Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical RCE vulnerability

Cybersecurity Threat Advisory: Critical RCE vulnerability

A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2024-21591, has been patched in Juniper Networks’ Junos OS on SRX firewalls and EX switches. Exploitable via an out-of-bounds write, the flaw poses risks of denial-of-service (DoS), RCE attacks, or unauthorized root...

/ January 16, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ivanti zero-day vulnerabilities

Cybersecurity Threat Advisory: Ivanti zero-day vulnerabilities

Two vulnerabilities have been identified in Ivanti Connect Secure and Ivanti Policy Secure Gateways, CVE-2023-46805 and CVE-2024-21887 respectively, which when exploited together allow for unauthenticated remote code execution. These CVEs affect all supported versions of the products. Continue reading this...

/ January 16, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: High-severity WebRTC vulnerability

Cybersecurity Threat Advisory: High-severity WebRTC vulnerability

A critical vulnerability identified as CVE-2023-7024 poses a significant threat to Google Chrome and Microsoft Edge browser users. This high-severity flaw, a heap-based buffer overflow in the WebRTC framework, can lead to remote code execution and potential compromise of sensitive...

/ January 10, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apache Struts2 RCE vulnerability

Cybersecurity Threat Advisory: Apache Struts2 RCE vulnerability

A new vulnerability known as CVE-2023-50164 is being used by attackers to exploit the file upload functionality in Apache Struts2, an open-source framework for developing Java web applications. Barracuda MSP advises users to review this Cybersecurity Threat Advisory and upgrade...

/ January 9, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Google OAuth MultiLogin exploit

Cybersecurity Threat Advisory: Google OAuth MultiLogin exploit

In October of 2023, an exploit was revealed by the threat actor PRISMA. This exploit generated persistent Google cookies through token manipulation. Now, attackers are exploiting a Google OAuth endpoint known as “MultiLogin” to restore expired authentication cookies. This allows...

/ January 3, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: A look back at 2023

Cybersecurity Threat Advisory: A look back at 2023

2023 was an eventful year for our Cybersecurity Threat Advisory series. We highlighted several vulnerabilities exploited in the wild, multiple ransomware groups striking against notable establishments (including targeting MSPs), and an increase in cyber hacktivism due to world events. Below...

/ January 1, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Google OAuth vulnerability

Cybersecurity Threat Advisory: Google OAuth vulnerability

In this Cybersecurity Threat Advisory, we’re looking at a critical Google OAuth vulnerability that allows ex-employees to maintain access to applications such as Slack and Zoom. After off boarding, attackers can achieve access by creating non-Gmail accounts using corporate email...

/ December 22, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

3CX advised customers that the SQL database integration has been disabled due to CVE-2023-49954. Businesses that use MongoDB or any of their web-based customer relationship management (CRM) integration templates are not affected. Read this Cybersecurity Threat Advisory to gain details...

/ December 19, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: End-of-Life firewalls actively exploited

Cybersecurity Threat Advisory: End-of-Life firewalls actively exploited

Sophos recently addressed a critical vulnerability CVE-2022-3236 involving end-of-life (EOL) firewalls that had been actively exploited. The vulnerability prompted Sophos to release patches for unsupported firewalls after reports of successful attacks on these systems surfaced. Read this Cybersecurity Threat Advisory...

/ December 15, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New malware campaign from Log4j security flaw

Cybersecurity Threat Advisory: New malware campaign from Log4j security flaw

The hacker group, known as Lazarus, is linked to a global campaign. It involves an old security flaw found in Log4j to deploy previously unknown remote access trojans (RATs) on compromised hosts. To learn more and limit the impact of...

/ December 14, 2023