| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Sep 30, 2024 | CISA | Alert | CISA’s VDP Platform 2023 Annual Report Showcases Success Throughout 2023, CISA focused on advocating for the increased agency adoption of the VDP Platform, supporting federal civilian executive branch (FCEB) agencies in identifying vulnerabilities in their systems, and engaging the public security researcher community. Public security researchers play a vital role in securing our federal government's networks. | CISA |
| Sep 30, 2024 | CERT-EU | Advisory | 2024-105: Multiple Vulnerabilities in WhatsUp Gold No technical details have been release at this time, but the following vulnerabilities have been listed by the WhatsUp Gold team in their security bulletin [1]: All WhatsUp Gold versions below 24.0.1. CERT-EU strongly recommends updating affected devices as soon as possible [1]. | CERT-EU |
| Sep 27, 2024 | CERT-EU | Advisory | 2024-104: Critical Vulnerability in NVIDIA Container Toolkit NVIDIA Container Toolkit is providing containerised AI applications with access to GPU resources. This vulnerability impacts any AI application that is running the vulnerable container toolkit to enable GPU support. | CERT-EU |
| Sep 26, 2024 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-270-01 Advantech ADAM-5550 ICSA-24-270-02 Advantech ADAM-5630 ICSA-24-270-03 Atelmo Atemio AM 520 HD Full HD Satellite Receiver ICSA-24-270-04 goTenna Pro X and Pro X2 ICSA-24-270-05 goTenna Pro ATAK Plugin This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 26, 2024 | CISA | Alert | Cisco Releases Security Updates for IOS and IOS XE Software A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. September 2024 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 26, 2024 | CISA | Alert | ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises First published: September 2024 This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active… | ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NSA |
| Sep 25, 2024 | CISA | Alert | CISA Warns of Hurricane-Related Scams This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 25, 2024 | CISA | Alert | Threat Actors Continue to Exploit OT/ICS through Unsophisticated Means CISA continues to respond to active exploitation of internet-accessible operational technology (OT) and industrial control systems (ICS) devices, including those in the Water and Wastewater Systems (WWS) Sector . Exposed and vulnerable OT/ICS systems may allow cyber threat actors to use default credentials, conduct brute force attacks, or use other unsophisticated methods to access these devices and cause harm. | CISA |
| Sep 25, 2024 | CISA | Alert | Citrix Releases Security Updates for XenServer and Citrix Hypervisor XenServer and Citrix Hypervisor Security Update for CVE-2024-45817 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 24, 2024 | CISA | Alert | CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-268-01 OPW Fuel Management Systems SiteSentinel ICSA-24-268-02 Alisonic Sibylla ICSA-24-268-03 Franklin Fueling Systems TS-550 EVO ICSA-24-268-04 Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE ICSA-24-268-05 Moxa MXview One ICSA-24-268-06 OMNTEC Proteus Tank Monitoring ICSA-24-156-01 Uniview NVR301-04S2-P4 (Update… | CISA |
| Sep 24, 2024 | CERT-EU | Advisory | 2024-102: Traefik Critical Vulnerability This vulnerability could allow an attacker to execute arbitrary commands via crafted HTTP requests, posing a significant risk to exposed services [1,2]. Immediate updates are recommended for all affected installations. | CERT-EU |
| Sep 20, 2024 | CISA | Alert | Versa Networks Releases Advisory for a Vulnerability in Versa Director, CVE-2024-45229 A cyber threat actor could exploit this vulnerability to exercise unauthorized REST APIs. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 19, 2024 | CISA | Alert | Ivanti Releases Admin Bypass Security Update for Cloud Services Appliance A cyber threat actor could exploit this vulnerability in conjunction with CVE-2024-8190 –detailed in a Sept. 13 Ivanti security advisory– to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 19, 2024 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-263-03 IDEC CORPORATION WindLDR and WindO/I-NV4 ICSA-24-263-04 MegaSys Computer Technologies Telenium Online Web Application ICSA-24-263-05 Kastle Systems Access Control System ICSA-20-168-01 Treck TCP/IP (Update I) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 19, 2024 | CISA | Alert | VMware Releases Security Advisory for VMware Cloud Foundation and vCenter Server A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 19, 2024 | CERT-EU | Advisory | 2024-101: Critical SAML Authentication Bypass in Gitlab The vulnerability affects the Community Edition (CE) and the Enterprise Edition (EE) instances that utilise SAML for single sign-on (SSO) [1,2]. It is recommended updating affected servers as soon as possible, and searching for potential successful exploitation of the vulnerability in the logs. | CERT-EU |
