| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| May 30, 2024 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-151-02 Fuji Electric Monitouch V-SFT ICSA-24-151-03 Inosoft VisiWin ICSA-24-151-04 Westermo EDW-100 ICSA-22-356-03 Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series (Update C) ICSMA-24-151-01 Baxter Welch Allyn Configuration Tool ICSMA-24-151-02 Baxter Welch Allyn Connex Spot Monitor This product is provid… | CISA |
| May 30, 2024 | CERT-EU | Advisory | 2024-053: Zero-day Vulnerability in Check Point Security Gateways This high-severity information disclosure vulnerability can be exploited to gain unauthorised access to sensitive information on systems with remote Access VPN or Mobile Access Software Blades enabled [1]. It is recommended applying the hotfix and the extra protection measures provided by the vendor Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed C… | CERT-EU |
| May 28, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-149-01 Campbell Scientific CSI Web Server This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 28, 2024 | CERT-EU | Advisory | 2024-052: Vulnerability in Cisco FMC Software If exploited, this vulnerability could allow an attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. The vulnerability CVE-2024-20360 [1], with a CVSS score of 8.8, lies in the web-based management interface of Cisco Firepower Management Center (FMC) Software. | CERT-EU, FMC |
| May 27, 2024 | CERT-EU | Advisory | 2024-051: Vulnerabilities in GitLab On May 22, GitLab has released several versions for GitLab Community Edition (CE) and Enterprise Edition (EE) containing important bug and security fixes [1]. These fixes notably address a vulnerability that would allow an attacker to take accounts over via an XSS vulnerability. It is strongly recommended upgrading affected versions to the latest version as soon as possible. | CERT-EU |
| May 24, 2024 | CISA | Alert | Cisco Releases May 2024 Cisco ASA, FMC, and FTD Software Security Publication Cisco released a bundled publication for security advisories that address vulnerabilities in Cisco Adaptive Security Appliance (ASA), Firepower Management Center (FMC), and Firepower Threat Defense (FTD) software. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. | CISA |
| May 23, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-144-01 AutomationDirect Productivity PLCs This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 22, 2024 | CERT-EU | Advisory | 2024-046: Multiple Vulnerabilities in Git These vulnerabilities could allow for remote code execution and unauthorised file modifications. The vulnerability CVE-2024-32002 , with a CVSS score of 9.1, could allow a remote attacker to execute code on the affected device. | CERT-EU |
| May 22, 2024 | CERT-EU | Advisory | 2024-047: Critical Vulnerability in GitHub Enterprise Server OnMay 21, 2024, GitHubdisclosed acriticalvulnerability inGitHubEnterprise Server(GHES) impacting instances using SAML single sign-on (SSO) with encrypted assertions. This vulnerability allows attackers to forge SAML responses, granting unauthorised administrative access A proof of concept is publicly available. | CERT-EU |
| May 22, 2024 | CERT-EU | Advisory | 2024-048: Critical Vulnerability in Veeam Backup Enterprise Manager The vulnerability CVE-2024-29849, with a CVSS score of 9.8, could allow an unauthenticated attacker to login into the Veeam Backup Enterprise Manager web interface as any user. The flaw lies in the authentication mechanism of the web interface. | CERT-EU |
| May 22, 2024 | CERT-EU | Advisory | 2024-049: Multiple Vulnerabilities in QNAP Products These vulnerabilities could allow remote attackers to execute arbitrary code. It is strongly advised updating affected systems to the latest versions to mitigate these risks. | CERT-EU |
| May 22, 2024 | CERT-EU | Advisory | 2024-050: Multiple Vulnerabilities in Ivanti EPMM An attacker could exploit these flaws to execute arbitrary commands on the appliance. It is strongly advised updating affected systems to the latest versions to mitigate these risks. | CERT-EU |
| May 22, 2024 | NSA | Guidance | CSI: Advancing Zero Trust Maturity Throughout the Application and Workload Pillar Information Technology (IT) professionals are keenly aware of the security challenges facing applications, but workloads are every bit as important to consider in this domain. Workloads represent computational tasks, which encompass multiple programs or applications performing those tasks by utilizing computing, data, networking, and storage resources. | CISA, NSA, NSM |
