CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ October 2024 ›
39 publications — sorted newest first
Date Source Type Title Author
Oct 31, 2024 CISA Alert Foreign Threat Actor Conducting Large-Scale Spearphishing Campaign with RDP Attachments The foreign threat actor, often posing as a trusted entity, is sending spearphishing emails containing malicious remote desktop protocol (RDP) files to targeted organizations to connect to and access files stored on the target’s network. Once access has been gained, the threat actor may pursue additional activity, such as deploying malicious code to achieve persistent access to the target’s network. CISA
Oct 31, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-305-01 Rockwell Automation FactoryTalk ThinManager ICSA-24-030-02 Mitsubishi Electric FA Engineering Software Products (Update A) ICSA-24-135-04 Mitsubishi Electric Multiple FA Engineering Software Products (Update A) ICSA-23-157-02 Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series (Update B) This product is provided… CISA
Oct 31, 2024 CERT-EU Advisory 2024-115: QNAP NAS Zero-Day Vulnerabilities These vulnerabilities allow remote attackers to gain root access and execute arbitrary commands on compromised devices The vulnerability CVE-2024-50387 in QNAP’s SMB service could allow remote attackers to exploit the NAS system and potentially gain a root shell [1,3]. The vulnerability CVE-2024-50388 could allow remote attackers to execute arbitrary commands on affected devices [2,4]. CERT-EU
Oct 30, 2024 CISA Alert Fortinet Updates Guidance and Indicators of Compromise following FortiManager Vulnerability Exploitation Fortinet has updated their security advisory addressing a critical FortiManager vulnerability (CVE-2024-47575) to include additional workarounds and indicators of compromise (IOCs). A remote, unauthenticated cyber threat actor could exploit this vulnerability to gain access to sensitive files or take control of an affected system. CISA
Oct 29, 2024 CISA Alert JCDC’s Industry-Government Collaboration Speeds Mitigation of CrowdStrike IT Outage CISA, through the Joint Cyber Defense Collaborative (JCDC), enabled swift, coordinated response and information sharing in the wake of a significant IT outage caused by a CrowdStrike software update. This outage, which impacted government, critical infrastructure, and industry across the globe, led to disruptions in essential services, including air travel, healthcare, and financial operations. CISA
Oct 29, 2024 CISA Alert Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 29, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-303-01 Siemens InterMesh Subscriber Devices ICSA-24-303-03 Delta Electronics InfraSuite Device Master This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 25, 2024 CERT-EU Advisory 2024-114: Multiple Critical CISCO Vulnerabilities These vulnerabilities can potentially allow attackers to conduct various types of attacks, including command injection, remote command execution, arbitrary command execution, and unauthorised access through static credentials due to improper input validation or insecure handling of web services components. CERT-EU, USDA
Oct 24, 2024 CISA Alert Cisco Releases Security Bundle for Cisco ASA, FMC, and FTD Software A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Cisco Event Response: October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 24, 2024 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-298-01 VIMESA VHF/FM Transmitter Blue Plus ICSA-24-298-02 iniNet Solutions SpiderControl SCADA PC HMI Editor ICSA-24-298-03 Deep Sea Electronics DSE855 ICSA-24-268-06 OMNTEC Proteus Tank Monitoring (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 24, 2024 CISA Alert CISA, US, and International Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes This guide aids software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC). ASD/ACSC, CISA, FBI
Oct 24, 2024 CERT-EU Advisory 2024-113: Critical 0-day Vulnerability in Fortinet FortiManager If exploited, a remote unauthenticated attacker could execute arbitrary code or commands on the affected device [1]. When not possible, it is recommended applying the workaround. CERT-EU
Oct 22, 2024 CERT-EU Advisory 2024-100: Critical RCE Vulnerability in VMware vCenter Server Following this, on October 21, 2024, Broadcom updated their advisory [2] with additional information about another related vulnerability tracked as CVE2024-38813. This allows an unauthenticated attacker to remotely execute arbitrary code without user interaction. via specially crafted network packets. CERT-EU
