AA21-287A: Ongoing Cyber Threats to U.S. Water and Wastewater Systems

Original release date: October 14, 2021SummaryImmediate Actions WWS Facilities Can Take Now to Protect Against Malicious Cyber Activity • Do not click on suspicious links.• If you use RDP, secure…

Comments Off on AA21-287A: Ongoing Cyber Threats to U.S. Water and Wastewater Systems

Microsoft Releases October 2021 Security Updates

Original release date: October 12, 2021Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected…

Comments Off on Microsoft Releases October 2021 Security Updates

Vulnerability Summary for the Week of October 4, 2021

Original release date: October 11, 2021  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info archibus -- web_central ** UNSUPPORTED WHEN ASSIGNED ** In ARCHIBUS…

Comments Off on Vulnerability Summary for the Week of October 4, 2021

Be Cyber Smart During Cybersecurity Awareness Month

Original release date: October 5, 2021CISA and the National Cybersecurity Alliance (NCSA) remind users to continue to “Do Your Part. #BeCyberSmart.” during October—2021’s Cybersecurity Awareness Month!   In 2021, CISA…

Comments Off on Be Cyber Smart During Cybersecurity Awareness Month

Vulnerability Summary for the Week of September 27, 2021

Original release date: October 4, 2021  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info adobe -- digital_editions Adobe Digital Editions 4.5.11.187646 (and earlier) are…

Comments Off on Vulnerability Summary for the Week of September 27, 2021

CISA and NSA Release Guidance on Selecting and Hardening VPNs

Original release date: September 28, 2021The National Security Agency (NSA) and CISA have released the cybersecurity information sheet Selecting and Hardening Standards-based Remote Access VPN Solutions to address the potential security…

Comments Off on CISA and NSA Release Guidance on Selecting and Hardening VPNs

RCE Vulnerability in Hikvision Cameras (CVE-2021-36260)

Original release date: September 28, 2021Hikvision has released updates to mitigate a command injection vulnerability—CVE-2021-36260—in Hikvision cameras that use a web server service. A remote attacker could exploit this vulnerability…

Comments Off on RCE Vulnerability in Hikvision Cameras (CVE-2021-36260)