCs). CISA encourages organizations to review the latest update to AA22-335A and apply the recommended… Read more