CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ November 2024 ›
26 publications — sorted newest first
Date Source Type Title Author
Nov 26, 2024 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-331-01 Schneider Electric PowerLogic PM55xx and PowerLogic PM8ECC ICSA-24-331-02 Schneider Electric PowerLogic P5 ICSA-24-331-03 Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs ICSA-24-331-04 Hitachi Energy MicroSCADA Pro/X SYS600 ICSA-24-331-05 Hit… CISA
Nov 25, 2024 CERT-EU Advisory 2024-118: Critical Vulnerability in 7-Zip The vulnerability tracked as CVE-2024-11477 has received a high CVSS score of 7.8 [1]. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. CERT-EU
Nov 21, 2024 CISA Alert CISA Releases Insights from Red Team Assessment of a U.S. Critical Infrastructure Sector Organization This cybersecurity advisory details lessons learned and key findings from an assessment, including the Red Team’s tactics, techniques, and procedures (TTPs) and associated network defense activity. This advisory provides comprehensive technical details of the Red Team’s cyber threat activity, including their attack path to compromise a domain controller and human machine interface (HMI), which serves as a dashboard for operational technology (OT)… CISA
Nov 21, 2024 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-326-01 Automated Logic WebCTRL Premium Server ICSA-24-326-02 OSCAT Basic Library ICSA-24-326-03 Schneider Electric Modicon M340, MC80, and Momentum Unity M1E ICSA-24-326-04 Schneider Electric Modicon M340, MC80, and Momentum Unity M1E ICSA-24-326-05 Schneider Electric EcoStruxure IT Gateway ICSA-24-326-06 Schneider Ele… CISA
Nov 21, 2024 CISA Advisory Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization During RTAs, CISA’s red team simulates real-world malicious cyber operations to assess an organization’s cybersecurity detection and response capabilities. In coordination with the assessed organization, CISA is releasing this Cybersecurity Advisory to detail the red team’s activity—including their tactics, techniques, and procedures (TTPs) and associated network defense activity. CISA
Nov 20, 2024 CISA Alert Apple Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 20, 2024 CISA Alert 2024 CWE Top 25 Most Dangerous Software Weaknesses This annual list identifies the most critical software weaknesses that adversaries frequently exploit to compromise systems, steal sensitive data, or disrupt essential services. Organizations are strongly encouraged to review this list and use it to inform their software security strategies. CISA
Nov 20, 2024 CISA Alert CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory Today, CISA, the Federal Bureau of Investigation (FBI), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released updates to #StopRansomware: BianLian Ransomware Group on observed tactics, techniques, and procedures (TTPs) and indicators of compromise attributed to data extortion group, BianLian. ASD/ACSC, CISA, FBI
Nov 20, 2024 CISA Alert USDA Releases Success Story Detailing the Implementation of Phishing-Resistant Multifactor Authentication This report details how USDA successfully implemented phishing-resistant authentication for its personnel in situations where USDA could not exclusively rely on personal identity verification (PIV) cards. USDA turned to Fast IDentity Online (FIDO) capabilities, a set of authentication protocols that uses cryptographic keys on user devices, to offer a secure way to authenticate user identities without passwords. CISA
Nov 19, 2024 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-324-01 Mitsubishi Electric MELSEC iQ-F Series This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 19, 2024 CERT-EU Advisory 2024-117: Zero-Day Vulnerabilities in Palo Alto Networks PAN-OS If exploited, these vulnerabilities could allow a remote unauthenticated attacker to gain administrator privileges, or a PAN-OS administrator to perform actions on the firewall with root privileges [1,2]. It recommended applying the updates and restricting the access to the management web interface to only trusted internal IP addresses, according to the vendor’s best practice deployment The vulnerability CVE-2024-0012, with a CVSS score of 9. CERT-EU
Nov 14, 2024 CISA Alert CISA Releases Nineteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-319-01 Siemens RUGGEDCOM CROSSBOW ICSA-24-319-03 Siemens OZW672 and OZW772 Web Server ICSA-24-319-04 Siemens SINEC NMS ICSA-24-319-05 Siemens Solid Edge ICSA-24-319-06 Siemens SCALANCE M-800 Family ICSA-24-319-07 Siemens Engineering Platforms ICSA-24-319-08 Siemens SINEC INS ICSA-24-319-10 Siemens TeleControl Server IC… CISA
