AA20-031A: Detecting Citrix CVE-2019-19781

Unknown cyber network exploitation (CNE) actors have successfully compromised numerous organizations that employed vulnerable Citrix devices through a critical vulnerability known as CVE-2019-19781.[1] Though mitigations were released on the same…

Comments Off on AA20-031A: Detecting Citrix CVE-2019-19781

AA20-014A: Critical Vulnerabilities in Microsoft Windows Operating Systems

New vulnerabilities are continually emerging, but the best defense against attackers exploiting patched vulnerabilities is simple: keep software up to date. Timely patching is one of the most efficient and…

Comments Off on AA20-014A: Critical Vulnerabilities in Microsoft Windows Operating Systems

AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability

Unpatched Pulse Secure VPN servers continue to be an attractive target for malicious actors. Affected organizations that have not applied the software patch to fix a remote code execution (RCE)…

Comments Off on AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability

AA19-339A: Dridex Malware

This Alert is the result of recent collaboration between Department of the Treasury Financial Sector Cyber Information Group (CIG) and the Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN)…

Comments Off on AA19-339A: Dridex Malware

AA19-168A: Microsoft Operating Systems BlueKeep Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this Activity Alert to provide information on a vulnerability, known as “BlueKeep,” that exists in the following Microsoft Windows Operating Systems…

Comments Off on AA19-168A: Microsoft Operating Systems BlueKeep Vulnerability

AA19-122A: New Exploits for Unsecure SAP Systems

The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this activity alert in response to recently disclosed exploits that target unsecure configurations of SAP components. [1] A presentation at the…

Comments Off on AA19-122A: New Exploits for Unsecure SAP Systems

AA19-024A: DNS Infrastructure Hijacking Campaign

The National Cybersecurity and Communications Integration Center (NCCIC), part of the Cybersecurity and Infrastructure Security Agency (CISA), is aware of a global Domain Name System (DNS) infrastructure hijacking campaign. Using…

Comments Off on AA19-024A: DNS Infrastructure Hijacking Campaign