Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Citrix Gateway vulnerability

Cybersecurity Threat Advisory: Citrix Gateway vulnerability

Citrix has issued emergency patches for a critical memory overflow flaw that impacts NetScaler ADC and Gateway. Exploitation can lead to denial-of-service (DoS) and system control issues. Review this Cybersecurity Threat Advisory for guidance on protecting your systems against this...

/ June 26, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Global Microsoft Exchange attack

Cybersecurity Threat Advisory: Global Microsoft Exchange attack

A recent cyber campaign has compromised over 70 Microsoft Exchange servers across 26 countries by injecting JavaScript-based keyloggers into Outlook Web Access (OWA) login pages. Review the details of this Cybersecurity Threat Advisory to safeguard against these vulnerabilities. What is...

/ June 25, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Vulnerabilities in Linux distributions

Cybersecurity Threat Advisory: Vulnerabilities in Linux distributions

Two critical local privilege escalation (LPE) vulnerabilities were disclosed, identified as CVE-2025-6018 and CVE-2025-6019. These vulnerabilities affect all versions of SUSE 15 and libblockdev, two major Linux distributions, allowing unprivileged users to escalate their privileges to root and posing significant...

/ June 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Grafana vulnerability

Cybersecurity Threat Advisory: Critical Grafana vulnerability

A newly disclosed Grafana vulnerability puts thousands of monitoring systems at risk of compromise through a simple malicious link. Review this Cybersecurity Threat Advisory to secure your environment. What is the threat? To exploit CVE-2025-4123, multiple conditions must be met....

/ June 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Veeam vulnerability

Cybersecurity Threat Advisory: Critical Veeam vulnerability

Veeam has released security patches to address a critical vulnerability in its Backup & Replication software, identified as CVE-2025-23121. The flaw allows unauthenticated remote attackers to execute arbitrary code under certain conditions. Review the details of this Cybersecurity Threat Advisory...

/ June 19, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: TP-Link and Zyxel devices targeted

Cybersecurity Threat Advisory: TP-Link and Zyxel devices targeted

Two vulnerabilities are actively targeted by threat actors for exploits, CVE-2023-33538, affects TP-Link routers, and CVE-2023-28771, affects Zyxel firewalls. Review this Cybersecurity Threat Advisory to help mitigate the risk of attackers targeting these vulnerabilities.   What is the threat? CVE-2023-33538...

/ June 18, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Wazuh servers targeted to launch Mirai attacks

Cybersecurity Threat Advisory: Wazuh servers targeted to launch Mirai attacks

Threat actors are actively targeting Wazuh servers running software version 4.4.0 by exploiting a vulnerability that enables them to install Mirai botnets. These botnets facilitate distributed denial of service (DDoS) attacks against victims and execute malicious payloads on the compromised...

/ June 12, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Fortinet vulnerability exploited by Qilin ransomware

Cybersecurity Threat Advisory: Critical Fortinet vulnerability exploited by Qilin ransomware

The Qilin ransomware group is exploiting two critical Fortinet vulnerabilities that allow attackers to bypass authentication and execute remote code on vulnerable systems. Read this Cybersecurity Threat Advisory to discover the tactics used and the best practices you can implement...

/ June 11, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Cisco ISE vulnerability

Cybersecurity Threat Advisory: Critical Cisco ISE vulnerability

The Cisco Identity Services Engine (ISE) has a critical vulnerability, CVE-2025-20286, with a CVSS score of 9.9 out of 10. If successfully exploited, threat actors can gain privileged access without authentication and perform unauthorized operations on vulnerable systems. Read this...

/ June 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Google Chrome zero-day vulnerability

Cybersecurity Threat Advisory: Google Chrome zero-day vulnerability

Google has issued a security update for Chrome desktop to address CVE-2025-5419, which has a CVSS score of 8.8. It is a critical zero-day flaw in the V8 JavaScript engine that is actively exploited by attackers. Continue to read this...

/ June 5, 2025