CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ March 2024 ›
45 publications — sorted newest first
Date Source Type Title Author
Mar 29, 2024 CISA Alert Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094 CISA
Mar 29, 2024 CERT-EU Advisory 2024-031: High Severity Vulnerabilities in Cisco Products Six (6) high severity vulnerabilities with a CVSS score of 8.6, could allow an unauthenticated, remote attacker to cause denial of service on an packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition [2]. to exhaust CPU resources and stop processing traffic, resulting in a DoS condition [3]. crafted UDP packets to an affected system. CERT-EU
Mar 28, 2024 CISA Alert Cisco Releases Security Updates for Multiple Products Cisco released security updates to address vulnerabilities in Cisco IOS, IOS XE, and AP software. A cyber threat actor could exploit some of these vulnerabilities to cause a denial-of-service. Cisco Event Response: March 2024 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication Cisco Access Point Software Secure Boot Bypass Vulnerability Cisco Access Point Software Denial of Service Vulnerability This product is provided… CISA
Mar 27, 2024 CISA Alert Apple Released Security Updates for Safari and macOS A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 26, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-086-01 Automation-Direct C-MORE EA9 HMI ICSA-24-086-03 Rockwell Automation Arena Simulation ICSA-24-086-04 Rockwell Automation FactoryTalk View ME This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 25, 2024 CISA Alert CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate SQL Injection Vulnerabilities This Alert was crafted in response to a recent, well-publicized exploitation of SQL injection (SQLi) defects in a managed file transfer application that impacted thousands of organizations. Additionally, the Alert highlights the prevalence of this class of vulnerability. CISA, FBI
Mar 21, 2024 CISA Alert CISA, FBI, and MS-ISAC Release Update to Joint Guidance on Distributed Denial-of-Service Techniques The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in network protocols. CISA, FBI, MS-ISAC
Mar 21, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-081-01 Advantech WebAccess/SCADA This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 21, 2024 CISA Alert Ivanti Releases Security Updates for Neurons for ITSM and Standalone Sentry A cyber threat actor could exploit these vulnerabilities to take control of an affected system. CVE-2023-46808 (Authenticated Remote File Write) for Ivanti Neurons for ITSM CVE-2023-41724 (Remote Code Execution) for Ivanti Standalone Sentry This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 21, 2024 CERT-EU Advisory 2024-030: Critical Vulnerabilities in Ivanti Products According to Ivanti, there is no evidence of these vulnerabilities being exploited in the wild. It is recommended upgrading affected software as soon as possible. CERT-EU
Mar 21, 2024 NCSC Guidance Responding to a cyber incident – a guide for CEOs It sets out aspects to consider at the start of an incident and If your organisation is victim of a significant cyber attack, the immediate aftermath will be challenging. You may find there is a lot of information in some areas, and none in others. NCSC-UK
Mar 21, 2024 NSA Alert PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders This fact sheet provides an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” CISA—along with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and other U.S. government and international partners1—released a major advisory on Feb. 7, 2024, in which the U.S. ASD/ACSC, CCCS, DOE, EPA,
FBI, NCSC-NZ, NCSC-UK, NSA,
TSA, Treasury
Mar 19, 2024 NSA Alert CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity and international partners are issuing a joint fact sheet, People’s Republic of China State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders . Partners of this publication include: U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S. Transportation Security Administration (TSA) U.S. CISA, FBI, NSA
Mar 19, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-079-01 Franklin Fueling System EVO 550/5000 This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 18, 2024 CISA Alert Repository for Software Attestation and Artifacts Now Live Software producers that provide the government software can fill out the form to attest to implementation of specific security practices. CISA and the Office of Management and Budget (OMB) released the form on March 11, 2024, following extensive stakeholder and industry engagement. CISA
Mar 14, 2024 CISA Alert CISA Releases Fifteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-074-01 Siemens SENTRON 7KM PAC3x20 ICSA-24-074-02 Siemens Solid Edge ICSA-24-074-03 Siemens SINEMA Remote Connect Server ICSA-24-074-04 Siemens SINEMA Remote Connect Client ICSA-24-074-05 Siemens RUGGEDCOM APE1808 ICSA-24-074-06 Siemens SENTRON ICSA-24-074-07 Siemens SIMATIC ICSA-24-074-08 Siemens SCALANCE XB-200/XC-20… CISA
Mar 14, 2024 CISA Alert Cisco Releases Security Updates for IOS XR Software A cyber threat actor could exploit one of these vulnerabilities to take control of an affected device. Cisco IOS XR Software for ASR 9000 Series Aggregation Services Routers PPPoE Denial of Service Vulnerability Cisco IOS XR Software SSH Privilege Escalation Vulnerability Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 12, 2024 CISA Alert Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 12, 2024 CISA Alert Microsoft Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for March Microsoft Security Update Guide for March This product is provided subject to this Notification and this Privacy & Use policy. CISA, JPCERT/CC
Mar 12, 2024 CISA Alert Fortinet Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. FR-IR-23-390: FortiClientEMS - CSV injection in log download feature FR-IR-23-390: FortiClientEMS - CSV injection in log download feature FR-IR-23-328: FortiOS, FortiProxy - Out-of-bounds Write in captive portal FR-IR-23-328: FortiOS, FortiProxy - Out-of-bounds Write in captive portal FR-IR-24-013: FortiOS, FortiProxy - Authorization bypass in… CISA
Mar 12, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-072-01 Schneider Electric EcoStruxure Power Design This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 12, 2024 CISA Alert CISA Publishes SCuBA Hybrid Identity Solutions Guidance This initial publication reflects feedback gathered during its 2023 draft public comment period . In accordance with Executive Order 14028 , CISA’s SCuBA project aims to develop consistent, effective, modern, and manageable security that will help secure organizations’ information assets stored within cloud environments. CISA
Mar 8, 2024 CISA Alert Apple Released Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 8, 2024 CERT-EU Advisory 2024-026: Vulnerabilities in GitLab CODEOWNERS approval allowing stealing protected variables by utilising a crafted payload in an old feature branch to perform malicious actions. role of manage_group_access_tokens to rotate group access tokens with owner privileges. CERT-EU strongly recommends updating software installations to the latest versions by following the instructions given by the vendor [1]. CERT-EU
Mar 7, 2024 CISA Alert Cisco Releases Security Updates for Secure Client A cyber threat actor could exploit one of these vulnerabilities to take control of an affected device. Cisco Secure Client Carriage Return Line Feed Injection Vulnerability Cisco Secure Client for Linux with ISE Posture Module Privilege Escalation Vulnerability This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 7, 2024 CISA Alert Apple Releases Security Updates for iOS and iPadOS A cyber threat actor could exploit one of these vulnerabilities to obtain sensitive information. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 7, 2024 NSA Guidance CSI: Enforce Secure Automated Deployment Practices through Infrastructure as Code These terms refer to templates that are used to deploy resources across on-premises and cloud infrastructures. IaC uses code to automate the deployment of compute, network, and storage services, as well as security policies (often denoted as policy as code). NSA
Mar 7, 2024 NSA Guidance CSI: Use Secure Cloud Key Management Practices Security | Cybersecurity Information Cryptographic operations enable secure communication, access control, authentication, and data encryption at rest. The security of these operations all rely on proper key management. Cloud service providers (CSPs) use key management systems (KMSs) to offer encryption and key management as a service, including functionality such as:  Management operations on symmetric and asymmetric keys, including:  applicat… NSA
Mar 7, 2024 NSA Guidance CSI: Mitigate Risks from Managed Service Providers in Cloud Environments The growth of the public cloud has encouraged the development of numerous MSPs that primarily provide these services within the cloud rather than in customer on-premises networks. Both cloud resellers and other IT vendors offer such third-party services. ASD/ACSC, CISA, NSA
Mar 7, 2024 NSA Guidance CSI: NSA’s Top Ten Cloud Security Mitigation Strategies As organizations continue to migrate to using cloud environments, these environments are becoming increasingly valuable targets for malicious cyber actors (MCA). Many cloud breaches occur due to misconfigurations in cloud tenants. NSA’s Top Ten Cloud Security Mitigation Strategies inform cloud customers of the most important practices to improve the security posture of their cloud environments. NSA
Mar 7, 2024 NSA Guidance CSI: Implement Network Segmentation and Encryption in Cloud Environments Security | Cybersecurity Information Network security is a crucial component for cloud users to configure properly. Historically, network security practices have focused on perimeter security, with few additional restrictions once authenticated to an organization’s internal network and the acceptance of unauthenticated and vulnerable “internal” protocols. NSA
