Star Support

We Love Our Clients!

Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server

Today, the CISA, Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) released a joint Cybersecurity Advisory (CSA), Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server. This joint CSA provides IT infrastructure defenders with tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and methods to detect and […]

Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server Read More »

Mozilla Releases Security Updates for Firefox 111 and Firefox ESR 102.9

Mozilla has released security updates to address vulnerabilities in Firefox 111 and Firefox ESR 102.9. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Mozilla’s security advisories for Firefox 111 and Firefox ESR 102.9 for more information and apply the necessary updates. Please share

Mozilla Releases Security Updates for Firefox 111 and Firefox ESR 102.9 Read More »

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server

Notification This report is provided “as is” for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. This document is marked TLP:CLEAR–Disclosure is not limited. Sources

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server Read More »

Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server

SUMMARY From November 2022 through early January 2023, the Cybersecurity and Infrastructure Security Agency (CISA) and authoring organizations identified the presence of indicators of compromise (IOCs) at a federal civilian executive branch (FCEB) agency. Analysts determined that multiple cyber threat actors, including an APT actor, were able to exploit a .NET deserialization vulnerability (CVE-2019-18935) in

Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server Read More »

CISA Announces Ransomware Vulnerability Warning Pilot

Today, CISA is announcing the creation of the Ransomware Vulnerability Warning Pilot (RVWP). Through the RVWP, CISA:      Proactively identifies information systems—belonging to critical infrastructure entities—that contain vulnerabilities commonly associated with ransomware intrusions. Notifies the owners of the affected information systems, which enables the owners to mitigate the vulnerabilities before damaging intrusions occur.  Review

CISA Announces Ransomware Vulnerability Warning Pilot Read More »

Fortinet Releases March 2023 Vulnerability Advisories

Fortinet has released its March 2023 Vulnerability Advisories to address vulnerabilities affecting multiple products. An attacker could exploit one of these vulnerabilities to take control of an affected system.    CISA encourages users and administrators to review the Fortinet March 2023 Vulnerability Advisories page for more information and apply the necessary updates.   

Fortinet Releases March 2023 Vulnerability Advisories Read More »

MAR-10365227-2.v1

Notification This report is provided “as is” for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. This document is marked TLP:WHITE–Disclosure is not limited. Sources

MAR-10365227-2.v1 Read More »