|
Jun 28, 2024 |
CISA
|
Alert
|
Progress Software Releases Security Bulletin for MOVEit Transfer
A cyber threat actor could exploit this vulnerability to take control of an affected system. Users and administrators are encouraged to review the following bulletin and apply the necessary updates: MOVEit Transfer Critical Security Alert Bulletin – June 2024 – (CVE-2024-5806) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 28, 2024 |
CERT-EU
|
Advisory
|
2024-064: Vulnerabilities in GitLab
GitLabpipelinesareafeature of the Continuous Integration/Continuous Deployment (CI/CD) system that enables users to automatically run processes and tasks, either in parallel or in sequence, to build, vulnerability could be imported from a project with malicious commit notes. GitLab’s GraphQL API leading to the execution of arbitrary GraphQL mutations. of a private repository in a public project.
|
CERT-EU |
|
Jun 27, 2024 |
CISA
|
Alert
|
CISA Releases Seven Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-179-01 TELSAT marKoni FM Transmitter ICSA-24-179-02 SDG Technologies PnPSCADA ICSA-24-179-03 Yokogawa FAST/TOOLS and CI Server This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 27, 2024 |
CERT-EU
|
Advisory
|
2024-063: Critical Vulnerability in MOVEit Transfer
This vulnerability allows attackers to bypass authentication and access sensitive data [1]. The vulnerability is actively being exploited, and there is an available proof of concept (PoC) The vulnerability CVE-2024-5806, with a CVSS score of 9,1, is an Improper Authentication vulnerability that can lead to Authentication Bypass.
|
CERT-EU |
|
Jun 26, 2024 |
CISA
|
Alert
|
CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects
Today, CISA, in partnership with the Federal Bureau of Investigation, Australian Signals Directorate’s Australian Cyber Security Centre, and Canadian Cyber Security Center, released Exploring Memory Safety in Critical Open Source Projects . This guidance was crafted to provide organizations with findings on the scale of memory safety risk in selected open source software (OSS).
|
ASD/ACSC, CISA, FBI |
|
Jun 25, 2024 |
CISA
|
Alert
|
CISA Releases Two Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-177-01 ABB Ability System 800xA ICSA-24-177-02 PTC Creo Elements/Direct License Server This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 21, 2024 |
CISA
|
Alert
|
Juniper Networks Releases Security Bulletin for Juniper Secure Analytics
A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following and apply the necessary updates: Juniper Security Bulletin JSA82681 This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 20, 2024 |
CISA
|
Alert
|
CISA Releases Guidance on Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: (SMBs)
The report also identifies potential ways to overcome these challenges and improve an SMB’s level of security. CISA also released a related blog post, Why SMBs Don’t Deploy Single Sign-On (SSO) , urging software manufacturers to consider how their business practices may inadvertently reduce the security posture of their customers.
|
CISA |
|
Jun 20, 2024 |
CISA
|
Alert
|
CISA Releases Three Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-172-01 Yokogawa CENTUM ICSA-24-172-02 CAREL Boss-Mini ICSA-24-172-03 Westermo L210-F2G This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 18, 2024 |
CISA
|
Alert
|
CISA and Partners Release Guidance for Modern Approaches to Network Access Security
The guidance urges business owners of all sizes to move toward more robust security solutions—such as Zero Trust, Secure Service Edge (SSE), and Secure Access Service Edge (SASE)—that provide greater visibility of network activity.
|
CISA, FBI |
|
Jun 18, 2024 |
CISA
|
Alert
|
CISA Releases One Industrial Control Systems Advisory
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-170-01 RAD Data Communications SecFlow-2 This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 18, 2024 |
CERT-EU
|
Advisory
|
2024-061: Vulnerabilities in Nextcloud Products
A vulnerability was disclosed in Nextcloud server products that allows the bypassing of the second factor of two-factor authentication (2FA) [1,2]. The vulnerability CVE-2024-37313, with a CVSS score of 7.3, is a 2FA bypass issue.
|
CERT-EU |
|
Jun 18, 2024 |
CERT-EU
|
Advisory
|
2024-060: Vulnerabilities in VMware Products
Exploitation these vulnerabilities could allow a malicious actor to execute remote code or escalate privileges The vulnerabilities CVE-2024-37079 and CVE-2024-37080, both with a CVSS score of 9.8, are heap-overflow vulnerabilities in the DCERPC protocol implementation. An attacker with network access to vCenter Server can exploit these vulnerabilities to execute remote code by sending a specially crafted network packet.
|
CERT-EU |
|
Jun 17, 2024 |
CERT-EU
|
Advisory
|
2024-059: Vulnerability in FortiOS
This vulnerability allows an authenticated attacker to execute unauthorised code or commands via specially crafted command line arguments. The issue arises from multiple stack-based buffer overflow security defects in the command line interpreter.
