WaterISAC Releases Advisory for Microsoft DCOM Patch

The Water Information Sharing and Analysis Center (WaterISAC) has released an advisory, Potential for Mandatory Microsoft DCOM Patch to Disrupt SCADA. ICS/OT/SCADA engineers and operators should assess the use of…

Comments Off on WaterISAC Releases Advisory for Microsoft DCOM Patch

Beware of Bank-Related Scams

In light of recent bank failures, CISA warns consumers to beware of potential scams requesting your money or sensitive personal information. Exercise caution in handling emails with bank-related subject lines,…

Comments Off on Beware of Bank-Related Scams

CISA Announces Ransomware Vulnerability Warning Pilot

Today, CISA is announcing the creation of the Ransomware Vulnerability Warning Pilot (RVWP). Through the RVWP, CISA:      Proactively identifies information systems—belonging to critical infrastructure entities—that contain vulnerabilities commonly…

Comments Off on CISA Announces Ransomware Vulnerability Warning Pilot

Fortinet Releases March 2023 Vulnerability Advisories

Fortinet has released its March 2023 Vulnerability Advisories to address vulnerabilities affecting multiple products. An attacker could exploit one of these vulnerabilities to take control of an affected system.    CISA encourages…

Comments Off on Fortinet Releases March 2023 Vulnerability Advisories

Vulnerability Summary for the Week of February 6, 2017

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info dotnetnuke -- dotnetnuke The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the…

Comments Off on Vulnerability Summary for the Week of February 6, 2017

Vulnerability Summary for the Week of January 8, 2018

  High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info advantech -- webaccess A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess…

Comments Off on Vulnerability Summary for the Week of January 8, 2018

Vulnerability Summary for the Week of August 21, 2017

  High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source & Patch Info apache2triad -- apache2triad Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions…

Comments Off on Vulnerability Summary for the Week of August 21, 2017

Vulnerability Summary for the Week of November 5, 2018

The NCCIC Weekly Vulnerability Summary Bulletin is created using information from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD). In some cases, the vulnerabilities in the…

Comments Off on Vulnerability Summary for the Week of November 5, 2018