| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Jul 30, 2024 | CISA | Alert | DigiCert Certificate Revocations Initial Alert (7:00 p.m., EDT, July 30, 2024): DigiCert, a certificate authority (CA) organization , is revoking a subset of transport layer security (TLS) certificates due to a non-compliance issue with domain control verification (DCV). Revocation of these certificates may cause temporary disruptions to websites, services, and applications relying on these certificates for secure communication. | CISA |
| Jul 30, 2024 | CISA | Alert | Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 29, 2024 | CERT-EU | Advisory | 2024-074: RADIUS Vulnerability Impacts Cisco Products A critical vulnerability, identified as CVE-2024-3596, has been discovered in the RADIUS (Remote Authentication Dial-In User Service) protocol, allowing for man-in-the-middle (MitM) attacks that bypass authentication mechanisms [1]. Dubbed the Blast-RADIUS attack, this vulnerability leverages an MD5 collision attack to forge authentication responses, potentially granting unauthorised access to network resources. | CERT-EU |
| Jul 25, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-207-01 Siemens SICAM Products ICSA-24-207-02 Positron Broadcast Signal Processor This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 25, 2024 | NSA | Advisory | North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs Cyber National Mission Force (CNMF) U.S. Cybersecurity and Infrastructure Security Agency (CISA) U.S. Department of Defense Cyber Crime Center (DC3) U.S. National Security Agency (NSA) Republic of Korea’s National Intelligence Service (NIS) Republic of Korea’s National Police Agency (NPA) United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi… | CISA, CNMF, DC3, FBI, NCSC-UK, NIS, NSA |
| Jul 25, 2024 | CISA | Alert | FBI, CISA, and Partners Release Advisory Highlighting North Korean Cyber Espionage Activity Today, CISA—in partnership with the Federal Bureau of Investigation (FBI)—released a joint Cybersecurity Advisory, North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs . The advisory was coauthored with the following organizations: U.S. Cyber National Mission Force (CNMF); U.S. Department of Defense Cyber Crime Center (DC3); U.S. | CISA, FBI |
| Jul 25, 2024 | NSA | Alert | North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. | CISA, CNMF, DC3, FBI, NCSC-UK, NIS, NSA |
| Jul 24, 2024 | CISA | Alert | ISC Releases Security Advisories for BIND 9 A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition. CVE-2024-4076: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-1975: SIG(0) can be used to exhaust CPU resources CVE-2024-1737: BIND’s database will be slow if a very large number of RRs exist at the same name CVE-2024-0760: A flood of DNS messages over TCP may make the server unstable This product i… | CISA |
| Jul 24, 2024 | CERT-EU | Advisory | 2024-073: Apache HTTP Server Critical Vulnerabilities These vulnerabilities can lead to HTTP request smuggling and SSL client authentication bypass, potentially resulting in unauthorised access and other malicious activities [1]. It is recommended to update affected systems immediately. allows source code disclosure via certain legacy content-type-based configuration settings. | CERT-EU |
| Jul 23, 2024 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-205-01 National Instruments IO Trace ICSA-24-205-02 Hitachi Energy AFS/AFR Series Products ICSA-24-205-03 National Instruments LabVIEW ICSA-22-333-02 Hitachi Energy IED Connectivity Packages and PCM600 Products (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 22, 2024 | CERT-EU | Advisory | 2024-072: Vulnerabilities in Ivanti EPMM These vulnerabilities could lead to remote code execution, authentication bypass, and sensitive information leakage. The vulnerability CVE-2024-36130, with a CVSS score of 9.8, is a flaw (insufficient authorisation checks) in the web component of EPMM that would allow an unauthorised attacker within the network to execute arbitrary commands on the underlying operating system of the The vulnerability CVE-2024-36131, with a CVSS score of 8. | CERT-EU |
| Jul 19, 2024 | CISA | Alert | Widespread IT Outage Due to CrowdStrike Update CrowdStrike has published its Root Cause Analysis (RCA) report . According to CrowdStrike, “the full report elaborates on the information previously shared in our preliminary Post Incident Review (PIR), providing further depth on the findings, mitigations, technical details and root cause analysis of the incident.” CrowdStrike also continues to provide updated information through its remediation and guidance hub . | CISA |
| Jul 19, 2024 | CERT-EU | Advisory | 2024-071: Critical Vulnerabilities in SolarWinds Access Rights Manager These vulnerabilities could lead to remote code execution, arbitrary file deletion and sensitive information leakage. The vulnerabilities CVE-2024-23469, CVE-2024-23466, CVE-2024-23467, CVE-2024-28074, CVE-2024-23471, and CVE-2024-23470, all with a CVSS score of 9.6, could lead to remote code execution if exploited. | CERT-EU |
