| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Feb 29, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-060-01 Delta Electronics CNCSoft-B ICSMA-24-060-01 MicroDicom DICOM Viewer This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 29, 2024 | CISA | Alert | CISA, FBI, and MS-ISAC Release Advisory on Phobos Ransomware Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars. This product is provided subject to this Notification and this Privacy & Use policy. | CISA, FBI, MS-ISAC |
| Feb 29, 2024 | CISA | Advisory | #StopRansomware: Phobos Ransomware INDICATORS OF COMPROMISE (IOCs) See Table 1 through 6 for IOCs obtained from CISA and the FBI investigations from September through Table 1: Associated Phobos Domains Table 2: Observed Phobos Shell Commands vssadmin delete shadows /all /quiet [T1490] netsh advfirewall set currentprofile state off netsh firewall set opmode mode=disable [T1562.004] bcdedit /set {default} bootstatuspolicy ignoreallfailures [T1547. | CISA, FBI, MS-ISAC |
| Feb 29, 2024 | CISA | Alert | CISA and Partners Release Advisory on Threat Actors Exploiting Ivanti Connect Secure and Policy Secure Gateways Vulnerabilities Additionally, the advisory describes two key CISA findings: The Ivanti Integrity Checker Tool is not sufficient to detect compromise due to the ability of threat actors to deceive it, and A cyber threat actor may be able to gain root-level persistence despite the victim having issued factory resets on the Ivanti device. | ASD/ACSC, CCCS, CISA, FBI, MS-ISAC, NCSC-NZ, NCSC-UK |
| Feb 29, 2024 | CISA | Advisory | Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect c… | ASD/ACSC, CCCS, CISA, FBI, MS-ISAC, NCSC-NZ, NCSC-UK |
| Feb 29, 2024 | CERT-EU | Advisory | 2024-022: Vulnerabilities in Adobe products If exploited, the vulnerabilities would allow an attacker to cause remote arbitrary code execution, remote denial of service, remote code injection or disclosure of sensitive information. Among all the fixed vulnerabilities, the critical ones, with CVSS scores ranging from 7.8 to 9.1 If exploited, these critical vulnerabilities could lead to arbitrary code execution. | CERT-EU |
| Feb 28, 2024 | CISA | Alert | CISA Releases Resource Guide for University Cybersecurity Clinics University cybersecurity clinics train students from diverse backgrounds and academic expertise to strengthen the digital defenses of non-profits, hospitals, municipalities, small businesses, and other under-resourced organizations. They can help address the national cyber workforce gap by developing a talent pipeline for cyber civil defense and helping students see themselves in a cybersecurity career. | CISA |
| Feb 27, 2024 | CISA | Alert | CISA, FBI, and HHS Release an Update to #StopRansomware Advisory on ALPHV Blackcat ALPHV Blackcat affiliates have been observed primarily targeting the healthcare sector. CISA, the FBI, and HHS urge network defenders to review the updated joint advisory to protect and detect against malicious activity. | CISA, FBI, HHS |
| Feb 27, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-058-01 Mitsubishi Electric Multiple Factory Automation Products ICSMA-24-058-01 Santesoft Sante DICOM Viewer Pro This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 27, 2024 | NSA | Alert | Russian Cyber Actors Use Compromised Routers to Facilitate Cyber Operations The Federal Bureau of Investigation (FBI), Actions EdgeRouter network defenders and Command, and international partners are releasing APT28 activity: this joint Cybersecurity Advisory (CSA) to warn of Perform a hardware factory reset. Russian state-sponsored cyber actors’ use of Upgrade to the latest firmware version. | FBI, NSA |
| Feb 26, 2024 | CISA | Alert | CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure This advisory provides recent tactics, techniques, and procedures (TTPs) used by Russian Foreign Intelligence Service (SVR) cyber actors—also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard—to gain initial access into a cloud environment. The authoring agencies encourage network defenders and organizations review the joint advisory for recommended mitigations. | CISA, NCSC, NCSC-UK |
| Feb 26, 2024 | NSA | Advisory | SVR Cyber Actors Adapt Tactics for Initial Cloud Access How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known as APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear. | CISA, FBI, NSA |
| Feb 26, 2024 | NSA | Alert | SVR Cyber Actors Adapt Tactics for Initial Cloud Access The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h… | ASD/ACSC, CCCS, CISA, CNMF, FBI, NCSC-UK, NSA |
| Feb 23, 2024 | CISA | Alert | Updated: Top Cyber Actions for Securing Water Systems This update includes additional resources—from American Water Works Association, the WaterISAC, and MS-ISAC—to support water systems in defending against from malicious cyber activity. The fact sheet outlines the following practical actions Water and Wastewater Systems (WWS) Sector entities can take to better protect water systems from malicious cyber activity and provides actionable guidance to implement concurrently: Reduce Exposure to the Publ… | CISA |
