Tag: Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Trickbot Trojan Continues to Evolve
What is the Issue: A new Trickbot iteration features a sneaky method of performing process-hollowing using direct system calls, anti-analysis techniques and the disabling of security tools. Process-hollowing is a technique used by malware in which a legitimate process is...
Cybersecurity Threat Advisory: DoS Vulnerability in Cisco Web Security Appliance
What is the Issue? There exists a vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances. This happens because of the improper handling of memory resources by this software for TCP connections on any...
Cybersecurity Threat Advisory: Microsoft ADFS Multi-Factor Authentication Bypass
What is the Issue? A vulnerability was discovered in the way multi factor authentication requests are handled by Microsoft’s Active Directory Federation Services (ADFS). It appears that an attacker can compromise a user’s account by bypassing the multi-factor token request....
Cybersecurity Threat Advisory: Bitcoin Blackmail Ransom Emails
What is the Issue? Cyber criminals are sending Bitcoin ransom emails that are attempting to blackmail users into paying ransoms based on leaked password being exposed. These cyber criminals create false narratives that attempt to blackmail you by claiming they...
Cybersecurity Threat Advisory: Drupal, Symfony Component Vulnerability
What is the Issue? Drupal, a free and open source platform that provides an easy framework for creating websites, discovered a vulnerability in its library (called Symfony) that could give cyber attackers access to caches and servers. The vulnerability could...
Cybersecurity Threat Advisory: North Korean Trojan: KEYMARBLE
What is the Issue? A group of security researchers has discovered a new variant of the Spectre attack that allows attackers to steal critical information from targets via network connections. Dubbed ‘NetSpectre’, the new attack improves upon its predecessor in...
Cybersecurity Threat Advisory: NetSpectre Attack can Steal CPU Secrets
What is the Issue? A group of security researchers has discovered a new variant of the Spectre attack that allows attackers to steal critical information from targets via network connections. Dubbed ‘NetSpectre’, the new attack improves upon its predecessor in...
Cybersecurity Threat Advisory: Hidden Malware Inside Images on GoogleUserContent
What is the Issue: Security researchers have discovered a new attack technique utilizing downloadable images from GoogleUserContent sites such as Google+ and blogger forums. Downloaded images can execute scripts that establish backdoors that have long term access to a system...
Cybersecurity Threat Advisory: Windows Desktop Shortcut Hijack
What is the Issue: Security researchers have discovered a new attack technique utilizing Microsoft Word, macros and your desktop shortcuts. Utilizing a malicious macro embedded within a Word document, desktop shortcuts are modified to download malware when you click on...
Cybersecurity Threat Advisory: Unprotected Marketing Database Exposes PII
What is the Issue? On June 27th, an unprotected database belonging to a marketing firm containing 340 million records exposed to the internet was discovered. The database was found by an independent research firm. Why is this noteworthy? The unprotected...