Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

3CX advised customers that the SQL database integration has been disabled due to CVE-2023-49954. Businesses that use MongoDB or any of their web-based customer relationship management (CRM) integration templates are not affected. Read this Cybersecurity Threat Advisory to gain details...

/ December 19, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: End-of-Life firewalls actively exploited

Cybersecurity Threat Advisory: End-of-Life firewalls actively exploited

Sophos recently addressed a critical vulnerability CVE-2022-3236 involving end-of-life (EOL) firewalls that had been actively exploited. The vulnerability prompted Sophos to release patches for unsupported firewalls after reports of successful attacks on these systems surfaced. Read this Cybersecurity Threat Advisory...

/ December 15, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New malware campaign from Log4j security flaw

Cybersecurity Threat Advisory: New malware campaign from Log4j security flaw

The hacker group, known as Lazarus, is linked to a global campaign. It involves an old security flaw found in Log4j to deploy previously unknown remote access trojans (RATs) on compromised hosts. To learn more and limit the impact of...

/ December 14, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Rising concerns over ALPHV ransomware group

Cybersecurity Threat Advisory: Rising concerns over ALPHV ransomware group

In recent weeks, there has been a surge in cyberattacks attributed to the ALPHV ransomware group. Some of the group’s latest hits include attacks against Tipalti, MGM Resorts, Caesars Entertainment, Clorox, McClaren Health Care, Fidelity National Financial, Five Guys, Estée...

/ December 7, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Outlook vulnerability exploited

Cybersecurity Threat Advisory: Critical Outlook vulnerability exploited

Microsoft recently discovered Russian state-sponsored hacker group APT28 (“Fancybear” or “Strontium”) exploiting a critical Outlook flaw to gain access to Microsoft Exchange accounts and steal their critical information. This Cybersecurity Threat Advisory looks at the threat and recommendations to protect...

/ December 6, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: End-of-Life Microsoft Exchange servers exposed

Cybersecurity Threat Advisory: End-of-Life Microsoft Exchange servers exposed

In this Cybersecurity Threat Advisory, we look at how over 20,000 Microsoft (MS) Exchange email servers across Europe, the U.S., and Asia are at risk of cyberattacks due to running on unsupported software versions. These servers are susceptible to numerous...

/ December 5, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Citrix Bleed vulnerability actively exploited

Cybersecurity Threat Advisory: Citrix Bleed vulnerability actively exploited

Recently, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a cybersecurity advisory warning that ransomware groups are actively exploiting the ‘Citrix Bleed’ vulnerability. In this Cybersecurity Threat Advisory, we look at the Citrix...

/ November 29, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New vulnerability for Windows users

Cybersecurity Threat Advisory: New vulnerability for Windows users

A new vulnerability has been identified which could compromise the security of Windows users. The vulnerability discussed in this Cybersecurity Threat Advisory, known as “forced authentication,” gives an attacker access to a user’s NT LAN Manager (NTLM) tokens by tricking...

/ November 28, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ‘LittleDrifter’ extends its reach

Cybersecurity Threat Advisory: ‘LittleDrifter’ extends its reach

This Cybersecurity Threat Advisory sheds light on a recently discovered USB worm identified as “LittleDrifter” has been attributed to the Russia-linked hacker group known as Gamaredon. The worm has spread beyond its presumed intended target, Ukraine, to other countries including...

/ November 28, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Navigating holiday cyber risks

Cybersecurity Threat Advisory: Navigating holiday cyber risks

The holiday season is here, and organizations are facing an increased risk of cyberthreats with a notable focus on the activities of access brokers. These threat actors specialize in gaining and selling unauthorized access to organization accounts by orchestrating social...

/ November 27, 2023 / 13 Comments