| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Jan 31, 2024 | CISA | Alert | CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers Today, CISA and the Federal Bureau of Investigation (FBI) published guidance on Security Design Improvements for SOHO Device Manufacturers as a part of the new Secure by Design (SbD) Alert series that focuses on how manufacturers should shift the burden of security away from customers by integrating security into product design and development. | CISA, FBI |
| Jan 31, 2024 | FBI | Alert | Malicious Cyber Actors Exploiting Insecure SOHO Routers Security Design Improvements for Threat actors—particularly the People’s Republic of China (PRC)—sponsored Volt Typhoon group—are compromising small office/home office (SOHO) routers by including the Volt Typhoon group, exploiting software defects that manufacturers must eliminate through secure have made headlines by exploiting software design and development. | FBI |
| Jan 30, 2024 | CISA | Alert | Updated: New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways On Feb. 14, 2024, Ivanti released new software updates for Ivanti Connect Secure and Ivanti Policy Secure. An newly disclosed XML external entity injection (XXE) vulnerability (CVE-2024-22024) affecting: Connect Secure supported versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2 Policy Secure supported versions 22.5R1.1 and ZTA version 22.6R1.3 Connect Secure supported versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1. | CISA |
| Jan 30, 2024 | CISA | Alert | CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-030-01 Emerson Rosemount GC370XA, GC700XA, GC1500XA ICSA-24-030-02 Mitsubishi Electric FA Engineering Software Products ICSA-24-030-03 Mitsubishi Electric MELSEC WS Series Ethernet Interface Module ICSA-24-030-04 Hitron Systems Security Camera DVR ICSA-24-030-05 Rockwell Automation ControlLogix and GuardLogix ICSA-24-0… | CISA |
| Jan 30, 2024 | CERT-EU | Advisory | 2024-014: Critical Remote Code Execution Vulnerability in Jenkins The advisory published provides detailed information on various attack scenarios, exploitation pathways, descriptions of the fixes, and potential workarounds for those unable to immediately Multiple proof-of-concept (PoC) exploits for CVE-2024-23897 are now available [2]. The vulnerability CVE-2024-23897, with a CVSS score of 9. | CERT-EU |
| Jan 29, 2024 | CISA | Alert | Juniper Networks Releases Security Bulletin for J-Web in Junos OS SRX Series and EX Series A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 29, 2024 | CERT-EU | Advisory | 2024-015: Remote Code Execution Vulnerability in Cisco Products This vulnerability, tracked as CVE-2024-20253 with a CVSS score of 9.9, could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. Currently, Cisco has no evidence of public proof of concept exploits for this vulnerability or active exploitation in the wild. | CERT-EU |
| Jan 26, 2024 | CISA | Alert | Guidance: Assembling a Group of Products for SBOM CISA’s community-driven working groups publish documents and reports to advance and refine SBOM and ultimately promote adoption. Specifically, software producers often need to assemble and test products together before releasing them to customers. These products may contain components that experience version changes over time, therefore creating a need to be tracked. | CISA |
| Jan 25, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-025-01 MachineSense FeverWarn ICSA-24-025-02 SystemK NVR 504/508/516 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 25, 2024 | CISA | Alert | Cisco Releases Security Advisory for Multiple Unified Communications and Contact Center Solutions Products A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 24, 2024 | CISA | Alert | Mozilla Releases Security Updates for Thunderbird and Firefox A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 24, 2024 | NCSC | Analysis Report | The near-term impact of AI on the cyber threat During the Bletchley AI Safety Summit in November 2023, international leaders came together to discuss the vast potential of AI models in promoting economic growth, propelling scientific advances, and providing a wide range of public benefits. They also underscored the security risks that could arise from the irresponsible development and use of AI technologies. | NCSC-UK |
| Jan 24, 2024 | CERT-EU | Advisory | 2024-013: Zero-Day Vulnerability in Apple Products This vulnerability affects iOS, iPadOS, macOS and tvOS devices and is currently being exploited in the wild [2]. The updates also contain fixes for other vulnerabilities It is recommended updating as soon as possible. | CERT-EU |
| Jan 23, 2024 | NSA | Guidance | CSI: Engaging with Artificial Intelligence The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk. | ASD/ACSC, BSI, CCCS, CISA, CSA, FBI, NCSC-NZ, NCSC-UK, NSA |
| Jan 23, 2024 | CISA | Alert | Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 23, 2024 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-023-01 APsystems Energy Communication Unit (ECU-C) Power Control Software ICSA-24-023-02 Crestron AM-300 ICSA-24-023-03 Voltronic Power ViewPower Pro ICSA-23-023-04 Westermo Lynx 206-F2G ICSA-24-023-05 Lantronix XPort ICSMA-24-023-01 Orthanc Osimis DICOM Web Viewer This product is provided subject to this Notification… | CISA |