Oct 22, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-296-01 ICONICS and Mitsubishi Electric Products This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 17, 2024 CISA Alert Oracle Releases Quarterly Critical Patch Update Advisory for October 2024 A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 17, 2024 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-291-01 Elvaco M-Bus Metering Gateway CMe3100 ICSA-24-291-02 LCDS LAquis SCADA ICSA-24-291-03 Mitsubishi Electric CNC Series ICSA-24-291-05 Kieback&Peter DDC4000 Series ICSA-24-270-04 goTenna Pro X and Pro X2 (Update A) ICSA-24-270-05 goTenna Pro ATAK Plugin (Update A) This product is provided subject to this Notificati… CISA
Oct 17, 2024 CERT-EU Advisory 2024-112: Critical Vulnerability in Kubernetes It is recommended updating the Kubernetes Image Builder, and redeploying or mitigating Virtual Machines (VMs) created by the vulnerable Kubernetes Image Builder. The flaw affects Kubernetes Image Builder version 0.1.37 and earlier. CERT-EU
Oct 16, 2024 NSA Alert CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations Using Brute Force This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors to impact organizations across multiple critical infrastructure sectors. Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations in the healthcare and public health (HPH), government, information technology, engineering, and energy s… CISA, FBI, NSA
Oct 16, 2024 NSA Advisory Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations Summary The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) are releasing this joint Cybersecurity Advisory to warn network defenders of Iranian cyber actors’ use of brute force and othe… AFP, ASD/ACSC, CCCS, CISA,
CSE, FBI, NIST, NSA
Oct 16, 2024 CISA Alert CISA and FBI Release Joint Guidance on Product Security Bad Practices for Public Comment This joint guidance supplies an overview of exceptionally risky product security bad practices for software manufacturers who produce software in support of critical infrastructure or national critical functions. The bad practices presented in this guidance are organized into three categories: product properties, security features, and organizational processes and policies. CISA, FBI
Oct 16, 2024 NCSC Guidance Guidance on effective communications in a cyber incident Cyber security incidents affect UK organisations every week, so it’s important to During an incident, organisations often prioritise their technical response and relegate communication to a secondary consideration. But effective communication to staff, stakeholders, customers and the media is crucial for shaping how an organisation is perceived. NCSC-UK
Oct 16, 2024 CERT-EU Advisory 2024-111: Multiple Vulnerabilities in Splunk Enterprise and Splunk Cloud These vulnerabilities could lead to arbitrary file write to Windows system root directory, access to potentially restricted data and remote code execution [1,2]. ThevulnerabilityCVE-2024-45733,withaCVSSscoreof8.8,couldallowalow-privilegeduser that does not hold the “admin” or “power” Splunk roles to perform a Remote Code Execution (RCE) due to an insecure session storage configuration. CERT-EU
Oct 16, 2024 CERT-EU Advisory 2024-110: Critical Vulnerability in Ivanti Products On October 8, 2024, Ivanti addressed a critical vulnerability in Ivanti Connect Secure and Ivanti Policy Secure. CERT-EU
Oct 15, 2024 CISA Alert Guidance: Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM) CISA’s community-driven working groups publish documents and reports to advance and refine SBOM and ultimately promote adoption. This resource serves as the detailed foundation of SBOM, defining SBOM concepts and related terms and offering an updated baseline of how software components are to be represented. This document serves as a guide on the processes around SBOM creation. CISA
Oct 15, 2024 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-289-01 Siemens Siveillance Video Camera ICSA-24-289-02 Schneider Electric Data Center Expert This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 11, 2024 CERT-EU Advisory 2024-109: Critical vulnerabilities in Gitlab It is recommended updating affected assets as soon as possible. The vulnerability CVE-2024-9164, with a CVSS score of 9.6, allows unauthorised users to execute pipelines on branches without appropriate permission, leading to unauthorised code execution. CERT-EU
Oct 11, 2024 CERT-EU Advisory 2024-108: Palo Alto Critical Vulnerabilities The vulnerabilities allow attackers to execute arbitrary commands, read or write files, and exploit SQL injection flaws. Successful exploitation could result in a full In the /var/apache/log/access.log file, anomalous calls to the following endpoints might indicate abuse of these vulnerabilities: It is recommended to upgrade to Expedition 1.2.96 or later to mitigate these vulnerabilities. CERT-EU
