Author: ContentCreator

  • Preparing Critical Infrastructure for Post-Quantum Cryptography

    Original release date: August 24, 2022 CISA has released CISA Insights: Preparing Critical Infrastructure for Post-Quantum Cryptography, which outlines the actions that critical infrastructure stakeholders should take now to prepare for their future migration to the post-quantum cryptographic standard that the National Institute of Standards and Technology (NIST) will publish in 2024.   CISA strongly urges… Read more

  • CISA releases 7 Industrial Control Systems Advisories

    Original release date: August 22, 2022 | Last revised: August 23, 2022 CISA has released 7 Industrial Control Systems (ICS) advisories on August 23, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and… Read more

  • Vulnerability Summary for the Week of August 15, 2022

    Original release date: August 22, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no medium vulnerabilities recorded this week.… Read more

  • CISA Updates Advisory on Threat Actors Exploiting Multiple CVEs Against Zimbra Collaboration Suite

    Original release date: August 22, 2022 CISA and the Multi-State Information Sharing & Analysis Center (MS-ISAC) have updated joint Cybersecurity Advisory AA22-228A: Threat Actors Exploiting Multiple CVEs Against Zimbra Collaboration Suite, originally released August 16, 2022. The advisory has been updated to include additional detection signatures. CISA encourages organizations to review the latest update to… Read more

  • CISA Adds One Known Exploited Vulnerabilities to Catalog

    Original release date: August 22, 2022 CISA has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: to view the newly added vulnerabilities in the catalog, click on the arrow… Read more

  • iPhone Users Urged to Update to Patch 2 Zero-Days

    Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack. Read more

  • CISA releases 5 Industrial Control Systems Advisories

    Original release date: August 18, 2022 CISA has released 5 Industrial Control Systems (ICS) advisories on August 18, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-172-01 Mitsubishi Electric MELSEC iQ-R,… Read more

  • Cisco Releases Security Update for Cisco Secure Web Appliance

    Original release date: August 18, 2022 Cisco has released security updates to address vulnerabilities in Cisco Secure Web Appliance. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page.    CISA encourages users and administrators to review Cisco advisory Cisco Secure… Read more

  • Vulnerability Summary for the Week of August 8, 2022

    Original release date: August 15, 2022 | Last revised: August 16, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were… Read more

  • Threat Actors Exploiting Multiple Vulnerabilities Against Zimbra Collaboration Suite

    Original release date: August 16, 2022 CISA and the Multi-State Information Sharing & Analysis Center (MS-ISAC) have released a joint Cybersecurity Advisory (CSA) in response to active exploitation of multiple vulnerabilities against Zimbra Collaboration Suite (ZCS), an enterprise cloud-hosted collaboration software and email platform.  CISA and MS-ISAC encourage users and administrators review Threat Actors Exploiting Multiple… Read more