CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ May 2024 ›
39 publications — sorted newest first
Date Source Type Title Author
May 30, 2024 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-151-02 Fuji Electric Monitouch V-SFT ICSA-24-151-03 Inosoft VisiWin ICSA-24-151-04 Westermo EDW-100 ICSA-22-356-03 Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series (Update C) ICSMA-24-151-01 Baxter Welch Allyn Configuration Tool ICSMA-24-151-02 Baxter Welch Allyn Connex Spot Monitor This product is provid… CISA
May 30, 2024 CERT-EU Advisory 2024-053: Zero-day Vulnerability in Check Point Security Gateways This high-severity information disclosure vulnerability can be exploited to gain unauthorised access to sensitive information on systems with remote Access VPN or Mobile Access Software Blades enabled [1]. It is recommended applying the hotfix and the extra protection measures provided by the vendor Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed C… CERT-EU
May 28, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-149-01 Campbell Scientific CSI Web Server This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 28, 2024 CERT-EU Advisory 2024-052: Vulnerability in Cisco FMC Software If exploited, this vulnerability could allow an attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. The vulnerability CVE-2024-20360 [1], with a CVSS score of 8.8, lies in the web-based management interface of Cisco Firepower Management Center (FMC) Software. CERT-EU, FMC
May 27, 2024 CERT-EU Advisory 2024-051: Vulnerabilities in GitLab On May 22, GitLab has released several versions for GitLab Community Edition (CE) and Enterprise Edition (EE) containing important bug and security fixes [1]. These fixes notably address a vulnerability that would allow an attacker to take accounts over via an XSS vulnerability. It is strongly recommended upgrading affected versions to the latest version as soon as possible. CERT-EU
May 24, 2024 CISA Alert Cisco Releases May 2024 Cisco ASA, FMC, and FTD Software Security Publication Cisco released a bundled publication for security advisories that address vulnerabilities in Cisco Adaptive Security Appliance (ASA), Firepower Management Center (FMC), and Firepower Threat Defense (FTD) software. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. CISA
May 23, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-144-01 AutomationDirect Productivity PLCs This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 22, 2024 CERT-EU Advisory 2024-046: Multiple Vulnerabilities in Git These vulnerabilities could allow for remote code execution and unauthorised file modifications. The vulnerability CVE-2024-32002 , with a CVSS score of 9.1, could allow a remote attacker to execute code on the affected device. CERT-EU
May 22, 2024 CERT-EU Advisory 2024-047: Critical Vulnerability in GitHub Enterprise Server OnMay 21, 2024, GitHubdisclosed acriticalvulnerability inGitHubEnterprise Server(GHES) impacting instances using SAML single sign-on (SSO) with encrypted assertions. This vulnerability allows attackers to forge SAML responses, granting unauthorised administrative access A proof of concept is publicly available. CERT-EU
May 22, 2024 CERT-EU Advisory 2024-048: Critical Vulnerability in Veeam Backup Enterprise Manager The vulnerability CVE-2024-29849, with a CVSS score of 9.8, could allow an unauthenticated attacker to login into the Veeam Backup Enterprise Manager web interface as any user. The flaw lies in the authentication mechanism of the web interface. CERT-EU
May 22, 2024 CERT-EU Advisory 2024-049: Multiple Vulnerabilities in QNAP Products These vulnerabilities could allow remote attackers to execute arbitrary code. It is strongly advised updating affected systems to the latest versions to mitigate these risks. CERT-EU
May 22, 2024 CERT-EU Advisory 2024-050: Multiple Vulnerabilities in Ivanti EPMM An attacker could exploit these flaws to execute arbitrary commands on the appliance. It is strongly advised updating affected systems to the latest versions to mitigate these risks. CERT-EU
May 22, 2024 NSA Guidance CSI: Advancing Zero Trust Maturity Throughout the Application and Workload Pillar Information Technology (IT) professionals are keenly aware of the security challenges facing applications, but workloads are every bit as important to consider in this domain. Workloads represent computational tasks, which encompass multiple programs or applications performing those tasks by utilizing computing, data, networking, and storage resources. CISA, NSA, NSM
