| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Aug 29, 2024 | CISA | Alert | CISA and Partners Release Advisory on RansomHub Ransomware Today, CISA—in partnership with the Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Department of Health and Human Services (HHS)—released a joint Cybersecurity Advisory, #StopRansomware: RansomHub Ransomware . | CISA, FBI, HHS, MS-ISAC |
| Aug 29, 2024 | CISA | Advisory | #StopRansomware: RansomHub Ransomware Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. An improper neutralization of special elements used in an SQL command (SQL injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and FortiClientEMS 7.0.1 through 7.0. | CISA, FBI, HHS, MS-ISAC |
| Aug 29, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-242-01 Rockwell Automation ThinManager ThinServer ICSA-24-242-02 Delta Electronics DTN Soft ICSA-24-226-06 Rockwell Automation FactoryTalk View Site Edition (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 28, 2024 | CISA | Alert | CISA and Partners Release Advisory on Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations Organizations . This joint advisory warns of cyber actors, known in the private sector as Pioneer Kitten, UNC757, Parisite, Rubidium, and Lemon Sandstorm, targeting and exploiting U.S. and foreign organizations across multiple sectors in the U.S. | CISA, DC3, FBI |
| Aug 28, 2024 | CISA | Advisory | Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as… | CISA, CSA, DC3, FBI |
| Aug 28, 2024 | FBI | Alert | Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as… | CISA, DC3, FBI |
| Aug 27, 2024 | CISA | Alert | Versa Networks Releases Advisory for a Vulnerability in Versa Director, CVE-2024-39717 A cyber threat actor could exploit this vulnerability to take control of an affected system. Versa Security Bulletin: Update on CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability Lumen: Taking the Crossroads: The Versa Director Zero-Day Exploitation CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. | CISA |
| Aug 27, 2024 | CERT-EU | Advisory | 2024-088: Chrome ZeroDay Vulnerabilities The flaw, which has been actively exploited in the wild, is rooted in a type confusion issue within Chrome’s V8 JavaScript engine. This vulnerability allows attackers to potentially execute arbitrary code on affected [New] On August 26, Google announced that it patched the tenth zero-day vulnerability in Chrome. | CERT-EU |
| Aug 27, 2024 | CERT-EU | Advisory | 2024-089: Critical Vulnerability in SonicWall SonicOS This flaw could allow attackers to gain unauthorised access to resources or cause the firewall crash [1]. Thevulnerability CVE-2024-40766,withaCVSSscoreof9.3,iscausedbyimproperaccesscontrol in the SonicOS management interface, potentially leading to unauthorised access and firewall CERT-EU recommends updating to the latest firmware versions immediately. | CERT-EU |
| Aug 22, 2024 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-235-01 Rockwell Automation Emulate3D ICSA-24-235-02 Rockwell Automation 5015 – AENFTXT ICSA-24-235-03 MOBOTIX P3 and Mx6 Cameras ICSA-24-235-04 Avtec Outpost 0810 ICSA-20-282-02 Mitsubishi Electric MELSEC iQ-R Series (Update D) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 21, 2024 | CISA | Alert | ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats. | AIVD, ASD/ACSC, CCCS, CISA, CSA, MIVD, NCSC-NZ, NCSC-UK, NIS, NSA |
| Aug 21, 2024 | CERT-EU | Advisory | 2024-084: High Severity Vulnerabilities in F5 Products Four of these vulnerabilities have been classified as high severity due to their potential to facilitate session hijacking and to lead to Denial-of-Service (DoS) attacks. [1,2] CVE-2024-39809, with a CVSS score 8.9, is a vulnerability that facilitates session hijacking. | CERT-EU |
| Aug 21, 2024 | CERT-EU | Advisory | 2024-085: Multiple Vulnerabilities in Moodle Several CVEs have been assigned with a Serious severity or risk by Moodle. ThevulnerabilityCVE-2024-43440isaLocalFileInclusion(LFI)flawtriggeredwhenrestoring The vulnerability CVE-2024-43439 is a flaw in unsanitised H5P error messages allowing for Reflected Cross-Site Scripting (XSS) [4]. | CERT-EU |
| Aug 20, 2024 | CERT-EU | Advisory | 2024-083: Palo Alto Cortex XSOAR CommonScripts Critical Vulnerability This flaw allows unauthenticated attackers to execute arbitrary commands within the context of an integration container, potentially compromising the system. The vulnerability affects the product’s CommonScripts Pack and is rated as high severity with a CVSS score of 9.0. | CERT-EU |
| Aug 16, 2024 | CERT-EU | Advisory | 2024-081: SolarWinds Web Help Desk Critical Remote Code Execution Vulnerability The vulnerability, caused by a Java deserialization flaw, allows attackers to execute arbitrary commands on the affected system. CVE-2024-28986 is a Java deserialization vulnerability that allows attackers to execute remote commands on the vulnerable system. | CERT-EU |
| Aug 16, 2024 | CERT-EU | Advisory | 2024-082: Zabbix Server Critical Arbitrary Code Execution Vulnerability The flaw, identified in the Ping script execution within the Monitoring Hosts section, can compromise the entire infrastructure. CVE-2024-22116 is a code injection vulnerability (CWE-94) where improper control over script parameters allows arbitrary code execution via the Ping script in the Monitoring Hosts section CERT-EU strongly recommends upgrading to Zabbix versions 6.4.16rc1 or 7.0.0rc3 immediately, as no workarounds are available. | CERT-EU |