Oct 11, 2024 CERT-EU Advisory 2024-107: Critical Vulnerability in Firefox The vulnerability CVE-2024-9680, with a CVSS score 7.5, could allow an attacker to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. The Mozilla Foundation had reports of this vulnerability being exploited in the wild. CERT-EU
Oct 10, 2024 CISA Alert CISA Releases Twenty-One Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-284-01 Siemens SIMATIC S7-1500 and S7-1200 CPUs ICSA-24-284-02 Siemens Simcenter Nastran ICSA-24-284-03 Siemens Teamcenter Visualization and JT2Go ICSA-24-284-04 Siemens SENTRON PAC3200 Devices ICSA-24-284-05 Siemens Questa and ModelSim ICSA-24-284-06 Siemens SINEC Security Monitor ICSA-24-284-08 Siemens HiMed Cockpit… CISA
Oct 10, 2024 CISA Alert Best Practices to Configure BIG-IP LTM Systems to Encrypt HTTP Persistence Cookies CISA has observed cyber threat actors leveraging unencrypted persistent cookies managed by the F5 BIG-IP Local Traffic Manager (LTM) module to enumerate other non-internet facing devices on the network. F5 BIG-IP is a suite of hardware and software solutions designed to manage and secure network traffic. CISA
Oct 10, 2024 NSA Alert Update on SVR Cyber Operations and Vulnerability Exploitation The Federal Bureau of Investigation (FBI), the The authoring agencies recommend the following mitigations to protect their networks. Mission Force (CNMF), and the United See the Mitigations section for the complete Kingdom’s National Cyber Security Centre (NCSC-UK) are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, • Reduce attack surface by disabling techniques, and procedures (TTPs) employed by Internet-accessible s… CNMF, FBI, NCSC-UK, NSA
Oct 9, 2024 CERT-EU Advisory 2024-106: Multiple Critical Vulnerabilities in Microsoft Products This Patch Tuesday also fixes three critical We highlight here the zero-day vulnerabilities, but it is highly recommended to deploy Microsoft patches for all 118 vulnerabilities identified. The vulnerability CVE-2024-43573, with a CVSS score 6.5, could be a bypass of a previous vulnerability that abused MSHTML to spoof file extensions in alerts displayed when opening The vulnerability CVE-2024-43572, with a CVSS score 7. CERT-EU
Oct 8, 2024 CISA Alert Microsoft Releases October 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for October This product is provided subject to this Notification and this Privacy & Use policy. CISA, JPCERT/CC
Oct 8, 2024 CISA Alert Avoid Scams After Disaster Strikes Federal Trade Commission’s Staying Alert to Disaster-related Scams and Before Giving to a Charity , Consumer Financial Protection Bureau's Frauds and Scams , FEMA's Disaster Fraud guidance , and CISA’s Phishing Guidance, Stopping the Attack Cycle at Phase One to help organizations reduce likelihood and impact of successful phishing attacks. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 8, 2024 CISA Alert CISA and FBI Release Fact Sheet on Protecting Against Iranian Targeting of Accounts Associated with National Political Organizations This fact sheet provides information about threat actors affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps (IRGC) targeting and compromising accounts of Americans to stoke discord and undermine confidence in U.S. democratic institutions. IRGC actors have previously gained and continue to seek access to personal and business accounts using social engineering techniques by targeting victims across email and chat. CISA, FBI
Oct 8, 2024 CISA Alert Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security update available for Adobe Substance 3D Printer| APSB24-52 Security update available for Adobe Commerce and Magento Open Source | APSB24-73 Security update available for Adobe Dimension | APSB24-74 Security update available for Adobe Animate | APSB24-76 Security update available for Adobe Lightroom | APSB24-78 Security update available… CISA
Oct 3, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-277-01 TEM Opera Plus FM Family Transmitter ICSA-24-277-02 Subnet Solutions Inc. PowerSYSTEM Center ICSA-24-277-03 Delta Electronics DIAEnergie This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 1, 2024 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-275-01 Optigo Networks ONS-S8 Spectra Aggregation Switch ICSA-24-275-02 Mitsubishi Electric MELSEC iQ-F FX5-OPC This product is provided subject to this Notification and this Privacy & Use policy. CISA
Oct 1, 2024 CISA Alert ASD’s ACSC, CISA, FBI, NSA, and International Partners Release Guidance on Principles of OT Cybersecurity for Critical Infrastructure Organizations Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)—in partnership with CISA, U.S. government and international partners—released the guide Principles of Operational Technology Cybersecurity . This guidance provides critical information on how to create and maintain a safe, secure operational technology (OT) environment. ASD/ACSC, CISA