Nov 14, 2024 NCSC Guidance Mail Check update Important information about the future of Mail Check The NCSC has made the decision to stop providing DMARC Aggregate Reporting on 24th March 2025. Mail Check users requiring DMARC Aggregate Reporting will need to switch to an alternative tool. This decision gives NCSC the opportunity to expand the Mail Check service to any UK organisation whilst significantly reducing cost and complexity. NCSC-UK
Nov 13, 2024 CISA Alert Palo Alto Networks Emphasizes Hardening Guidance Palo Alto Networks (PAN) has updated their informational bulletin, noting they "observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet. CISA
Nov 13, 2024 CERT-EU Advisory 2024-116: Microsoft November 2024 Patch Tuesday Two of these zero-days, CVE-2024-43451 (NTLM Hash Disclosure Spoofing) and CVE-2024-49039 (Windows Task Scheduler Elevation of Privilege), have been actively exploited. These vulnerabilities allow attackers to potentially gain unauthorised access or escalate privileges through minimal user interaction or crafted applications [1-4]. CERT-EU
Nov 12, 2024 CISA Alert Fortinet Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. FG-IR-23-396 ReadOnly Users Could Run Some Sensitive Operations FG-IR-23-475 FortiOS - SSLVPN Session Hijacking Using SAML Authentication FG-IR-24-144 Privilege Escalation via Lua Auto Patch Function FG-IR-24-199 Named Pipes Improper Access Control This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 12, 2024 CISA Alert Microsoft Releases November 2024 Security Updates Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for November This product is provided subject to this Notification and this Privacy & Use policy. CISA, JPCERT/CC
Nov 12, 2024 CISA Alert Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Security update available for Adobe Bridge | APSB24-77 Security update available for Adobe Audition | APSB24-83 Security update available for Adobe After Effects | APSB24-85 Security update available for Adobe Substance 3D Painter | APSB24-86 Security update available for Adobe Illustrator| APSB24-87 Security update available for Adobe InDesign… CISA
Nov 12, 2024 CISA Alert Ivanti Releases Security Updates for Multiple Products Ivanti released security updates to address vulnerabilities in Ivanti Endpoint Manager (EPM), Ivanti Avalanche, Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Security Access Client. Ivanti Security Advisory Avalanche Ivanti Security Advisory Connect Secure, Ivanti Policy Secure, and Ivanti Security Access Client This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 12, 2024 CISA Alert JCDC’s Collaborative Efforts Enhance Cybersecurity for the 2024 Olympic and Paralympic Games The Cybersecurity and Infrastructure Security Agency (CISA), through the Joint Cyber Defense Collaborative (JCDC), enabled proactive coordination and information sharing to bolster cybersecurity ahead of the 2024 Olympic and Paralympic Games in Paris. Recognizing the potential for cyber threats targeting the Games, CISA worked to strengthen U.S. CISA
Nov 12, 2024 CISA Alert Citrix Releases Security Updates for NetScaler and Citrix Session Recording A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2024-8534 and CVE-2024-8535 Citrix Session Recording Security Bulletin for CVE-2024-8068 and CVE-2024-8069 This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 12, 2024 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-317-01 Subnet Solutions PowerSYSTEM Center ICSA-24-317-02 Hitachi Energy TRO600 ICSA-24-317-03 Rockwell Automation FactoryTalk View ME ICSA-23-306-03 Mitsubishi Electric MELSEC Series (Update A) ICSA-23-136-01 Snap One OvrC Cloud (Update A) This product is provided subject to this Notification and this Privacy & Use po… CISA
Nov 12, 2024 CISA Alert CISA, FBI, NSA, and International Partners Release Joint Advisory on 2023 Top Routinely Exploited Vulnerabilities This advisory supplies details on the top Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors and their associated Common Weakness Enumeration(s) (CWE) to help organizations better understand the impact of exploitation. CISA, FBI, NSA
Nov 12, 2024 CISA Advisory 2023 Top Routinely Exploited Vulnerabilities Summary The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA) Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zeal… ASD/ACSC, CCCS, CISA, NCSC-NZ,
NCSC-UK, NIST, NSA
Nov 7, 2024 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-312-01 Beckhoff Automation TwinCAT Package Manager ICSA-24-312-02 Delta Electronics DIAScreen ICSA-24-312-03 Bosch Rexroth IndraDrive This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 6, 2024 NCSC Guidance Guidance for brands to help advertising partners counter malvertising Guidance for brands to help advertising Advice to make it harder for cyber criminals to deliver malicious advertising, and reduce the risk of cyber-facilitated fraud. This guidance helps brands that use in-house and third-party digital advertising services choose digital advertising partners that prioritise security. NCSC-UK