May 21, 2024 CISA Alert Rockwell Automation Encourages Customers to Assess and Secure Public-Internet-Exposed Assets Rockwell Automation has released guidance encouraging users to remove connectivity on all Industrial Control Systems (ICS) devices connected to the public-facing internet to reduce exposure to unauthorized or malicious cyber activity. CISA
May 21, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-142-01 LCDS LAquis SCADA This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 16, 2024 CISA Alert CISA Releases Seventeen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-137-01 Siemens Parasolid ICSA-24-137-02 Siemens SICAM Products ICSA-24-137-03 Siemens Teamcenter Visualization and JT2Go ICSA-24-137-04 Siemens Polarion ALM ICSA-24-137-05 Siemens Simcenter Nastran ICSA-24-137-06 Siemens SIMATIC CN 4100 Before V3. CISA
May 16, 2024 CISA Alert Cisco Releases Security Updates for Multiple Products Cisco has released security updates to address vulnerabilities in Cisco software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply necessary updates: • Cisco Crosswork Network Services Orchestrator • Cisco Crosswork Network Services Orchestrator Privilege Escalation • ConfD CLI Privilege Escalation and Arbitr… CISA
May 16, 2024 CERT-EU Advisory 2024-044: Zero-day Vulnerability in Chrome It has been reported that this vulnerability is beingactivelyexploited[1]. Google Chrome prior to version 125.0.6422.60/.61 for Windows and Mac, 125.0.6422.60 for Linuxareimpacted[1]. CERT-EU
May 16, 2024 FBI Alert Democratic People's Republic of Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue The Federal Bureau of Investigation (FBI) is warning the public and private sector of the threat posed to U.S. businesses by information technology (IT) workers from the Democratic People's Republic of Korea (North Korea). North Korea is evading U.S. and U.N. sanctions by targeting private companies to illicitly generate substantial revenue for the regime. FBI
May 15, 2024 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB24-29) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
May 15, 2024 CISA Alert Adobe Releases Security Updates for Multiple Products Adobe has released security updates to address vulnerabilities in Adobe software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following Adobe Security Bulletins and apply necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 14, 2024 NCSC Guidance Guidance for organisations considering payment in ransomware incidents This guidance has been jointly developed by the insurance industry bodies ABI, BIBA, IUA and the NCSC. It is for organisations experiencing a ransomware attack and the partner organisations supporting them. It aims to minimise the overall impact of a ransomware incident on an disruption and cost to businesses the number of ransoms paid by UK ransomware victims the size of ransoms where victims choose to pay The NCSC and the insurance industry bod… NCSC-UK
May 14, 2024 CISA Alert CISA and Partners Release Guidance for Civil Society Organizations on Mitigating Cyber Threats with Limited Resources The joint guidance provides civil society organizations and individuals with recommended actions and mitigations to reduce the risk of cyber intrusions. Additionally, the guide encourages software manufactures to actively implement and publicly commit to Secure by Design practices that are necessary to help protect vulnerable and high-risk communities. CISA, DHS, FBI
May 14, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-135-01 Rockwell Automation FactoryTalk Remote Access ICSA-24-135-02 SUBNET PowerSYSTEM Center ICSA-24-135-03 Johnson Controls Software House C-CURE 9000 ICSA-24-135-04 Mitsubishi Electric Multiple FA Engineering Software Products This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 14, 2024 CISA Alert Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply necessary updates: This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 14, 2024 CISA Alert Microsoft Releases May 2024 Security Updates Microsoft has released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisory and apply the necessary updates: Microsoft Security Update Guide for May This product is provided subject to this Notification and this Privacy & Use policy. CISA, JPCERT/CC