| Sep 18, 2024 | CISA | Alert | Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 18, 2024 | CERT-EU | Advisory | 2024-099: Critical Vulnerabilities in Openshift ThevulnerabilityCVE-2024-45496withaCVSSscoreof9.9,arisesfromthemisuseofelevated privileges during the build process [1]. The git-clone container runs with privileged access, allowing attackers with developer-level permission to exploit a crafted .gitconfig file. | CERT-EU |
| Sep 18, 2024 | FBI | Alert | People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations The actors may then use the botnet as a proxy to conceal their identities while deploying distributed denial of service (DDoS) attacks or compromising targeted U.S. networks. Integrity Technology Group (Integrity Tech), a PRC-based company, has controlled and managed a botnet active since mid-2021. | CNMF, FBI |
| Sep 17, 2024 | CISA | Alert | CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities Vulnerabilities like cross-site scripting (XSS) continue to appear in software, enabling threat actors to exploit them. However, cross-site scripting vulnerabilities are preventable and should not be present in software products. | CISA, FBI |
| Sep 17, 2024 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-261-01 Siemens SIMATIC S7-200 SMART Devices ICSA-24-261-02 Millbeck Communications Proroute H685t-w ICSA-24-261-03 Yokogawa Dual-redundant Platform for Computer (PC2CKM) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 16, 2024 | CISA | Alert | New CISA Plan Aligns Federal Agencies in Cyber Defense The version number will be updated for each subsequent publication of the FOCAL Plan. Version Summary of revisions Edited By Date 1.0 • Publication of version 1.0 FEIT 03/01/2024 Public Version • Shorter, public version of plan FEIT 07/22/2024 1. Introduction ............................................................................................................................................................. 4 1. | CISA |
| Sep 16, 2024 | CERT-EU | Advisory | 2024-097: Vulnerabilities in SolarWinds Access Rights Manager These vulnerabilities, if exploited, could lead to authenticated remote code execution, and authentication bypass [1][2]. The vulnerability CVE-2024-28990, with a CVSS Score of 6.3, is a hard-coded credential authentication bypass flaw. | CERT-EU |
| Sep 16, 2024 | CERT-EU | Advisory | 2024-098: Command Injection Vulnerability in PaloAlto PAN-OS If exploited, this flaw could allow an authenticated attacker to execute arbitrary commands as root on the firewall. The vulnerability CVE-2024-8686, with a CVSS score of 8.6, is a command injection vulnerability in Palo Alto Networks PAN-OS software. | CERT-EU |
| Sep 13, 2024 | CISA | Alert | Ivanti Releases Security Update for Cloud Services Appliance A cyber threat actor could exploit this vulnerability to take control of an affected system. At this time, Ivanti has confirmed limited exploitation and urges its customers using the affected versions to upgrade to CSA version 5.0. | CISA |
| Sep 13, 2024 | CISA | Alert | CISA Releases Analysis of FY23 Risk and Vulnerability Assessments The Cybersecurity and Infrastructure Security Agency (CISA) conducts Risk and Vulnerability Assessments (RVAs) for the federal civilian executive branch (FCEB), high priority private and public sector critical infrastructure (CI) operators, and select state, local, tribal, and territorial (SLTT) stakeholders. | CISA |
| Sep 12, 2024 | CISA | Alert | CISA Releases Twenty-Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-256-01 Siemens SINEMA Remote Connect Server ICSA-24-256-02 Siemens SINUMERIK ONE, SINUMERIK 840D and SINUMERIK 828D ICSA-24-256-03 Siemens User Management Component (UMC) ICSA-24-256-04 Siemens SINUMERIK Systems ICSA-24-256-05 Siemens Mendix Runtime ICSA-24-256-06 Siemens Automation License Manager ICSA-24-256-07 Sieme… | CISA |
| Sep 12, 2024 | CISA | Alert | Cisco Releases Security Updates for IOS XR Software September 2024 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 12, 2024 | CISA | Alert | Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security update available for Adobe Media Encoder | APSB24-53 Security update available for Adobe Audition | APSB24-54 Security update available for Adobe After Effects | APSB24-55 Security update available for Adobe Premiere Pro | APSB24-58 Security update available for Adobe Illustrator | APSB24-66 Security update available for Adobe Acrobat… | CISA |
| Sep 12, 2024 | CERT-EU | Advisory | 2024-095: Critical vulnerabilities in Adobe Products When exploited, these vulnerabilities could allow an attacker to execute arbitrary code [1]. A publicly available proof-of-concept exploit exists for one of the vulnerabilities [2]. | CERT-EU |