| Jul 18, 2024 | CERT-EU | Advisory | 2024-010: Vulnerabilities in Netscaler ADS and Netscaler Gateway These vulnerabilities have been actively exploited and require urgent patching [1, 2]. [New] On July 17, The NHS England National Cyber Security Operations Centre announced that new intelligence provided by CrowdStrike indicates that contrary to Citrix’s initial disclosure, the vulnerability CVE-2023-6548 does not require user privileges for exploitation [3]. [Updated] The vulnerability CVE-2023-6548, with a CVSS score of 8. | CERT-EU |
| Jul 18, 2024 | CISA | Alert | Oracle Releases Critical Patch Update Advisory for July 2024 A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 18, 2024 | CISA | Alert | Ivanti Releases Security Updates for Endpoint Manager A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security Advisory Ivanti Endpoint Manager for Mobile (EPMM) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 18, 2024 | CISA | Alert | Cisco Releases Security Updates for Multiple Products Cisco released security updates to address vulnerabilities in Cisco software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Cisco Secure Email Gateway Arbitrary File Write Vulnerability Cisco Smart Software Manager On-Prem Password Change Vulnerability Cisco Secure Web Appliance Privilege Escalation Vulnerability Cisco Identity Services Engine Arbitrary File Upload Vulnerability Cisco Inte… | CISA |
| Jul 18, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-200-01 Mitsubishi Electric MELSOFT MaiLab ICSA-24-200-02 Subnet Solutions PowerSYSTEM Center ICSMA-24-200-01 Philips Vue PACS This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 18, 2024 | CERT-EU | Advisory | 2024-070: Critical Vulnerabilities in Cisco Products It is strongly recommended applying update on affected devices as soon as possible, prioritising internet facing and business critical devices. The critical vulnerability CVE-2024-20401, with a CVSS score of 9.8, is an arbitrary file write flaw [1]. | CERT-EU |
| Jul 16, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 15, 2024 | CERT-EU | Advisory | 2024-069: Vulnerabilities in Citrix Netscaler The vulnerability CVE-2024-6235, with a CVSS score of 9.4 out of 10, can lead to sensitive information disclosure. This vulnerability arises from an improper authentication mechanism in the Citrix NetScaler Console. | CERT-EU |
| Jul 12, 2024 | CISA | Alert | AT&T Discloses Breach of Customer Data AT&T also provided recommendations and resources for affected customers. AT&T: Unlawful access of customer data This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 12, 2024 | CERT-EU | Advisory | 2024-067: Multiple Vulnerabilities in Microsoft Products On July 10, 2024, Microsoft addressed 139 vulnerabilities in its July 2024 Patch Tuesday update,includingfourzero-dayvulnerabilities. Additionally, five critical vulnerabilities leading to Remote Code Execution have been It is recommended updating as soon as possible. The zero-day vulnerability CVE-2024-38080, with a CVSS score of 7. | CERT-EU |
| Jul 11, 2024 | CISA | Alert | CISA Releases Advisory Detailing Red Team Activity During Assessment of US FCEB Organization, Highlighting Necessity of Defense-in-Depth Today, CISA released CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth in coordination with the assessed organization. This Cybersecurity Advisory (CSA) details key findings and lessons learned from a 2023 assessment, along with the red team’s tactics, techniques, and procedures (TTPs) and associated network defense activity. | CISA, CSA |
| Jul 11, 2024 | CISA | Alert | CISA Releases Twenty-one Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-193-01 Siemens Remote Connect Server ICSA-24-193-02 Siemens RUGGEDCOM APE 1808 ICSA-24-193-03 Siemens Teamcenter Visualization and JT2Go ICSA-24-193-04 Siemens Simcenter Femap ICSA-24-193-05 Siemens SCALANCE, RUGGEDCOM, SIPLUS, and SINEC ICSA-24-193-06 Siemens RUGGEDCOM ICSA-24-193-07 Siemens SIMATIC and SIMIT ICSA-24-… | CISA |
| Jul 11, 2024 | CISA | Advisory | CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth During SILENTSHIELD assessments, the red team first performs a no-notice, long-term simulation of nation-state cyber operations. The team mimics the techniques, tradecraft, and behaviors of sophisticated threat actors and measures the potential dwell time actors have on a network, providing a realistic assessment of the organization’s security posture. | CISA, CSA |
| Jul 11, 2024 | CERT-EU | Advisory | 2024-068: Critical Vulnerabilities in GeoServer and GeoTools These vulnerabilities can result in arbitrary code execution through the unsafe evaluation of user-supplied XPath expressions [1,2,3]. The vulnerability CVE-2024-36401, with a CVSS score of 9.8, allows Remote Code Execution (RCE) flaw by unauthenticated users via specially crafted input to a default GeoServer installation. | CERT-EU |
