Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Root Access by Way of Linux Kernel Bug

Cybersecurity Threat Advisory: Root Access by Way of Linux Kernel Bug

Threat Update Qualys’ research team has discovered a pair of vulnerabilities in the Linux operating system. While one is a local privilege escalation (LPE) vulnerability, the other vulnerability is a stack exhaustion denial-of-service (DOS) vulnerability in the system. Both of...

/ July 28, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ransomware Targets Unpatched, End-of-Life SonicWall Firmware

Cybersecurity Threat Advisory: Ransomware Targets Unpatched, End-of-Life SonicWall Firmware

Threat Update A ransomware campaign using stolen credentials is actively targeting networking device maker SonicWall’s Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running unpatched and end-of-life (EOL) 8.x firmware. The exploitation targets a known vulnerability...

/ July 27, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Patch for FortiManager and FortiAnalyzer Vulnerability

Cybersecurity Threat Advisory: Patch for FortiManager and FortiAnalyzer Vulnerability

Threat Update A patch has been released by Fortinet for their FortiManager & FortiAnalyzer platforms. This critical patch resolves a Use After Free vulnerability (CWE-416) that allowed attackers to execute code as administrators on the targeted device. SKOUT recommends that...

/ July 21, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Windows Print Spooler Elevation of Privilege Vulnerability

Cybersecurity Threat Advisory: Windows Print Spooler Elevation of Privilege Vulnerability

Threat Update Last week, SKOUT released a security advisory regarding the “PrintNightmare” Zero-Day vulnerability exploited via the Windows Print Spooler service. This past weekend, on July 16th, Microsoft identified another vulnerability within the Print Spooler service that allows for local...

/ July 19, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SolarWinds Serv-U Zero-day Exploit

Cybersecurity Threat Advisory: SolarWinds Serv-U Zero-day Exploit

Threat Update SolarWinds, an IT management and remote monitoring software developer that fell victim to the Sunburst supply chain attack, has been exploited again. However, the Serv-U zero day exploit is limited to targeted customer impact according to Microsoft. A...

/ July 16, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Zero-Day Vulnerability in Windows Print Spooler

Cybersecurity Threat Advisory: Zero-Day Vulnerability in Windows Print Spooler

Threat Update Last week, security researchers accidentally published proof-of-concept (PoC) exploit code which has now been dubbed “PrintNightmare”. The vulnerability exploits a critical flaw in Microsoft’s Print Spooler service. Microsoft has issued out-of-band security updates to address the flaw and...

/ July 7, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: 07-06-2021 Kaseya VSA Follow-Up Threat Advisory

Cybersecurity Threat Advisory: 07-06-2021 Kaseya VSA Follow-Up Threat Advisory

Threat Update This Threat Advisory acts as a follow-up to our previously released Advisories “0048-21” and “0049-21”. Kaseya has scheduled an urgent patch for July 6, 2021, between 4:00PM EDT – 7:00PM EDT. The Kaseya VSA vulnerabilities are still un-remediated...

/ July 6, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Kaseya VSA Ransomware Update

Cybersecurity Threat Advisory: Kaseya VSA Ransomware Update

NOTE TO CLARIFY ON AN EARLIER COMMUNICATION: SKOUT Cybersecurity’s product offerings do not use Kaseya in any means and are not impacted by this incident. If you have any questions, please contact the Security Operations Center. Threat Update Kaseya has...

/ July 3, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Kaseya VSA Supply Chain Exploit Distributing Ransomware

Cybersecurity Threat Advisory: Kaseya VSA Supply Chain Exploit Distributing Ransomware

Threat Update On July 2nd, 2021, Kaseya’s Remote Monitoring and Management Platform “Kaseya VSA” was exploited with signs of a sophisticated Supply Chain attack. Kaseya VSA is now actively being used by threat actors to distribute ransomware. Kaseya has taken...

/ July 2, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Buffer Overflow Leads to Partial Memory Leak

Cybersecurity Threat Advisory: Buffer Overflow Leads to Partial Memory Leak

Threat Update On June 23, security researchers reported that SonicWall’s stack-based Buffer Overflow vulnerability from late last year was only partially patched, yielding another attack vector for unpatched systems. A threat actor can send malicious requests to the firewall to...

/ July 2, 2021