Summary of Security Items from June 15 through June 21, 2005

Information in the US-CERT Cyber Security Bulletin is a compilation and includes information published by outside sources, so the information should not be considered the result of US-CERT analysis. Software…

Comments Off on Summary of Security Items from June 15 through June 21, 2005

Mozilla Releases Security Update for Thunderbird 102.9.1

Mozilla has released a security update to address vulnerabilities in Thunderbird 102.9.1. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users…

Comments Off on Mozilla Releases Security Update for Thunderbird 102.9.1

CISA Adds Ten Known Exploited Vulnerabilities to Catalog

CISA has added ten new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2013-3163 Microsoft Internet Explorer Memory Corruption Vulnerability CVE-2014-1776 Microsoft Internet Explorer Memory Corruption Vulnerability CVE-2017-7494 Samba…

Comments Off on CISA Adds Ten Known Exploited Vulnerabilities to Catalog

JCDC Cultivates Pre-Ransomware Notification Capability

In today’s blog post, Associate Director of the Joint Cyber Defense Collaborative (JCDC) Clayton Romans highlighted recent successes of pre-ransomware notification and its impact in reducing harm from ransomware intrusions. With…

Comments Off on JCDC Cultivates Pre-Ransomware Notification Capability

Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments

Today, CISA released the Untitled Goose Tool to help network defenders detect potentially malicious activity in Microsoft Azure, Azure Active Directory (AAD), and Microsoft 365 (M365) environments. The Untitled Goose…

Comments Off on Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments

Vulnerability Summary for the Week of June 6, 2016

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info ansibleworks -- ansible The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before…

Comments Off on Vulnerability Summary for the Week of June 6, 2016

Vulnerability Summary for the Week of January 31, 2011

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info automatedsolutions -- modbus/tcp_master_opc_server Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote…

Comments Off on Vulnerability Summary for the Week of January 31, 2011

Vulnerability Summary for the Week of October 17, 2011

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info apple -- iphone_os The Settings component in Apple iOS before 5, when a configuration profile is used…

Comments Off on Vulnerability Summary for the Week of October 17, 2011