| Jan 23, 2024 | CISA | Alert | CISA Joins ACSC-led Guidance on How to Use AI Systems Securely The following organizations also collaborated with ACSC on the guidance: Israel National Cyber Directorate (INCD) Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and the Secretariat of Science, Technology and Innovation Policy, Cabinet Office Norway National Cyber Security Centre (NCSC-NO) Sweden National Cybersecurity Center The guidance provides AI systems users with an overview of AI-related threats as well as… | ASD/ACSC, CISA |
| Jan 19, 2024 | CERT-EU | Advisory | 2024-011: Vulnerability in Wordpress POST SMTP Mailer Plugin This vulnerability, identified as CVE-2023-6875 (CVSS score of 9.8)[1], may allow an unauthenticated attacker to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin [2]. This vulnerability could affect sites that have the POST SMTP Mailer plugin installed and configured, which is estimated to be over 300,000 sites [3]. | CERT-EU |
| Jan 19, 2024 | CERT-EU | Advisory | 2024-012: Vulnerability in Chrome On January 16, 2024, Google has released an advisory addressing a zero-day vulnerability identified as CVE-2024-0519, which affects the V8 engine in Google Chromium. This vulnerability allows for out-of-bounds memory access, potentially leading to heap corruption through a crafted HTML page. It has been reported that this vulnerability is being actively exploited. | CERT-EU |
| Jan 19, 2024 | CISA | Alert | CISA Issues Emergency Directive on Ivanti Vulnerabilities ED 24-01 directs all Federal Civilian Executive Branch (FCEB) agencies running Ivanti Connect Secure and Ivanti Policy Secure to: Report indications of compromise to CISA. Remove compromised products from agency networks and follow the ED’s comprehensive instructions for restoring and bringing the products back into service. | CISA |
| Jan 18, 2024 | CISA | Alert | Drupal Releases Security Advisory for Drupal Core A cyber threat actor could exploit this vulnerability to cause a denial-of-service condition. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 18, 2024 | CISA | Alert | Oracle Releases Critical Patch Update Advisory for January 2024 A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Jan 18, 2024 | CISA | Alert | Citrix Releases Security Updates for NetScaler ADC and NetScaler Gateway A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 18, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-018-01 AVEVA PI Server This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 18, 2024 | CISA | Alert | Incident Response Guide for the WWS Sector The guide includes contributions from over 25 WWS Sector organizations spanning private industry, nonprofit, and government entities. This coordination enabled CISA, FBI, and EPA to develop a guide with meaningful value to WWS Sector organizations. | CISA |
| Jan 18, 2024 | CISA | Alert | Atlassian Releases Security Updates for Multiple Products Atlassian released a security advisory to address a vulnerability (CVE-2023-22527) in out-of-date versions of Confluence Data Center and Server as well as its January 2024 security bulletin to address vulnerabilities in multiple products. A malicious cyber actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 17, 2024 | CISA | Alert | VMware Releases Security Advisory for Aria Automation A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 17, 2024 | CERT-EU | Advisory | 2024-009: Critical and High Vulnerabilities in Atlassian Products The editor also released a security advisory addressing 28 high-severity vulnerabilities which have been fixed in new versions of Atlassian products [2]. The critical vulnerability CVE-2023-22527, with a CVSS score of 10, is due to a template injection vulnerability on out-of-date versions of Confluence Data Center and Server that allows an unauthenticated attacker to achieve RCE on an affected version [1]. | CERT-EU |
| Jan 17, 2024 | FBI | Guidance | Cybersecurity Guidance: Chinese-Manufactured UAS national security. While any UAS could have vulnerabilities that enable data theft or facilitate network compromises, the People’s Republic of China (PRC) has enacted laws that provide the government with expanded legal grounds for accessing and controlling data held by firms in China. The use of Chinese-manufactured UAS requires careful consideration and potential mitigation to reduce risk to networks and sensitive information. | FBI |
| Jan 16, 2024 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-016-01 SEW-EURODRIVE MOVITOOLS MotionStudio ICSA-24-016-02 Integration Objects OPC UA Server Toolkit This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 16, 2024 | CISA | Alert | CISA and FBI Release Known IOCs Associated with Androxgh0st Malware Androxgh0st malware establishes a botnet for victim identification and exploitation in vulnerable networks, and targets files that contain confidential information, such as credentials, for various high profile applications. Threat actors deploying Androxgh0st malware have been observed exploiting specific vulnerabilities which could lead to remote code execution, including: CVE-2017-9841 (PHP Unit Command) CVE-2021-41773 (Apache HTTP Server vers… | CISA, FBI |
| Jan 16, 2024 | CISA | Advisory | Known Indicators of Compromise Associated with Androxgh0st Malware tactics, techniques, and procedures (TTPs) associated • Review and ensure only necessary with threat actors deploying Androxgh0st malware. servers and services are exposed to Multiple, ongoing investigations and trusted third party the internet. reporting yielded the IOCs and TTPs, and provided • Review platforms or services that information on Androxgh0st malware’s ability to have credentials listed in . | CISA, CSA, FBI |