| Aug 15, 2024 | CISA | Alert | CISA Releases Eleven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-228-01 Siemens SCALANCE M-800, RUGGEDCOM RM1224 ICSA-24-228-02 Siemens INTRALOG WMS ICSA-24-228-03 Siemens Teamcenter Visualization and JT2Go ICSA-24-228-04 Siemens SINEC Traffic Analyzer ICSA-24-228-05 Siemens LOGO! V8. | CISA |
| Aug 14, 2024 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB24-57) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Aug 14, 2024 | CISA | Alert | Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security Update Available for Adobe Illustrator | APSB24-45 Security Update Available for Adobe Dimension | APSB24-47 Security Update Available for Adobe Photoshop | APSB24-49 Security Update Available for Adobe InDesign | APSB24-56 Security Update Available for Adobe Acrobat Reader | APSB24-57 Security Update Available for Adobe Bridge | APSB2… | CISA |
| Aug 14, 2024 | CERT-EU | Advisory | 2024-080: Multiple Critical Vulnerabilities in Microsoft Products This Patch Tuesday also fixes six critical vulnerabilities [1,2]. We highlight here the most critical vulnerabilities, but it is highly recommended to deploy Microsoft patches for all 89 vulnerabilities identified. | CERT-EU |
| Aug 14, 2024 | CERT-EU | Advisory | 2024-079: Critical SAP Authentication Bypass Vulnerability This flaw allows remote attackers to bypass authentication mechanisms, potentially leading to full system compromise. The vulnerability has a CVSS score of 9.8, highlighting its severity. | CERT-EU |
| Aug 13, 2024 | CISA | Alert | CISA Releases Ten Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-226-01 AVEVA SuiteLink Server ICSA-24-226-02 Rockwell Automation AADvance Standalone OPC-DA Server ICSA-24-226-03 Rockwell Automation GuardLogix/ControlLogix 5580 Controller ICSA-24-226-04 Rockwell Automation Pavilion8 ICSA-24-226-05 Rockwell Automation DataMosaix Private Cloud ICSA-24-226-06 Rockwell Automation Factor… | CISA |
| Aug 13, 2024 | CISA | Alert | Microsoft Releases August 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for August This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Aug 13, 2024 | CISA | Alert | Ivanti Releases Security Updates for Avalanche, Neurons for ITSM, and Virtual Traffic Manager A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Ivanti advises users to reduce their attack surface and follow industry best practices by adhering to Ivanti’s network configuration guidance to restrict access to the management interface. | CISA |
| Aug 12, 2024 | CERT-EU | Advisory | 2024-077: Vulnerabilities in Microsoft Office This security flaw is caused by an information disclosure weakness that enables unauthorised actors to access The vulnerability CVE-2024-38200 (CVSS score: 7.5) is an information disclosure vulnerability that allows remote attackers to access NTLM hashes. | CERT-EU |
| Aug 12, 2024 | CERT-EU | Advisory | 2024-076: Vulnerabilities in OpenVPN On August 8, 2024, Microsoft released a writeup for those vulnerabilities [2]. openvpn.exe process and the openvpnserv.exe service. requests received through the \\openvpn\\service named pipe. be loaded from various paths on an endpoint device. In the project’s src folder, the device.c file contains the code for the TAP device object and its initialisation. | CERT-EU |
| Aug 12, 2024 | CERT-EU | Advisory | 2024-075: Vulnerabilities in AMD CPUs OnAugust9,2024,AMDdisclosedahigh-severityvulnerability,CVE-2023-31315(SinkClose), affecting multiple generations of EPYC, Ryzen, and Threadripper processors. The flaw allows attackers with kernel-level access to gain Ring-2 privileges, potentially installing undetectable malware by modifying System Management Mode (SMM) settings [1]. The SinkClose vulnerability (CVSS score: 7. | CERT-EU |
| Aug 8, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-221-01 Dorsett Controls InfoScan This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 8, 2024 | CISA | Alert | Best Practices for Cisco Device Configuration A Cisco password type is the type of algorithm used to secure a Cisco device’s password within a system configuration file. The use of weak password types enables password cracking attacks. | CISA |
| Aug 7, 2024 | CISA | Alert | Royal Ransomware Actors Rebrand as “BlackSuit,” FBI and CISA Release Update to Advisory The updated advisory provides network defenders with recent and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with BlackSuit and legacy Royal activity. FBI investigations identified these TTPs and IOCs as recently as July 2024. | CISA, FBI |
| Aug 6, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-219-01 Delta Electronics DIAScreen This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 6, 2024 | CISA | Alert | CISA Releases Secure by Demand Guidance An organization’s acquisition staff often has a general understanding of the core cybersecurity requirements for a particular technology acquisition. However, they frequently don’t assess whether a given supplier has practices and policies in place to ensure that security is a core consideration from the earliest stages of the product development lifecycle. | CISA |
| Aug 1, 2024 | CISA | Alert | CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-214-01 Johnson Controls exacqVision Client and exacqVision Server ICSA-24-214-02 Johnson Controls exacqVision Web Service ICSA-24-214-03 Johnson Controls exacqVision Web Service ICSA-24-214-04 Johnson Controls exacqVision Web Service ICSA-24-214-05 Johnson Controls exacqVision Server ICSA-24-214-06 Johnson Controls exa… | CISA |