Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical vulnerabilities in SonicWall

Cybersecurity Threat Advisory: Critical vulnerabilities in SonicWall

SonicWall disclosed three critical vulnerabilities affecting the SonicOS firmware. These flaws include an authentication bypass affecting the SSL VPN and SSH management interfaces, which can enable attackers unauthorized access upon successful exploitation. Continue reading this Cybersecurity Threat Advisory for more...

/ January 10, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft Windows zero-click RCE vulnerability

Cybersecurity Threat Advisory: Microsoft Windows zero-click RCE vulnerability

A critical Microsoft Windows Lightweight Directory Access Protocol (LDAP) vulnerability has been discovered, identified as CVE-2024-49112. The flaw has a CVSS severity score of 9.8, representing a major threat to enterprise networks. Continue reading this Cybersecurity Threat Advisory to learn...

/ January 3, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: PAN-OS critical vulnerability

Cybersecurity Threat Advisory: PAN-OS critical vulnerability

A critical vulnerability, tracked as CVE-2024-3393 with a CVSS score of 8.7, has been identified in Palo Alto Networks’ PAN-OS software. This flaw allows unauthenticated attackers to send specially crafted packets that can reboot affected firewalls, leading to potential service...

/ December 31, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Apache Struts 2 vulnerability

Cybersecurity Threat Advisory: Critical Apache Struts 2 vulnerability

The Apache Software Foundation (ASF) has issued a security update to address a critical vulnerability in both end-of-life and current versions of Apache Struts 2. Under specific conditions, this vulnerability could lead to remote code execution (RCE). Review this Cybersecurity...

/ December 30, 2024
Cybersecurity Threat Advisory
The top viewed Cybersecurity Threat Advisories in 2024

The top viewed Cybersecurity Threat Advisories in 2024

2024 was a standout year in cybersecurity. With over 130 Cybersecurity Threat Advisory issued, SmarterMSP.com reflects on the most viewed emerging threats by our audience. From targeted industry attacks to zero-click vulnerabilities and high CVSS flaws, here are the top...

/ December 30, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Three critical Sophos firewall vulnerabilities

Cybersecurity Threat Advisory: Three critical Sophos firewall vulnerabilities

Sophos has disclosed three critical vulnerabilities in its firewall product that could allow remote unauthenticated attackers to perform structured query language (SQL) injection, execute arbitrary code, and gain privileged secure shell (SSH) access to affected devices. Review the details of...

/ December 23, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Adobe ColdFusion vulnerability

Cybersecurity Threat Advisory: Adobe ColdFusion vulnerability

A vulnerability within Adobe ColdFusion could result in arbitrary system file reads and writes. Continue reading this Cybersecurity Threat Advisory to learn how to mitigate your risk. What is the threat? The vulnerability, tracked as CVE-2024-20767, was found within the...

/ December 21, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Windows kernel vulnerability

Cybersecurity Threat Advisory: Critical Windows kernel vulnerability

A pointer dereference weakness was discovered within the Microsoft Kernel Streaming Service that would allow an attacker to escalate their privileges to SYSTEM without any user interaction being required. Review the details in this Cybersecurity Threat Advisory to learn how...

/ December 20, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New social engineering campaign

Cybersecurity Threat Advisory: New social engineering campaign

An active social engineering campaigns uses Microsoft Teams and AnyDesk to deploy DarkGate malware. Attackers are impersonating trusted contacts during Teams calls to deceive victims into installing remote access tools, facilitating unauthorized system access, and deploying the malware. Review the...

/ December 20, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft MFA AuthQuake flaw

Cybersecurity Threat Advisory: Microsoft MFA AuthQuake flaw

A new critical security flaw in Microsoft’s multi-factor authentication (MFA) system has been discovered. It enables attackers to easily bypass the protection and gain unauthorized access to user accounts. Review this Cybersecurity Threat Advisory to learn how to mitigate your...

/ December 19, 2024