| Jan 15, 2024 | CERT-EU | Advisory | 2024-008: Critical Vulnerabilities in Junos OS While Juniper SIRT is not aware of any malicious exploitation of this vulnerability, it is recommended upgrading as soon as possible. The vulnerability CVE-2024-21591 , with a CVSS score of 9.8, is due to an insecure function allowing an attacker to overwrite arbitrary memory. | CERT-EU |
| Jan 12, 2024 | CERT-EU | Advisory | 2024-007: Critical Vulnerabilities in GitLab and Mattermost integrations to execute slash commands as another user. the required CODEOWNERS approval by adding changes to a previously approved merge Within these versions, all authentication mechanisms are impacted. Additionally, users who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their second authentication factor is required to login. | CERT-EU |
| Jan 11, 2024 | CISA | Alert | Cisco Releases Security Advisory for Cisco Unity Connection A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 11, 2024 | CISA | Alert | Juniper Networks Releases Security Bulletin for Junos OS and Junos OS Evolved A cyber threat actor could exploit this vulnerability to cause a denial-of-service condition. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 11, 2024 | CISA | Alert | CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-011-03 Rapid Software LLC Rapid SCADA ICSA-24-011-04 Horner Automation Cscape ICSA-24-011-05 Schneider Electric Easergy Studio ICSA-24-011-06 Siemens Teamcenter Visualization and JT2Go ICSA-24-011-08 Siemens SICAM A8000 ICSA-24-011-09 Siemens SIMATIC CN 4100 ICSA-24-011-10 Siemens SIMATIC ICSA-24-011-11 Siemens Solid E… | CISA |
| Jan 11, 2024 | CERT-EU | Advisory | 2024-006: High Vulnerability in FortiOS & FortiProxy This vulnerability, tracked as CVE-2023-44250 and with a CVSS score of 8.3, could allow an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests. The bug is due to an improper privilege management vulnerability in a FortiOS & FortiProxy HA cluster. If exploited, this vulnerability could allow an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests. | CERT-EU |
| Jan 11, 2024 | CERT-EU | Advisory | 2024-005: Critical Vulnerability in Cisco Unity Connection This vulnerability, tracked as CVE-2024-20272 with a CVSS score of 7.3, could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. Currently, Cisco has no evidence of public proof of concept exploits for this vulnerability or active exploitation in the wild. | CERT-EU |
| Jan 10, 2024 | CISA | Alert | Ivanti Releases Security Update for Connect Secure and Policy Secure Gateways | CISA |
| Jan 9, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-23-348-01 Cambium ePMP 5GHz Force 300-25 Radio (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 9, 2024 | CISA | Alert | Fortinet Releases Security Updates for FortiOS and FortiProxy A cyber threat actor could exploit this vulnerability to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 9, 2024 | CISA | Alert | Microsoft Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Jan 9, 2024 | CERT-EU | Advisory | 2024-003: Critical Vulnerability in Apache OFBiz The vulnerability allows attackers to bypass authentication, which could lead to remote code execution (RCE) [1]. The vulnerability, identified as CVE-2023-51467 with a CVSS score of 9.8 [2], may allow an attacker to bypass authentication to achieve a simple Server-Side Request Forgery (SSRF). | CERT-EU |
| Jan 8, 2024 | CERT-EU | Advisory | 2024-002: Critical Vulnerability in Ivanti Endpoint Management Software This vulnerability, tracked as CVE-2023-39336 (CVSS score : 9.6), allows unauthenticated attackers to hijack enrolled devices or the core server. Ivanti EPM is used to manage client devices across various platforms, including Windows, macOS,ChromeOS,andIoToperatingsystems. | CERT-EU |
| Jan 8, 2024 | CERT-EU | Advisory | 2024-001: Vulnerability in Wordpress Google Fonts Plugin On January 2, 2024, an unauthenticated Stored Cross-Site Scripting (XSS) and directory deletion vulnerability has been discovered in the “OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. This vulnerability, identified as CVE-2023-6600 (CVSS score of 8.6)[1], may allow unauthenticated attackers to update the plugin’s settings and inject malicious scripts into affected sites [2]. | CERT-EU |
| Jan 4, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-004-01 Rockwell Automation FactoryTalk Activation ICSA-24-004-02 Mitsubishi Electric Factory Automation Products ICSA-23-348-15 Unitronics Vision and Samba Series (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 4, 2024 | NSA | Guidance | CSI: Recommendations for Software Bill of Materials (SBOM) Management (Jan 2024 Update) Recommendations for Software Bill of Materials The dramatic increase in cyber compromises over the past five years, specifically of software supply chains, prompted intense scrutiny of measures to strengthen the resilience of supply chains for software used throughout government and critical infrastructure. Several policies and working groups at multiple levels within the U.S. | CISA, NSA, NSM |
| Jan 2, 2024 | CISA | Alert | Juniper Releases Security Advisory for Juniper Secure Analytics A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |