Category: alerts

Category Added in a WPeMatico Campaign

  • Vulnerability Summary for the Week of August 23, 2021

    Original release date: August 30, 2021   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info adobe — bridge Adobe Bridge version 11.0.2 (and earlier) are affected by a Heap-based Buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the… Read more

  • CISA Adds Single-Factor Authentication to list of Bad Practices

    Original release date: August 30, 2021 Today, CISA added the use of single-factor authentication for remote or administrative access systems to our Bad Practices list of exceptionally risky cybersecurity practices. Single-factor authentication is a common low-security method of authentication. It only requires matching one factor—such as a password—to a username to gain access to a system.… Read more

  • Microsoft Azure Cosmos DB Guidance

    Original release date: August 27, 2021 CISA is aware of a misconfiguration vulnerability in Microsoft’s Azure Cosmos DB that may have exposed customer data. Although the misconfiguration appears to have been fixed within the Azure cloud, CISA strongly encourages Azure Cosmos DB customers to roll and regenerate their certificate keys and to review Microsoft’s guidance… Read more

  • Winning the Cyber-Defense Race: Understand the Finish Line

    Kerry Matre, Mandiant senior director, clears up misconceptions about the value to business for enterprise cyber-defense. Hint: It’s not achieving visibility. Read more

  • Parallels Offers ‘Inconvenient’ Fix for High-Severity Bug

    Firm offers guidance on how to mitigate a five-months-old privilege escalation bug impacting Parallels Desktop 16 for Mac and all previous versions. Read more

  • Critical Azure Cosmos DB Bug Allows Full Cloud Account Takeover

    It’s unclear if Microsoft customers were breached during the months-long period where the #ChaosDB bug in Jupyter Notebooks was exploitable. Read more

  • FBI Releases Indicators of Compromise Associated with Hive Ransomware

    Original release date: August 27, 2021 The Federal Bureau of Investigation (FBI) has released a Flash report detailing indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with ransomware attacks by Hive, a likely Ransomware-as-a-Service organization consisting of a number of actors using multiple mechanisms to compromise business networks, exfiltrate data and encrypt… Read more

  •  ICSJWG 2021 Fall Virtual Meeting

    Original release date: August 27, 2021 The Industrial Control Systems Joint Working Group (ICSJWG) will hold the virtual 2021 ICSJWG Fall Meeting, September 21—22, 2021. ICSJWG meetings facilitate relationship building among critical infrastructure stakeholders and owners/operators of industrial control systems, idea exchange regarding critical issues affecting industrial control systems (ICS) cybersecurity, and information sharing to… Read more

  • ‘Pay Ransom’ Screen? Too Late, Humpty Dumpty – Podcast

    Splunk’s Ryan Kovar discusses the rise in supply-chain attacks a la Kaseya & how to get ahead of encryption leaving your business a pile of broken shells.  Read more

  • F5 Bug Could Lead to Complete System Takeover

    The worst of 13 bugs fixed by the August updates could lead to complete system compromise for users in sensitive sectors running products in Appliance mode. Read more