| May 21, 2024 | CISA | Alert | Rockwell Automation Encourages Customers to Assess and Secure Public-Internet-Exposed Assets Rockwell Automation has released guidance encouraging users to remove connectivity on all Industrial Control Systems (ICS) devices connected to the public-facing internet to reduce exposure to unauthorized or malicious cyber activity. | CISA |
| May 21, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-142-01 LCDS LAquis SCADA This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 16, 2024 | CISA | Alert | CISA Releases Seventeen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-137-01 Siemens Parasolid ICSA-24-137-02 Siemens SICAM Products ICSA-24-137-03 Siemens Teamcenter Visualization and JT2Go ICSA-24-137-04 Siemens Polarion ALM ICSA-24-137-05 Siemens Simcenter Nastran ICSA-24-137-06 Siemens SIMATIC CN 4100 Before V3. | CISA |
| May 16, 2024 | CISA | Alert | Cisco Releases Security Updates for Multiple Products Cisco has released security updates to address vulnerabilities in Cisco software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply necessary updates: • Cisco Crosswork Network Services Orchestrator • Cisco Crosswork Network Services Orchestrator Privilege Escalation • ConfD CLI Privilege Escalation and Arbitr… | CISA |
| May 16, 2024 | CERT-EU | Advisory | 2024-044: Zero-day Vulnerability in Chrome It has been reported that this vulnerability is beingactivelyexploited[1]. Google Chrome prior to version 125.0.6422.60/.61 for Windows and Mac, 125.0.6422.60 for Linuxareimpacted[1]. | CERT-EU |
| May 16, 2024 | FBI | Alert | Democratic People's Republic of Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue The Federal Bureau of Investigation (FBI) is warning the public and private sector of the threat posed to U.S. businesses by information technology (IT) workers from the Democratic People's Republic of Korea (North Korea). North Korea is evading U.S. and U.N. sanctions by targeting private companies to illicitly generate substantial revenue for the regime. | FBI |
| May 15, 2024 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB24-29) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| May 15, 2024 | CISA | Alert | Adobe Releases Security Updates for Multiple Products Adobe has released security updates to address vulnerabilities in Adobe software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following Adobe Security Bulletins and apply necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 14, 2024 | NCSC | Guidance | Guidance for organisations considering payment in ransomware incidents This guidance has been jointly developed by the insurance industry bodies ABI, BIBA, IUA and the NCSC. It is for organisations experiencing a ransomware attack and the partner organisations supporting them. It aims to minimise the overall impact of a ransomware incident on an disruption and cost to businesses the number of ransoms paid by UK ransomware victims the size of ransoms where victims choose to pay The NCSC and the insurance industry bod… | NCSC-UK |
| May 14, 2024 | CISA | Alert | CISA and Partners Release Guidance for Civil Society Organizations on Mitigating Cyber Threats with Limited Resources The joint guidance provides civil society organizations and individuals with recommended actions and mitigations to reduce the risk of cyber intrusions. Additionally, the guide encourages software manufactures to actively implement and publicly commit to Secure by Design practices that are necessary to help protect vulnerable and high-risk communities. | CISA, DHS, FBI |
| May 14, 2024 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-135-01 Rockwell Automation FactoryTalk Remote Access ICSA-24-135-02 SUBNET PowerSYSTEM Center ICSA-24-135-03 Johnson Controls Software House C-CURE 9000 ICSA-24-135-04 Mitsubishi Electric Multiple FA Engineering Software Products This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 14, 2024 | CISA | Alert | Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 14, 2024 | CISA | Alert | Microsoft Releases May 2024 Security Updates Microsoft has released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisory and apply the necessary updates: Microsoft Security Update Guide for May This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| May 14, 2024 | CERT-EU | Advisory | 2024-039: Critical Putty Client Vulnerability This vulnerability stems from a bias in ECDSA nonce generation when using the NIST P-521 elliptic curve. Attackers can exploit this bias to recover private keys after observing a relatively small PuTTY, when utilising the NIST P-521 elliptic curve, generates ECDSA nonces with the first 9 bits set to zero. | CERT-EU |
