Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco Update to Global Intrusion Campaign

Cybersecurity Threat Advisory: Cisco Update to Global Intrusion Campaign

Advisory Overview Cisco has reported that internal machines were compromised within one of their lab environments as a result of the vulnerability found in SolarWinds Orion. There were approximately two dozen computers compromised internally, which have reportedly already been identified...

/ December 23, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Multiple Vulnerabilities in SolarWinds N-Central

Cybersecurity Threat Advisory: Multiple Vulnerabilities in SolarWinds N-Central

Advisory Overview The Center for Internet Security has announced that multiple vulnerabilities have been discovered in SolarWinds N-Central. The SolarWinds N-Central vulnerabilities are not associated with the SolarWinds Orion security incident. SolarWinds has released patches for the vulnerabilities and all...

/ December 23, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft Update to Global Intrusion Campaign

Cybersecurity Threat Advisory: Microsoft Update to Global Intrusion Campaign

Advisory Overview Microsoft has released additional information from their investigation into the SolarWinds Orion incident. Part of their investigation revealed that the threat actors execute multiple levels of privilege escalation and authentication theft after initial compromise through the Orion application....

/ December 23, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SolarWinds Orion Backdoor

Cybersecurity Threat Advisory: SolarWinds Orion Backdoor

Advisory Overview SolarWinds Orion, a prominent IT monitoring and management solution, has been compromised with a backdoor by a sophisticated state-sponsored threat actor. The application has been discovered communicating with unknown third-party servers through traffic deliberately designed to mimic normal...

/ December 14, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FireEye Breach

Cybersecurity Threat Advisory: FireEye Breach

Advisory Overview FireEye, a major cybersecurity organization, has reported a compromise that resulted in the theft of their suite of Red Team tools. While these tools do not contain any zero-day vulnerabilities, only widely known and documented methods, the theft...

/ December 9, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Egregor Ransomware

Cybersecurity Threat Advisory: Egregor Ransomware

Advisory Overview The Ransomware as a Service variant “Egregor” is spiking across the Cybersecurity and IT landscape after the shutdown of the notorious Maze ransomware campaign. Some major organizations have fallen victim to the malware including Kmart, Cencosud (a retail...

/ December 8, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: POS Malware Targeting Restaurants

Cybersecurity Threat Advisory: POS Malware Targeting Restaurants

Advisory Overview Cybersecurity researchers have discovered a modular backdoor known as ModPipe targeting point-of-sale (POS) systems in the hospitality sector. This malware can potentially allow unauthorized retrieval of payment information. SKOUT recommends maintaining updates and patches for all POS systems...

/ November 25, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apple MacOS Big Sur Vulnerabilities

Cybersecurity Threat Advisory: Apple MacOS Big Sur Vulnerabilities

Advisory Overview Apple has deprecated its support for its Network Kernel Extensions (NKE) which are the services that supported local firewalls on previous Mac systems. This change has allowed macOS Big Sur and roughly 50 other applications in Apple’s app...

/ November 23, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Second Patch Released for VMWare Vulnerability

Cybersecurity Threat Advisory: Second Patch Released for VMWare Vulnerability

Advisory Overview A previously discovered remote code execution vulnerability for VMware ESXi has received a second patch from VMware, which should now correctly stop exploitation of the OpenSLP service issue. If an attacker were to attempt to exploit an unpatched...

/ November 16, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ryuk Ransomware Activities Overview

Cybersecurity Threat Advisory: Ryuk Ransomware Activities Overview

Advisory Overview The SKOUT Security Operation Center is closely following the increase of ransomware activity targeting the healthcare sector. Threat actors are infecting critical healthcare providers/facilities networks with the ransomware variant, Ryuk. A successful attack could disable critical healthcare infrastructure...

/ October 29, 2020