Category: alerts

Category Added in a WPeMatico Campaign

  • Open Redirect Flaw Snags Amex, Snapchat User Data

    Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims. Read more

  • AA22-216A: 2021 Top Malware Strains

    Original release date: August 4, 2022 Summary Immediate Actions You Can Take Now to Protect Against Malware: • Patch all systems and prioritize patching known exploited vulnerabilities. • Enforce multifactor authentication (MFA). • Secure Remote Desktop Protocol (RDP) and other risky services. • Make offline backups of your data. • Provide end-user awareness and training… Read more

  • VMWare Urges Users to Patch Critical Authentication Bypass Bug

    Vulnerability—for which a proof-of-concept is forthcoming—is one of a string of flaws the company fixed that could lead to an attack chain. Read more

  • VMware Releases Security Updates

    Original release date: August 3, 2022 VMware has released security updates to address multiple vulnerabilities in VMware’s Workspace ONE Access, Access Connector, Identity Manager, Identity Manager Connector, and vRealize Automation. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.  CISA encourages users and administrators to review VMware Security… Read more

  • Universities Put Email Users at Cyber Risk

    DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails. Read more

  • Vulnerability Summary for the Week of July 25, 2022

    Original release date: August 1, 2022 | Last revised: August 2, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were… Read more

  • Malicious Npm Packages Tapped Again to Target Discord Users

    Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods. Read more

  • CISA Releases Log4Shell-Related MAR

    Original release date: July 28, 2022 From May through June 2022, CISA responded to an organization that was compromised by an exploitation of an unpatched and unmitigated Log4Shell vulnerability in a VMware Horizon server. CISA analyzed five malware samples obtained from the organization’s network and released a Malware Analysis Report of the findings. Users and… Read more

  • Vulnerability Summary for the Week of July 18, 2022

    Original release date: July 26, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info infiray — iray-a8z3_firmware An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand. 2022-07-17 10 CVE-2022-31209 MISC infiray — iray-a8z3_firmware… Read more

  • IoT Botnets Fuels DDoS Attacks – Are You Prepared?

    The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. This is a dangerous warning that the possibility of a sophisticated DDoS attack and a prolonged service outage will prevent businesses from growing. Read more