| May 13, 2024 | NSA | Analysis Report | CTR: DoD Microelectronics: Field Programmable Gate Array Best Practices – Threat Catalog (May 2024 Update) Cybersecurity Technical Report Best Practices – Threat Catalog National Security Agency | Cybersecurity Technical Report DoD Microelectronics: FPGA Best Practices – Threat Catalog This document was created through collaboration with each of the JFAC labs: National Security Agency (NSA), Air Force Research Lab (AFRL) RYDT, Naval Surface Warfare Center (NSWC) Crane, and Army Development Command (DEVCOM)/AVMC. | NSA |
| May 10, 2024 | CISA | Advisory | #StopRansomware: Black Basta These #StopRansomware advisories include recently and historically observed tactics, Install updates for operating techniques, and procedures (TTPs) and indicators of systems, software, and firmware compromise (IOCs) to help organizations protect against as soon as they are released. | CISA, FBI, HHS, MS-ISAC |
| May 10, 2024 | CISA | Alert | CISA and Partners Release Advisory on Black Basta Ransomware Today, CISA, in partnership with the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released joint Cybersecurity Advisory (CSA) #StopRansomware: Black Basta to provide cybersecurity defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified thr… | CISA, CSA, FBI, HHS, MS-ISAC |
| May 9, 2024 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-130-01 Rockwell Automation FactoryTalk Historian SE ICSA-24-130-02 alpitronic Hypercharger EV Charger ICSA-24-130-03 Delta Electronics InfraSuite Device Master ICSA-24-107-03 Rockwell Automation ControlLogix and GuardLogix (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 9, 2024 | CISA | Alert | ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), together with CISA, the Canadian Centre for Cyber Security (CCCS), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the New Zealand National Cyber Security Centre (NCSC-NZ) are releasing the following guidance: Secure by Design Choosing Secure and Verifiable Technologies . | ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK |
| May 7, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-128-02 SUBNET Substation Server This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 2, 2024 | CISA | Alert | CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate Directory Traversal Vulnerabilities This Alert was crafted in response to recent well-publicized threat actor campaigns that exploited directory traversal vulnerabilities in software (e.g., CVE-2024-1708 , CVE-2024-20345 ) to compromise users of the software—impacting critical infrastructure sectors, including the Healthcare and Public Health Sector. Additionally, this Alert highlights the prevalence, and continued threat actor exploitation of, directory traversal defects. | CISA, FBI |
| May 2, 2024 | NSA | Alert | North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts Department of State, and the National Security Agency malicious activity: (NSA) are jointly issuing this advisory to highlight attempts by Democratic People’s Republic of Korea (DPRK, a.k.a. North Korea) Kimsuky cyber actors to exploit improperly configured DNS Domain-based Message Authentication, configurations found below. Reporting and Conformance (DMARC) record policies to conceal social engineering attempts. | FBI, NSA |
| May 2, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-123-01 CyberPower PowerPanel ICSA-24-123-02 Delta Electronics DIAEnergie ICSA-24-067-01 Chirp Systems Chirp Access (Update C) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 1, 2024 | CISA | Alert | CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity This fact sheet provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists who seek to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors. | CCCS, CISA, MS-ISAC, NCSC-UK, USDA |
| May 1, 2024 | CISA | Alert | CERT/CC Reports R Programming Language Vulnerability A cyber threat actor could exploit this vulnerability to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply the necessary updates: CERT/CC VU#23819 Hidden Layer Blog: R-Bitrary Code Execution--Vulnerability in R’s Deserialization Comprehensive R Archive Network This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 1, 2024 | NSA | Alert | Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity | CCCS, CISA, DOE, EPA, FBI, MS-ISAC, NCSC-UK, NSA, USDA |