AA20-099A: COVID-19 Exploited by Malicious Cyber Actors

This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). This…

Comments Off on AA20-099A: COVID-19 Exploited by Malicious Cyber Actors

AA20-073A: Enterprise VPN Security

As organizations prepare for possible impacts of Coronavirus Disease 2019 (COVID-19), many may consider alternate workplace options for their employees. Remote work options—or telework—require an enterprise virtual private network (VPN)…

Comments Off on AA20-073A: Enterprise VPN Security

AA20-049A: Ransomware Impacting Pipeline Operations

Note: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) framework. See the MITRE ATT&CK for Enterprise and ATT&CK for Industrial Control Systems (ICS) frameworks for…

Comments Off on AA20-049A: Ransomware Impacting Pipeline Operations

AA20-031A: Detecting Citrix CVE-2019-19781

Unknown cyber network exploitation (CNE) actors have successfully compromised numerous organizations that employed vulnerable Citrix devices through a critical vulnerability known as CVE-2019-19781.[1] Though mitigations were released on the same…

Comments Off on AA20-031A: Detecting Citrix CVE-2019-19781

AA20-014A: Critical Vulnerabilities in Microsoft Windows Operating Systems

New vulnerabilities are continually emerging, but the best defense against attackers exploiting patched vulnerabilities is simple: keep software up to date. Timely patching is one of the most efficient and…

Comments Off on AA20-014A: Critical Vulnerabilities in Microsoft Windows Operating Systems

AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability

Unpatched Pulse Secure VPN servers continue to be an attractive target for malicious actors. Affected organizations that have not applied the software patch to fix a remote code execution (RCE)…

Comments Off on AA20-010A: Continued Exploitation of Pulse Secure VPN Vulnerability

AA19-339A: Dridex Malware

This Alert is the result of recent collaboration between Department of the Treasury Financial Sector Cyber Information Group (CIG) and the Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN)…

Comments Off on AA19-339A: Dridex Malware