| Feb 22, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-053-01 Delta Electronics CNCSoft-B DOPSoft This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 22, 2024 | CISA | Alert | CISA Adds One Known Exploited ConnectWise Vulnerability, CVE-2024-1709, to Catalog Reducing the Significant Risk of Known Exploited Vulnerabilities The impact of cybersecurity intrusions that leverage vulnerabilities in information technology and operational technology products threaten the public sector, the private sector, and ultimately the American people’s security and privacy. In 2020, industry partners identified a total of 18,358 new cybersecurity vulnerabilities, or Common Vulnerabilities and Exposures (CVEs). | CISA |
| Feb 21, 2024 | CISA | Alert | CISA, EPA, and FBI Release Top Cyber Actions for Securing Water Systems This fact sheet outlines the following practical actions Water and Wastewater Systems (WWS) Sector entities can take to better protect water systems from malicious cyber activity and provides actionable guidance to implement concurrently: Reduce Exposure to the Public-Facing Internet Conduct Regular Cybersecurity Assessments Change Default Passwords Immediately Conduct an Inventory of Operational Technology/Information Technology Assets Develop a… | CISA, FBI |
| Feb 21, 2024 | CISA | Alert | Mozilla Releases Security Updates for Firefox and Thunderbird A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 21, 2024 | CERT-EU | Advisory | 2024-021: Vulnerabilities in Atlassian Products The security advisory also addresses 10 other high severity vulnerabilities which have been fixed in new versions of several Atlassian products [2]. The vulnerability CVE-2024-21678 , with a CVSS score of 8.5, is a stored XSS vulnerability that allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victim’s browser which has a high impact to confidentiality, low impact to integrity, no impact to availability, and requi… | CERT-EU |
| Feb 20, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-051-01 Commend WS203VICM ICSA-24-051-02 Ethercat Zeek Plugin ICSA-24-051-03 Mitsubishi Electric Electrical Discharge Machines This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 20, 2024 | NCSC | Guidance | Private Branch Exchange (PBX) best practice Protecting your organisation’s telephony systems from cyber attacks and telecoms All PBX systems should follow the NICC’s Requirements on Communications Providers in relation to Customer Line Identification display services and other related services A Private Branch Exchange (PBX) is a telecommunications system used to manage and route incoming and outgoing telephone calls within an organisation. | NCSC-UK |
| Feb 15, 2024 | CISA | Alert | CISA Releases Seventeen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-046-01 Siemens SCALANCE W1750D ICSA-24-046-02 Siemens SIDIS Prime ICSA-24-046-03 Siemens SIMATIC RTLS Gateways ICSA-24-046-04 Siemens CP343-1 Devices ICSA-24-046-05 Siemens Location Intelligence ICSA-24-046-06 Siemens Unicam FX ICSA-24-046-07 Siemens Tecnomatix Plant Simulation ICSA-24-046-08 Siemens RUGGEDCOM APE1808… | CISA |
| Feb 15, 2024 | CISA | Alert | CISA and MS-ISAC Release Advisory on Compromised Account Used to Access State Government Organization Following an incident response assessment of a state government organization’s network environment, analysis confirmed compromise through network administrator credentials of a former employee. This allowed the threat actor to successfully authenticate to an internal virtual private network (VPN) access point. | CISA, MS-ISAC |
| Feb 15, 2024 | CISA | Advisory | Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization CISA Analysis: Fiscal Year 2022 Risk and Vulnerability Assessments The Cybersecurity and Infrastructure Security Agency (CISA) conducts Risk and Vulnerability Assessments (RVAs) for the federal civilian executive branch (FCEB); high priority private and public sector critical infrastructure operators; and select state, local, tribal, and territorial (SLTT) stakeholders. | CISA, CSA |
| Feb 15, 2024 | CERT-EU | Advisory | 2024-020: Critical Vulnerability in Zoom Products If exploited, this vulnerability allows an unauthenticated attacker to conduct privilege escalation on the target system via network access. The vulnerability CVE-2024-24691 , with a CVSS score of 9.6, is due to an improper input validation flaw that could allow an unauthenticated attacker to conduct privilege escalation on the target system over the network. | CERT-EU |
| Feb 14, 2024 | JPCERT/CC | Alert | Alert Regarding Vulnerability in Adobe Acrobat and Reader (APSB24-07) A vulnerability exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Feb 14, 2024 | CERT-EU | Advisory | 2024-019: Critical Vulnerabilities in Microsoft Products On February 13, 2024, Microsoft released its February 2024 Patch Tuesday advisory [1,2], addressing 73 vulnerabilities, two of which are exploited in the wild. It recommended applying updates as soon as possible on affected products. a malicious file, which could result in bypassing the SmartScreen user experience and potentially code injection into SmartScreen to achieve remote code execution. | CERT-EU |