May 14, 2024 CERT-EU Advisory 2024-039: Critical Putty Client Vulnerability This vulnerability stems from a bias in ECDSA nonce generation when using the NIST P-521 elliptic curve. Attackers can exploit this bias to recover private keys after observing a relatively small PuTTY, when utilising the NIST P-521 elliptic curve, generates ECDSA nonces with the first 9 bits set to zero. CERT-EU
May 13, 2024 NSA Analysis Report CTR: DoD Microelectronics: Field Programmable Gate Array Best Practices – Threat Catalog (May 2024 Update) Cybersecurity Technical Report Best Practices – Threat Catalog National Security Agency | Cybersecurity Technical Report DoD Microelectronics: FPGA Best Practices – Threat Catalog This document was created through collaboration with each of the JFAC labs: National Security Agency (NSA), Air Force Research Lab (AFRL) RYDT, Naval Surface Warfare Center (NSWC) Crane, and Army Development Command (DEVCOM)/AVMC. NSA
May 10, 2024 CISA Advisory #StopRansomware: Black Basta These #StopRansomware advisories include recently and historically observed tactics,  Install updates for operating techniques, and procedures (TTPs) and indicators of systems, software, and firmware compromise (IOCs) to help organizations protect against as soon as they are released. CISA, FBI, HHS, MS-ISAC
May 10, 2024 CISA Alert CISA and Partners Release Advisory on Black Basta Ransomware Today, CISA, in partnership with the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released joint Cybersecurity Advisory (CSA) #StopRansomware: Black Basta to provide cybersecurity defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified thr… CISA, CSA, FBI, HHS,
MS-ISAC
May 9, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-130-01 Rockwell Automation FactoryTalk Historian SE ICSA-24-130-02 alpitronic Hypercharger EV Charger ICSA-24-130-03 Delta Electronics InfraSuite Device Master ICSA-24-107-03 Rockwell Automation ControlLogix and GuardLogix (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 9, 2024 CISA Alert ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), together with CISA, the Canadian Centre for Cyber Security (CCCS), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the New Zealand National Cyber Security Centre (NCSC-NZ) are releasing the following guidance: Secure by Design Choosing Secure and Verifiable Technologies . ASD/ACSC, CCCS, CISA, NCSC-NZ,
NCSC-UK
May 7, 2024 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-128-02 SUBNET Substation Server This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 2, 2024 CISA Alert CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate Directory Traversal Vulnerabilities This Alert was crafted in response to recent well-publicized threat actor campaigns that exploited directory traversal vulnerabilities in software (e.g., CVE-2024-1708 , CVE-2024-20345 ) to compromise users of the software—impacting critical infrastructure sectors, including the Healthcare and Public Health Sector. Additionally, this Alert highlights the prevalence, and continued threat actor exploitation of, directory traversal defects. CISA, FBI
May 2, 2024 NSA Alert North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts Department of State, and the National Security Agency malicious activity: (NSA) are jointly issuing this advisory to highlight attempts by Democratic People’s Republic of Korea (DPRK, a.k.a. North Korea) Kimsuky cyber actors to exploit improperly configured DNS Domain-based Message Authentication, configurations found below. Reporting and Conformance (DMARC) record policies to conceal social engineering attempts. FBI, NSA
May 2, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-123-01 CyberPower PowerPanel ICSA-24-123-02 Delta Electronics DIAEnergie ICSA-24-067-01 Chirp Systems Chirp Access (Update C) This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 1, 2024 CISA Alert CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity This fact sheet provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists who seek to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors. CCCS, CISA, MS-ISAC, NCSC-UK,
USDA
May 1, 2024 CISA Alert CERT/CC Reports R Programming Language Vulnerability A cyber threat actor could exploit this vulnerability to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply the necessary updates: CERT/CC VU#23819 Hidden Layer Blog: R-Bitrary Code Execution--Vulnerability in R’s Deserialization Comprehensive R Archive Network This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 1, 2024 NSA Alert Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity CCCS, CISA, DOE, EPA,
FBI, MS-ISAC, NCSC-UK, NSA,
USDA