Microsoft Releases Security Updates for Multiple Products

Microsoft has released security updates to address multiple vulnerabilities in products that use the Autodesk FBX library. These include Office 2016, Office 2019, Office 365 ProPlus, and Paint 3D. A…

Comments Off on Microsoft Releases Security Updates for Multiple Products

NSA, ASD Release Guidance for Mitigating Web Shell Malware

The U.S. National Security Agency (NSA) and the Australian Signals Directorate (ASD) have jointly released a Cybersecurity Information Sheet (CSI) on mitigating web shell malware. Malicious cyber actors are increasingly…

Comments Off on NSA, ASD Release Guidance for Mitigating Web Shell Malware

IC3 Releases Alert on Extortion Email Scams

The Internet Crime Complaint Center (IC3) has released an alert warning of a recent increase in extortion email scams. Cyber criminals threaten to release sexually explicit photos or videos of…

Comments Off on IC3 Releases Alert on Extortion Email Scams

Vulnerability Summary for the Week of April 13, 2020

Original release date: April 20, 2020The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet…

Comments Off on Vulnerability Summary for the Week of April 13, 2020

Apple Releases Security Update for Xcode

Apple has released a security update to address vulnerabilities in Xcode. A remote attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security…

Comments Off on Apple Releases Security Update for Xcode

AA20-107A: Continued Threat Actor Exploitation Post Pulse Secure VPN Patching

Note: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor techniques and mitigations. This…

Comments Off on AA20-107A: Continued Threat Actor Exploitation Post Pulse Secure VPN Patching

Oracle Releases April 2020 Security Bulletin

Oracle has released its Critical Patch Update for April 2020 to address 397 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of…

Comments Off on Oracle Releases April 2020 Security Bulletin

AA20-106A: Guidance on the North Korean Cyber Threat

The U.S. Departments of State, the Treasury, and Homeland Security, and the Federal Bureau of Investigation are issuing this advisory as a comprehensive resource on the North Korean cyber threat…

Comments Off on AA20-106A: Guidance on the North Korean Cyber Threat

VMware Releases Security Updates for vRealize Log Insight

VMware has released security updates to address vulnerabilities in VMware vRealize Log Insight. An attacker could exploit these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure…

Comments Off on VMware Releases Security Updates for vRealize Log Insight

Microsoft Releases April 2020 Security Updates

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and…

Comments Off on Microsoft Releases April 2020 Security Updates