| Sep 11, 2024 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB24-70) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Sep 11, 2024 | CERT-EU | Advisory | 2024-094: Critical Vulnerabilities in Ivanti EPM The most severe vulnerability, CVE-2024-29847, with a CVSS score of 10, is due to improper input validation which could lead to deserialisation of untrusted data in the agent portal of Ivanti EPM. It could allow a remote unauthenticated attacker to achieve remote code execution. | CERT-EU |
| Sep 10, 2024 | CISA | Alert | Cisco Releases Security Updates for Cisco Smart Licensing Utility A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. Cisco Smart Licensing Utility Vulnerabilities This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 10, 2024 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-254-02 iniNet Solutions SpiderControl SCADA Web Server ICSA-24-254-03 Rockwell Automation SequenceManager ICSMA-24-254-01 BPL Medical Technologies PWS-01-BT and BPL Be Well Android Application This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 10, 2024 | CISA | Alert | Ivanti Releases Security Updates for Endpoint Manager, Cloud Service Application, and Workspace Control A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Ivanti Cloud Service Application 4.6 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 10, 2024 | CISA | Alert | Microsoft Releases September 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for September This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Sep 10, 2024 | CISA | Alert | Citrix Releases Security Updates for Citrix Workspace App for Windows Citrix Workspace app for Windows Security Bulletin for CVE-2024-7889 and CVE-2024-7890 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 6, 2024 | CERT-EU | Advisory | 2024-092: Critical Vulnerability in Veeam Thisflawallows unauthenticated attackers to execute arbitrary code on vulnerable systems (CVSS score: 9.8). VBR is a target for ransomware attacks, as it plays a key role in enterprise data protection. | CERT-EU |
| Sep 5, 2024 | NSA | Alert | Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity. | ASD/ACSC, CCCS, CISA, CNMF, FBI, MIVD, NCSC-UK, NSA, Treasury, USCC |
| Sep 5, 2024 | NSA | Advisory | Russian Military Cyber Actors Target US and Global Critical Infrastructure GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity. | ASD/ACSC, CCCS, CISA, CNMF, FBI, MIVD, NCSC-UK, NIST, NSA, Treasury, USCC |
| Sep 5, 2024 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-249-01 Hughes Network Systems WL3000 Fusion Software ICSMA-24-249-01 Baxter Connex Health Portal ICSA-20-303-01 Mitsubishi Electric MELSEC iQ-R, Q, and L Series (Update E) ICSA-22-356-03 Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series (Update E) This product is provided subject to this Notification and t… | CISA |
| Sep 5, 2024 | NSA | Alert | FBI, CISA, NSA, and US and International Partners Release Advisory on Russian Military Cyber Actors Targeting US and Global Critical Infrastructure Today, the Federal Bureau of Investigation (FBI)—in partnership with CISA, the National Security Agency (NSA), and other U.S. and international partners—released a joint Cybersecurity Advisory Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure . | CISA, FBI, NSA |
| Sep 4, 2024 | CERT-EU | Advisory | 2024-091: High Severity Vulnerability in VMware Fusion for MacOS which could allow attackers to execute arbitrary code on macOS systems [1]. ThevulnerabilityCVE-2024-38811,withaCVSSscoreof8.8,arisesfromimproperhandlingof environment variables, allowing malicious actors with standard user privileges to execute arbitrary code within the VMware Fusion environment. This may lead to full-system compromise, potentially exposing sensitive data and disrupting operations. | CERT-EU |
| Sep 3, 2024 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-247-01 LOYTEC Electronics LINX Series This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 3, 2024 | FBI | Alert | North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks The Democratic People's Republic of Korea (DPRK, aka North Korea) is conducting highly tailored, difficult-to-detect social engineering campaigns against employees of decentralized finance (DeFi), cryptocurrency, and similar businesses to deploy malware and steal company cryptocurrency. North Korean social engineering schemes are complex and elaborate, often compromising victims with sophisticated technical acumen. | FBI |
| Sep 2, 2024 | CERT-EU | Advisory | 2024-090: Multiple Vulnerabilities in Cisco NX-OS Software The most severe of these is a high-severity denial-of-service (DoS) vulnerability in the DHCPv6 relay agent, which could allow an unauthenticated remote attacker to cause targeted devices to reload repeatedly, leading to a DoS condition. Additionally, several medium-severity vulnerabilities were addressed, including issues that could allow privilege escalation and unauthorised code execution [1,2]. | CERT-EU |