| Feb 13, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-044-01 Mitsubishi Electric MELSEC iQ-R Series Safety CPU and SIL2 Process CPU This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 13, 2024 | CISA | Alert | ISC Releases Security Advisories for BIND 9 A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 13, 2024 | CISA | Alert | Microsoft Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Feb 13, 2024 | CISA | Alert | Adobe Releases Security Updates for Multiple Products Adobe has released security updates to address vulnerabilities in Adobe software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Adobe FrameMaker Publishing Server This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 12, 2024 | CISA | Alert | Priorities of the Joint Cyber Defense Collaborative for 2024 Similar to the 2023 JCDC Planning Agenda, JCDC’s 2024 Priorities will help focus the collective group on developing high-impact and collaborative solutions to the most pressing cybersecurity challenges. Resulting from the trusted partnerships the collaborative has fostered, the focused goals of the 2024 priorities are to: Defend against Advanced Persistent Threat (APT) operations. | CISA |
| Feb 9, 2024 | CISA | Alert | Fortinet Releases Security Advisories for FortiOS | CISA |
| Feb 9, 2024 | CERT-EU | Advisory | 2024-018: Critical Vulnerabilities in FortiOS It is recommended The vulnerability CVE-2024-21762 [1], with a CVSS score of 9.8, is due to incorrect parameter checks in FortiOS SSL-VPN. When exploited by a remote and unauthenticated attacker via crafted HTTP requests, a reduced number of bytes could be copied outside buffer bounds, leading to memory corruption and flow redirection. | CERT-EU |
| Feb 9, 2024 | CERT-EU | Advisory | 2024-004: Critical Vulnerabilities in Ivanti Connect Secure These vulnerabilities, identified as CVE-2023-46805 and CVE-2024-21887, have been exploited in the wild and can allow remote attackers to execute arbitrary commands on targeted gateways. On January 31, 2024, Ivanti has released an advisory about two new critical vulnerabilities [2] in Ivanti Connect Secure (ICS) and Policy Secure gateways. | CERT-EU |
| Feb 9, 2024 | CISA | Alert | JetBrains Releases Security Advisory for TeamCity On-Premises A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 8, 2024 | CISA | Alert | CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security Recognizing the critical role package repositories play in securing open source software ecosystems, this framework lays out voluntary security maturity levels for package repositories. This publication supports Objective 1.2 of CISA's Open Source Software Security Roadmap , which states the goal of "working collaboratively [with relevant working groups] to develop security principles for package managers. | CISA |
| Feb 8, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-039-01 Qolsys IQ Panel 4, IQ4 HUB ICSA-23-082-06 ProPump and Controls Osprey Pump Controller (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 8, 2024 | CISA | Alert | Cisco Releases Security Advisory for Vulnerabilities in Cisco Expressway Series A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 7, 2024 | NSA | Alert | CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance Today, CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure alongside supplemental Joint Guidance: Identifying and Mitigating Living off the Land Techniques . | CISA, FBI, NSA |
| Feb 7, 2024 | CISA | Alert | VMware Releases Security Advisory for Aria Operations for Networks A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 7, 2024 | CISA | Analysis Report | MAR-10448362-1.v1 Volt Typhoon Malware Analysis Report 2024-05-17 This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. | CISA |
| Feb 7, 2024 | NSA | Advisory | PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51. | ASD/ACSC, CCCS, CISA, DOE, EPA, FBI, NCSC-NZ, NCSC-UK, NIST, NSA, TSA |
| Feb 7, 2024 | NSA | Alert | PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States. | ASD/ACSC, CCCS, CISA, DOE, EPA, FBI, NCSC-NZ, NCSC-UK, NSA, TSA |
| Feb 7, 2024 | NSA | Analysis Report | CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S. | ASD/ACSC, CCCS, CISA, DOE, EPA, FBI, NCSC-NZ, NCSC-UK, NSA, TSA |
| Feb 6, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-037-01 HID Global Encoders ICSA-24-037-02 HID Global Reader Configuration Cards This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 6, 2024 | CERT-EU | Advisory | 2024-017: Critical Vulnerabilites in FortiSIEM If exploited, these vulnerabilities could allow a remote unauthenticated attacker to execute commands on the system. The vulnerabilities CVE-2024-23108 and CVE-2024-23109, both with a provisional CVSS score of 10 out of 10, are due to improper neutralisation of special elements. | CERT-EU |
| Feb 6, 2024 | CERT-EU | Advisory | 2024-016: High Vulnerability in the runc package This vulnerability, tracked as CVE-2024-21626 with a CVSS score of 8.6, enables attackers to escape containers and potentially gain unauthorised access to the host operating system. The vulnerability CVE-2024-21626 arises from an internal file descriptor leak within runc, a core component for running containers according to the Open Container Initiative (OCI) standards. | CERT-EU |
| Feb 2, 2024 | CISA | Alert | Juniper Networks Releases Security Bulletin for Juniper Secure Analytics A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 1, 2024 | CISA | Alert | Moby and Open Container Initiative Release Critical Updates for Multiple Vulnerabilities Affecting Docker-related Components A cyber threat actor could exploit these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Feb 1, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-032-01 Gessler GmbH WEB-MASTER ICSA-24-032-03 AVEVA Edge products (formerly known as InduSoft Web Studio) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |