CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ April 2024 ›
37 publications — sorted newest first
Date Source Type Title Author
Apr 30, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-121-01 Delta Electronics CNCSoft-G2 DOPSoft ICSA-24-016-01 SEW-EURODRIVE MOVITOOLS MotionStudio (Update A) ICSA-24-109-01 Unitronics Vision Legacy Series (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 29, 2024 CERT-EU Advisory 2024-037: Critical Vulnerability in PAN-OS software This vulnerability allows an unauthenticated remote attacker to execute arbitrary code as root on the affected device [1]. This vulnerability is being exploited in the wild, and proof-of-concepts have been publicly disclosed by third parties [4]. CERT-EU
Apr 25, 2024 CISA Alert CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-116-01 Multiple Vulnerabilities in Hitachi Energy RTU500 Series ICSA-24-116-02 Hitachi Energy MACH SCM ICSA-24-116-03 Siemens RUGGEDCOM APE1808 Devices Configured with Palo Alto Networks Virtual NGFW ICSA-24-116-04 Honeywell Experion PKS, Experion LX, PlantCruise by Experion, Safety Manager, Safety Manager SC ICSA-23-1… CISA
Apr 24, 2024 CISA Alert Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms Today, Cisco released security updates to address ArcaneDoor—exploitation of Cisco Adaptive Security Appliances (ASA) devices and Cisco Firepower Threat Defense (FTD) software. A cyber threat actor could exploit vulnerabilities ( CVE-2024-20353 , CVE-2024-20359 , CVE-2024-20358 ) to take control of an affected system. CISA
Apr 24, 2024 CERT-EU Advisory 2024-043: Vulnerabilities in Cisco ASA and FTD Software It is recommended upgrading affected products as soon as possible, and checking for possible compromise. The vulnerability CVE-2024-20353 [1], with a CVSS score of 8.6, allows an attacker to cause a DoS condition by sending a crafted HTTP request to the web server on a targeted device. CERT-EU
Apr 23, 2024 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-051-03 Mitsubishi Electric Electrical Discharge Machines (Update A) ICSA-24-067-01 Chirp Systems Chirp Access (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 19, 2024 CISA Alert Cisco Releases Security Advisories for Cisco Integrated Management Controller A remote cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply the necessary updates: Cisco Integrated Management Controller CLI Command Injection Vulnerability Cisco Integrated Management Controller Web-Based Management Interface Command Injection Vulnerability This product is provided subject to this Notification a… CISA
Apr 18, 2024 CISA Alert CISA and Partners Release Advisory on Akira Ransomware Today, CISA, the Federal Bureau of Investigation (FBI), Europol’s European Cybercrime Centre (EC3), and the Netherlands’ National Cyber Security Centre (NCSC-NL) released a joint Cybersecurity Advisory (CSA), #StopRansomware: Akira Ransomware , to disseminate known Akira ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as February 2024. CISA, EC3, FBI, NCSC-NL
Apr 18, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-109-01 Unitronics Vision Series PLCs ICSA-21-287-03 Mitsubishi Electric MELSEC iQ-R Series (Update B) ICSA-21-250-01 Mitsubishi Electric MELSEC iQ-R Series (Update B) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 18, 2024 CISA Alert Oracle Releases Critical Patch Update Advisory for April 2024 A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following Critical Patch Update Advisory and apply the necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 18, 2024 CISA Advisory #StopRansomware: Akira Ransomware #StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira  Prioritize remediating known exploited vulnerabilities.  Enable and enforce phishing-resistant multifactor authentication (MFA). CISA, DC3, EC3, FBI,
HHS, NCSC-NL, OFAC
Apr 18, 2024 CERT-EU Advisory 2024-042: Vulnerability in Cisco Integrated Management Controller The vulnerability CVE-2024-20356 [2], with a CVSS score of 8.7, could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. CERT-EU
Apr 17, 2024 CERT-EU Advisory 2024-040: Vulnerabilities in Atlassian Products It is recommended updating as soon as possible prioritising internet facing instances. All the vulnerabilities, with CVSS scores ranging from 7.5 to 8.2, are caused by vulnerable dependencies used by Atlassian products. CERT-EU
Apr 17, 2024 CERT-EU Advisory 2024-041: Multiple Vulnerabilities in Ivanti Avalanche MDM The two critical security flaws, tracked as CVE-2024-24996 and CVE-2024-29204, with CVSS score of 9.8, were found in Avalanche’s WLInfoRailService and WLAvalancheService components [1]. They are both caused by heap-based buffer overflow weaknesses, which can let unauthenticated remote attackers execute arbitrary commands on vulnerable systems in low-complexity attacks that do not require user interaction [1]. CERT-EU
Apr 16, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-107-01 Measuresoft ScadaPro ICSA-24-107-02 Electrolink FM/DAB/TV Transmitter ICSA-24-107-03 Rockwell Automation ControlLogix and GuardLogix This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 16, 2024 CERT-EU Advisory 2024-038: Critical vulnerabilities in Junos OS and Junos OS Evolved These vulnerabilities could allow remote attackers to execute arbitrary code, cause denial of service, or leak sensitive information. It is strongly advised to update affected systems to the latest versions to mitigate these risks. CERT-EU
Apr 15, 2024 CISA Alert Joint Guidance on Deploying AI Systems Securely Provide methodologies and controls to protect, detect, and respond to malicious activity against AI systems and related data and services. This product is provided subject to this Notification and this Privacy & Use policy. CISA, FBI, NSA
Apr 12, 2024 CISA Alert Palo Alto Networks Releases Guidance for Vulnerability in PAN-OS, CVE-2024-3400 Palo Alto Networks has reported active exploitation of this vulnerability in the wild. CISA has also added this vulnerability to its Known Exploited Vulnerabilities Catalog . CISA
Apr 12, 2024 CISA Alert Citrix Releases Security Updates for XenServer and Citrix Hypervisor XenServer and Citrix Hypervisor Security Update for CVE-2023-46842, CVE-2024-2201 and CVE-2024-31142 This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 12, 2024 CISA Alert Juniper Networks Releases Security Bulletin for Multiple Juniper Products Juniper Networks released security updates to address multiple vulnerabilities in Junos OS, Junos OS Evolved, Paragon Active Assurance and Junos OS: EX4300 Series. A cyber threat actor could exploit some of these vulnerabilities to cause a denial-of-service condition . Users and administrators are encouraged to review Juniper’s Support Portal and apply the necessary updates. CISA
Apr 11, 2024 CISA Alert CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-102-01 Siemens SIMATIC S7-1500 ICSA-24-102-02 Siemens SIMATIC WinCC ICSA-24-102-03 Siemens RUGGEDCOM APE1808 before V11.0. CISA
Apr 11, 2024 CISA Alert Compromise of Sisense Customer Data Reset credentials and secrets potentially exposed to, or used to access, Sisense services. Investigate—and report to CISA —any suspicious activity involving credentials potentially exposed to, or used to access, Sisense services. CISA
Apr 11, 2024 CISA Alert CISA Issues Emergency Directive 24-02: Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System Today, CISA publicly issued Emergency Directive (ED) 24-02 to address the recent campaign by Russian state-sponsored cyber actor Midnight Blizzard to exfiltrate email correspondence of Federal Civilian Executive Branch (FCEB) agencies through a successful compromise of Microsoft corporate email accounts. CISA
Apr 11, 2024 CERT-EU Advisory 2024-036: Vulnerabilities in Fortinet products It is recommended upgrading affected software as soon as possible. ThevulnerabilityCVE-2023-45590[2],withaCVSSscoreof9.4,isduetoanimpropercontrol of generation of code. CERT-EU
Apr 10, 2024 CERT-EU Advisory 2024-034: Multiple Vulnerabilities in Microsoft Products OnApril9,2024,Microsoftaddressed150vulnerabilitiesinitsApril2024PatchTuesdayupdate [1], including 67 remote code execution (RCE) vulnerabilities and 2 zero-days exploited in It is recommended applying updates as soon as possible on affected products. CERT-EU
Apr 10, 2024 CERT-EU Advisory 2024-035: Critical Vulnerability in Rust on Windows This flaw allows command injection attacks via crafted batch file executions with untrusted arguments. It is recommended updating as soon as possible, prioritising assets running code (or one of its dependencies) which executes batch files with untrusted arguments [1]. CERT-EU
Apr 9, 2024 NSA Guidance CSI: Advancing Zero Trust Maturity Throughout the Data Pillar This cybersecurity information sheet (CSI) provides recommendations for maturing data security and enforcing access to data at rest and in transit, ensuring that only those with authorization can access the data. It further discusses how these capabilities integrate into a comprehensive Zero Trust (ZT) framework, as described in Embracing a Zero Trust Security Model. CISA, NSA, NSM
Apr 9, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-100-01 SUBNET PowerSYSTEM Server and Substation Server This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 9, 2024 CISA Alert Fortinet Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. FR-IR-23-345 FortiClientMac - Lack of configuration file validation FG-IR-23-493 FortiOS & FortiProxy - Administrator cookie leakage FG-IR-23-087 FortiClient Linux - Remote Code Execution due to dangerous nodejs configuration This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 9, 2024 CISA Alert Microsoft Releases April 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following and apply the necessary updates: Microsoft Security Update Guide for April This product is provided subject to this Notification and this Privacy & Use policy. CISA, JPCERT/CC
Apr 9, 2024 CISA Alert Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following Adobe Security Bulletins and apply the necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 4, 2024 CISA Alert Ivanti Releases Security Update for Ivanti Connect Secure and Policy Secure Gateways Ivanti has released security updates to address vulnerabilities in all supported versions (9.x and 22.x) of Ivanti Connect Secure and Policy Secure gateways. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. CISA
Apr 4, 2024 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-095-02 Schweitzer Engineering Laboratories SEL This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 4, 2024 CERT-EU Advisory 2024-033: Multiple Vulnerabilities in Ivanti Connect Secure Thevulnerability trackedasCVE-2024-21894isa severeflawinvolvinga heapoverflowin the IPSec component, enabling RCE and DoS without user interaction. Ivanti also fixed additional vulnerabilities [2] potentially leading to DoS attacks [1]. 22.5R1.3, 22.5R2.4, 22.6R2.3, 9.1R14.6, 9.1R15.4, 9.1R16.4, 9.1R17.4 and 9.1R18.5. CERT-EU
Apr 2, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-093-01 IOSIX IO-1020 Micro ELD This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 2, 2024 CISA Alert CISA Publishes New Webpage Dedicated to Providing Resources for High-Risk Communities Today, CISA published a new dedicated High-Risk Communities webpage comprised of cybersecurity resources to support civil society communities at heighted risk of digital security threats, including cyber hygiene guidance, a repository of local cyber volunteer programs, and free or discounted tools and services. CISA
Apr 2, 2024 CERT-EU Advisory 2024-032: Critical Vulnerability in XZ Utils XZ Utils is a data compression software and may be present in Linux distributions. The malicious code may allow a Threat Actor, with the right authentication key, to achieve gated pre-auth RCE on affected systems. [1] It is recommended downgrading XZ Utils to a not compromised version. [Updated]TheissueistrackedasCVE-2024-3094,withaCVSSscoreof10outof10. CERT-EU