AA20-107A: Continued Threat Actor Exploitation Post Pulse Secure VPN Patching

Note: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor techniques and mitigations. This…

Comments Off on AA20-107A: Continued Threat Actor Exploitation Post Pulse Secure VPN Patching

Oracle Releases April 2020 Security Bulletin

Oracle has released its Critical Patch Update for April 2020 to address 397 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of…

Comments Off on Oracle Releases April 2020 Security Bulletin

AA20-106A: Guidance on the North Korean Cyber Threat

The U.S. Departments of State, the Treasury, and Homeland Security, and the Federal Bureau of Investigation are issuing this advisory as a comprehensive resource on the North Korean cyber threat…

Comments Off on AA20-106A: Guidance on the North Korean Cyber Threat

VMware Releases Security Updates for vRealize Log Insight

VMware has released security updates to address vulnerabilities in VMware vRealize Log Insight. An attacker could exploit these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure…

Comments Off on VMware Releases Security Updates for vRealize Log Insight

Microsoft Releases April 2020 Security Updates

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and…

Comments Off on Microsoft Releases April 2020 Security Updates

Vulnerability Summary for the Week of April 6, 2020

Original release date: April 13, 2020The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet…

Comments Off on Vulnerability Summary for the Week of April 6, 2020

Mozilla Releases Security Updates for Firefox, Firefox ESR

Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity…

Comments Off on Mozilla Releases Security Updates for Firefox, Firefox ESR

Google Releases Security Updates

Google has released Chrome version 81.0.4044.92 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. The Cybersecurity and…

Comments Off on Google Releases Security Updates

AA20-099A: COVID-19 Exploited by Malicious Cyber Actors

This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). This…

Comments Off on AA20-099A: COVID-19 Exploited by Malicious Cyber Actors