Mar 7, 2024 NSA Guidance CSI: Secure Data in the Cloud Security | Cybersecurity Information As organizations move more of their data into cloud environments, the prevention of unauthorized access to that data is extremely important. Data stored in the cloud can take many forms depending on the needs of the organization. NSA
Mar 7, 2024 NSA Guidance CSI: Uphold the Cloud Shared Responsibility Model The threat landscape of the cloud differs from that of a traditional on-premises environment. An increasing reliance on the cloud brings new complexities and security challenges, and as a result, adversaries are increasingly targeting these environments. Customers often incorrectly assume that the cloud service provider (CSP) manages important aspects of safeguarding resources in the cloud that are not the CSP’s responsibility. NSA
Mar 7, 2024 NSA Guidance CSI: Manage Cloud Logs for Effective Threat Hunting The many ways of accessing and managing a cloud tenant (often from anywhere in the world) can complicate the problem of security monitoring. Since cloud networks are virtualized, getting to “ground truth” can be difficult. Defense of a cloud tenant hinges on maintaining logs that record the right level of detail on security-relevant events. NSA
Mar 7, 2024 NSA Guidance CSI: Account for Complexities Introduced by Hybrid Cloud and Multi-Cloud Environments The private cloud, often referred to as an on-premises (on-prem) solution, is an infrastructure provisioned for use by a single company, whereas the public cloud is provisioned for general use by many organizations. A multi-cloud environment, on the other hand, provisions multiple offerings from different cloud service providers. NSA
Mar 7, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-067-01 Chirp Systems Chirp Access This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 7, 2024 CISA Alert CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices Use Secure Cloud Identity and Access Management Practices Use Secure Cloud Key Management Practices Mitigate Risks from Managed Service Providers in Cloud Environments This product is provided subject to this Notification and this Privacy & Use policy. CISA, NSA
Mar 7, 2024 CISA Alert CISA Adds One Known Exploited JetBrains Vulnerability, CVE-2024-27198, to Catalog Reducing the Significant Risk of Known Exploited Vulnerabilities The impact of cybersecurity intrusions that leverage vulnerabilities in information technology and operational technology products threaten the public sector, the private sector, and ultimately the American people’s security and privacy. In 2020, industry partners identified a total of 18,358 new cybersecurity vulnerabilities, or Common Vulnerabilities and Exposures (CVEs). CISA
Mar 7, 2024 CERT-EU Advisory 2024-025: Zero-Day Vulnerabilities in Apple Products The two zero-day vulnerabilities, namely CVE-2024-23225 and CVE-2024-23296 , respectively exist in the iOS Kernel and RTKit. A memory corruption in those components would allow an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. CERT-EU
Mar 7, 2024 CERT-EU Advisory 2024-024: Vulnerabilities in VMware Products The most serious bugs could allow a malicious actor with local admin privileges on a virtual machine to execute code as the virtual machine’s VMX process running on the host. It is recommended upgrading affected software as soon as possible. CERT-EU
Mar 7, 2024 CERT-EU Advisory 2024-023: Vulnerabilities in JetBrains TeamCity Both vulnerabilities are authentication bypass vulnerabilities. If exploited, the most severe vulnerability allows for a complete compromise of a vulnerable TeamCity server by a remote unauthenticated attacker, including unauthenticated RCE [1,2]. CERT-EU
Mar 6, 2024 CISA Alert VMware Releases Security Advisory for Multiple Products A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 5, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-065-01 Nice Linear eMerge E3-Series ICSMA-24-065-01 Santesoft Sante FFT Imaging ICSA-24-016-02 Integration Objects OPC UA Server Toolkit (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Mar 5, 2024 NSA Guidance CSI: Advancing Zero Trust Maturity Throughout the Network and Environment Pillar The Zero Trust network and environment pillar curtails adversarial lateral movement by employing controls and capabilities to logically and physically segment, isolate, and control access (on-premises and off-premises) through granular policy restrictions. CISA, NSA, NSM
Mar 1, 2024 CISA Alert Cisco Releases Security Advisories for Cisco NX-OS Software A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition. Cisco NX-OS Software MPLS Encapsulated IPv6 Denial of Service Vulnerability Cisco NX-OS Software External Border Gateway Protocol Denial of Service Vulnerability This product is provided subject to this Notification and this Privacy & Use policy. CISA