Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apache Server Vulnerability

Cybersecurity Threat Advisory: Apache Server Vulnerability

What is the cybersecurity threat? A new flaw recently discovered in Apache allows for local privilege escalation where a person or program that has limited access or privileges (such as a user account) may be able execute code with root...

/ June 9, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: MFA Bypassed via O365 and IMAP Attacks

Cybersecurity Threat Advisory: MFA Bypassed via O365 and IMAP Attacks

What is the threat? Researchers from Proofpoint recently observed over one hundred thousand unauthorized logins across millions of Office 365 and Google Suite cloud users. These illegitimate brute force attacks utilize the Internet Message Access Protocol (IMAP) which bypasses multi-factor...

/ June 9, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Chrome Update Patches Zero-Day Vulnerability

Cybersecurity Threat Advisory: Chrome Update Patches Zero-Day Vulnerability

What is the threat? On Friday, March 1st, Google released an update to patch a vulnerability in its Chrome browser. The vulnerability is currently being exploited in the wild and is a use-after-free flaw in the browser’s FileReader API. This...

/ June 9, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: IRS Reveals Ongoing Threat of Internet Phishing Scams

Cybersecurity Threat Advisory: IRS Reveals Ongoing Threat of Internet Phishing Scams

What is the threat? The IRS warned taxpayers, businesses, and tax professionals about the ongoing threat of internet phishing campaigns that lead to theft of their sensitive information through its ‘Dirty Dozen Campaign’. To protect taxpayer’s confidential data against scams,...

/ June 9, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Considerations following the recent viral ‘Momo’ Challenge

Cybersecurity Threat Advisory: Considerations following the recent viral ‘Momo’ Challenge

What is the threat? There have been recent reports that seemingly innocent videos on YouTube, WhatsApp and other outlets include violence provoking and/or other inappropriate content. These videos have been dubbed the “Momo challenge” similar to last years “Blue Whale...

/ June 8, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Separ Malware Steals Credentials

Cybersecurity Threat Advisory: Separ Malware Steals Credentials

What is the threat? Researchers from Deep Instinct have detected an ongoing phishing campaign being aimed at many organizations located across North America, Southeast Asia, and the Middle East. The campaign has been effectively distributing the credential-stealing malware known as...

/ May 30, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: WordPress Plugin Flaw Allows Complete Website Takeover

Cybersecurity Threat Advisory: WordPress Plugin Flaw Allows Complete Website Takeover

What is the threat? A serious vulnerability in WordPress was recently discovered via the specific plugin known as “Simple Social Buttons.” This add-on enables site editors to insert social media sharing buttons throughout their website in an appealing and accessible...

/ May 29, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Zero-Day Privilege Escalation Vulnerability in Apple’s iOS

Cybersecurity Threat Advisory: Zero-Day Privilege Escalation Vulnerability in Apple’s iOS

What is the threat? Recently, Google’s Project Zero team reported a new zero-day vulnerability discovered in Apple’s iOS. They identified several malicious/fraudulent applications available for download in the app store. These applications leave iPhones susceptible to vulnerabilities that put the...

/ May 28, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Zero Day Microsoft Exchange PrivExchange Vulnerability

Cybersecurity Threat Advisory: Zero Day Microsoft Exchange PrivExchange Vulnerability

What is the threat? Remote attackers can exploit a vulnerability that has been discovered in Microsoft Exchange to gain Domain Controller admin privileges using the credentials of an Exchange Mailbox user. The attacker must exploit a combination of flaws to...

/ May 27, 2019
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RogueRobin Advanced Malware

Cybersecurity Threat Advisory: RogueRobin Advanced Malware

What is the threat? Cyber researchers have recently found that there’s a custom-developed malware known as RogueRobin which uses multiple techniques to upload and download files to/from affected host(s). It was reported that the cyber threat adversary, DarkHydrus, is responsible...

/ May 26, 2019