|
CERT-EU |
|
Jun 13, 2024 |
CISA
|
Alert
|
CISA Releases Twenty Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-165-01 Siemens Mendix Applications ICSA-24-165-02 Siemens SIMATIC S7-200 SMART Devices ICSA-24-165-03 Siemens TIA Administrator ICSA-24-165-04 Siemens ST7 ScadaConnect ICSA-24-165-05 Siemens SITOP UPS1600 ICSA-24-165-06 Siemens TIM 1531 IRC ICSA-24-165-07 Siemens PowerSys ICSA-24-165-08 Siemens Teamcenter Visualization…
|
CISA |
|
Jun 13, 2024 |
CERT-EU
|
Advisory
|
2024-058: Vulnerabilities in PHP
On June 6, 2024, a critical vulnerability was identified in certain versions of PHP that could allow the execution of arbitrary code or disclosure of sensitive information on Windows systems using Apache and PHP-CGI [1]. The vulnerability is currently being actively exploited, and several proof of concepts are available [2]. The vulnerability, identified as CVE-2024-4577. with a CVSS score of 9.3 [3], affects certain PHP versions.
|
CERT-EU |
|
Jun 12, 2024 |
CISA
|
Alert
|
Phone Scammers Impersonating CISA Employees
The Cybersecurity and Infrastructure Security Agency (CISA) is aware of recent impersonation scammers claiming to represent the agency. As a reminder, although CISA staff will occasionally contact organizations with important notifications, CISA staff will never contact you with a request to wire money, cash, cryptocurrency, or use gift cards and will never instruct you to keep the discussion secret.
|
CISA |
|
Jun 12, 2024 |
CERT-EU
|
Advisory
|
2024-057: Vulnerabilities in JetBrains Products
This vulnerability could lead to disclosure of access tokens to The vulnerability, identified as CVE-2024-37051 with a CVSS score of 9.3 [2], affects pull requests within the IntelliJ-based IDEs. Specifically, malicious content included in a pull request to a GitHub project, when handled by IntelliJ-based IDEs, could lead to exposure of access The fixed versions are listed below.
|
CERT-EU |
|
Jun 11, 2024 |
CISA
|
Alert
|
Microsoft Releases June 2024 Security Updates
Microsoft has released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisory and apply the necessary updates: Microsoft Security Update Guide for June This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA, JPCERT/CC |
|
Jun 11, 2024 |
CISA
|
Alert
|
Fortinet Releases Security Updates for FortiOS
Users and administrators are encouraged to review the following Fortinet Security Bulletin and apply the necessary updates: FG-IR-23-460: Multiple Buffer Overflows in Diag Npu Command This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 11, 2024 |
CISA
|
Alert
|
CISA Releases Six Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-163-01 Rockwell Automation ControlLogix, GuardLogix, and CompactLogix ICSA-24-163-02 AVEVA PI Web API ICSA-24-163-03 AVEVA PI Asset Framework Client ICSA-24-163-04 Intrado 911 Emergency Gateway ICSA-23-108-02 Schneider Electric APC Easy UPS Online Monitoring Software (Update A) ICSMA-24-163-01 MicroDicom DICOM Viewer T…
|
CISA |
|
Jun 8, 2024 |
CERT-EU
|
Advisory
|
2024-055: SolarWinds High-Severity Vulnerabilities
CERT-EU strongly recommends patching them as soon as possible. CVE-2024-28995 - SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine [2].
|
CERT-EU |
|
Jun 7, 2024 |
CERT-EU
|
Advisory
|
2024-054: Confluence Data Center and Server Remote Code Execution
This vulnerability allows authenticated attackers with privileges of adding new macro languages to execute arbitrary code. The vulnerability arises from insufficient input validation in the “Add a new language” function within the Configure Code Macro section.
|
CERT-EU |
|
Jun 6, 2024 |
CISA
|
Alert
|
CISA Releases Four Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-158-01 Emerson PACSystem and Fanuc ICSA-24-158-02 Emerson Ovation ICSA-24-158-03 Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch ICSA-24-158-04 Johnson Controls Software House iStar Pro Door Controller This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Jun 4, 2024 |
CISA
|
Alert
|
CISA Releases Four Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-156-01 Uniview NVR301-04S2-P4 ICSA-23-278-03 Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch (Update A) ICSA-22-172-01 Mitsubishi Electric MELSEC iQ-R, Q, L Series and MELIPC Series (Update C) ICSA-24-151-02 Fuji Electric Monitouch V-SFT (Update A) This product is provided subject to this Notification and…
|
CISA |
|
Jun 3, 2024 |
CISA
|
Alert
|
Snowflake Recommends Customers Take Steps to Prevent Unauthorized Access
On June 2, Snowflake indicated a recent increase in cyber threat activity targeting customer accounts on its cloud data platform. Snowflake issued a recommendation for users to query for unusual activity and conduct further analysis to prevent unauthorized user access.
|
CISA |
|
Jun 3, 2024 |
CERT-EU
|
Guidance
|
DDoS Overview and Response Guide
The evolution of DDoS attack techniques and targets has been continuously followed in the past by the specialists ranging from large companies to security expert blogs. However, recently it has caught general attention due to several incidents that might mean a change of paradigm in the way such attacks have been addressed so far. Strategies to mitigate DDoS need to be adopted, and should focus initially on prevention, but eventually on designing multi-layered defense strategies.
|
CERT-EU, NCSC-UK |