Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Critical vulnerabilities found in Fortinet and SonicWall products

Critical vulnerabilities found in Fortinet and SonicWall products

In this cybersecurity threat advisory, Fortinet and SonicWall both advised of vulnerabilities found in their products. Fortinet shared that FortiOS and FortiProxy has a critical vulnerability where successful exploitation of the vulnerability allows an attacker to perform remote arbitrary code...

/ July 13, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New malware campaign targets banking institutions

Cybersecurity Threat Advisory: New malware campaign targets banking institutions

A sophisticated malware campaign known as “Toitoin” is targeting banking firms in Latin America. The campaign employs evasive techniques, including the use of custom-built modules, encryption methods, and hosting malware on Amazon EC2 instances to evade detection. It is crucial...

/ July 12, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical VMware Aria Operations vulnerabilities

Cybersecurity Threat Advisory: Critical VMware Aria Operations vulnerabilities

Two vulnerabilities were discovered in older versions of VMware Aria Operations for Networks and VMware Aria Operations for Logs. The vulnerabilities allow bad actors to perform remote code execution as the root user. Remote code execution can lead to system...

/ July 12, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical MOVEit vulnerability discovered

Cybersecurity Threat Advisory: Critical MOVEit vulnerability discovered

A critical vulnerability has been discovered in the MOVEit Transfer software, prompting urgent action from customers to patch their systems. This flaw, identified as CVE-2023-36934, allows an attacker to execute arbitrary commands on the affected system with elevated privileges without...

/ July 8, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New FortiNAC critical vulnerability update released

Cybersecurity Threat Advisory: New FortiNAC critical vulnerability update released

A critical remote code execution vulnerability (CVE-2023-33299) with a CVSS score of 9.6 has been discovered in Fortinet’s FortiNAC product. This vulnerability poses a significant risk as it could allow an unauthenticated user to execute unauthorized code or commands by...

/ June 27, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Command injection flaw in Zyxel NAS devices

Cybersecurity Threat Advisory: Command injection flaw in Zyxel NAS devices

Zyxel, a networking equipment manufacturer, has released urgent security updates to address critical vulnerabilities in their network-attached storage devices. CVE-2023-27992 (CVSS score: 9.8) has been declared as a pre-authentication command injection vulnerability. What is the threat? The threat involves multiple vulnerabilities...

/ June 26, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New custom malware discovered

Cybersecurity Threat Advisory: New custom malware discovered

Researchers have uncovered a year-long, highly targeted cyber-attack utilizing custom malware called RDStealer. The bespoke malware campaign against an East Asian IT company has been active for more than a year with the intent to compromise credentials and exfiltrating data....

/ June 22, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical vulnerabilities with ASUS routers

Cybersecurity Threat Advisory: Critical vulnerabilities with ASUS routers

ASUS recently released critical security updates for several vulnerabilities across multiple router models. Two out of the nine vulnerabilities are categorized as Critical, including an out-of-bounds write vulnerability and a memory corruption flaw. Barracuda SOC recommends applying the latest security...

/ June 21, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New remote control escalation vulnerability – updated

Cybersecurity Threat Advisory: New remote control escalation vulnerability – updated

Fortinet recently released updates for several products utilizing SSL-VPN functionalities after discovering a critical vulnerability. The major flaw discovered gives the ability to an attacker to perform an unauthenticated remote code execution on devices. Barracuda SOC recommends updating Fortinet products...

/ June 12, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: “File Archiver in the Browser” exploits

Cybersecurity Threat Advisory: “File Archiver in the Browser” exploits

A new skilled and clever “File Archiver in the Browser” phishing trick that utilizes ZIP domains has surfaced. Bad actors can employ this technique to deceive users into downloading malicious files, compromise systems, and potentially gaining unauthorized access. What is...

/ June 7, 2023