| Jul 10, 2024 | CISA | Alert | CISA and FBI Release Secure by Design Alert on Eliminating OS Command Injection Vulnerabilities These vulnerabilities allowed unauthenticated malicious actors to remotely execute code on network edge devices. OS command injection vulnerabilities have long been preventable by clearly separating user input from the contents of a command. | CISA, FBI |
| Jul 9, 2024 | CISA | Alert | Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security Updates Available for Adobe Premiere Pro | APSB24-46 Security Update Available for Adobe InDesign | APSB24-48 Security Updates Available for Adobe Bridge | APSB24-51 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 9, 2024 | CISA | Alert | Citrix Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. NetScaler ADC and NetScaler Gateway Security Update for CVE-2024-5491 and CVE-2024-5492 NetScaler Console, Agent and SVM Security Update for CVE-2024-6235 and CVE-2024-6236 Citrix Workspace app for HTML5 Security Bulletin CVE-2024-6148 and CVE-2024-6149 Citrix Provisioning Security Bulletin CVE-2024-6150 Windows Virtual Delivery Agent for CVAD… | CISA |
| Jul 9, 2024 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-191-01 Delta Electronics CNCSoft-G2 ICSA-24-191-02 Mitsubishi Electric MELIPC Series MI5122-VW ICSA-24-191-04 Johnson Controls Software House C●CURE 9000 ICSA-24-191-05 Johnson Controls Software House C●CURE 9000 ICSA-24-177-02 PTC Creo Elements/Direct License Server (Update A) ICSA-23-269-03 Mitsubishi Electric FA Eng… | CISA |
| Jul 9, 2024 | FBI | Alert | State-Sponsored Russian Media Leverages Meliorator Software for Foreign Malign Influence Activity Affiliates of RT (formerly Russia Today), a Russian state-sponsored media organization, used Meliorator—a covert artificial intelligence (AI) enhanced software package—to create fictitious online personas, representing a number of nationalities, to post content on X (formerly Twitter). | AIVD, CCCS, CNMF, FBI, MIVD |
| Jul 9, 2024 | CERT-EU | Advisory | 2024-066: Critical Vulnerability in OpenSSH This vulnerability, identified as CVE-2024-6387, allows remote attackers to execute arbitrary code as root due to a signal handler race condition in sshd [1]. This vulnerability, if exploited, could lead to full-system compromise, where an attacker can execute arbitrary code with the highest privileges, resulting in a complete system takeover, installation of malware, data manipulation, and the creation of backdoors for persistent access. | CERT-EU |
| Jul 9, 2024 | CISA | Alert | Microsoft Releases July 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for July This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Jul 8, 2024 | CISA | Alert | CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40 CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity. | ASD/ACSC, CISA |
| Jul 8, 2024 | NSA | Advisory | People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally. | ASD/ACSC, BND, CCCS, CISA, FBI, NCSC-NZ, NCSC-UK, NIS, NISC, NPA, NSA |
| Jul 8, 2024 | NSA | Advisory | APT40 Advisory: PRC MSS Tradecraft in Action Background The following Advisory provides a sample of significant case studies of this adversary’s techniques in action This advisory, authored by the Australian Signals against two victim networks. The case studies are Directorate’s Australian Cyber Security Centre consequential for cybersecurity practitioners to identify, (ASD’s ACSC), the United States Cybersecurity and prevent and remediate APT40 intrusions against their Infrastructure Secur… | ASD/ACSC, CCCS, FBI, NCSC-NZ, NCSC-UK, NIS, NPA, NSA |
| Jul 2, 2024 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-184-01 Johnson Controls Kantech Door Controllers ICSA-24-184-03 ICONICS and Mitsubishi Electric Products ICSA-24-179-04 Johnson Controls Illustra Essentials Gen 4 (Update A) ICSA-24-179-05 Johnson Controls Illustra Essentials Gen 4 (Update A) ICSA-24-179-06 Johnson Controls Illustra Essentials Gen 4 (Update A) ICSA-24-… | CISA |
| Jul 2, 2024 | CISA | Alert | Juniper Networks Releases Security Bulletin for Junos OS: SRX Series A cyber threat actor could exploit this vulnerability to cause a denial-of-service condition. Users and administrators are encouraged to review the following and apply the necessary updates: JSA83195 Juniper Security Bulletin This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 1, 2024 | CERT-EU | Advisory | 2024-065: Critical Vulnerability in Juniper Networks Products This vulnerability allows an attacker to bypass authentication and gain full control of the device, primarily affecting high-availability redundant configurations [1]. The vulnerability, CVE-2024-2973, is an authentication bypass using an alternate path or channel. | CERT-EU |