Tag CISA

CISA Alerts on Threat Actors Using F5 BIG-IP Cookies for Network Reconnaissance

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding malicious actors exploiting unencrypted persistent cookies from the F5 BIG-IP Local Traffic Manager (LTM) module for reconnaissance within target networks. This technique enables attackers to identify additional non-internet-facing devices, raising significant concerns about potential vulnerabilities in those systems.…

Read MoreCISA Alerts on Threat Actors Using F5 BIG-IP Cookies for Network Reconnaissance

Nation-State Hackers Target Ivanti CSA Vulnerabilities for Network Breaches

A suspected nation-state actor has been detected exploiting three critical vulnerabilities in the Ivanti Cloud Service Appliance (CSA), leveraging these zero-day flaws to conduct a series of targeted cyberattacks. According to Fortinet’s FortiGuard Labs, these vulnerabilities allowed attackers to gain unauthorized access to the CSA, enumerate users, and access their…

Read MoreNation-State Hackers Target Ivanti CSA Vulnerabilities for Network Breaches

CISA Issues Alert on Ongoing Exploitation of Vulnerability in SolarWinds Help Desk Software

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Tuesday the addition of a serious vulnerability affecting SolarWinds Web Help Desk (WHD) software to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes amid indications of active exploitation of the flaw. Identified as CVE-2024-28987, this vulnerability has been assigned…

Read MoreCISA Issues Alert on Ongoing Exploitation of Vulnerability in SolarWinds Help Desk Software

US and Global Partners Blame China for Major Microsoft Exchange Cyberattack

The U.S. government, along with critical allies such as the European Union, the United Kingdom, and NATO, has officially linked a substantial cyberattack on Microsoft Exchange email servers to state-sponsored hacking groups associated with China’s Ministry of State Security (MSS). The attack exploited zero-day vulnerabilities in Microsoft Exchange, which were…

Read MoreUS and Global Partners Blame China for Major Microsoft Exchange Cyberattack

CISA Alerts on Ongoing Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)

A critical vulnerability affecting Microsoft SharePoint, identified as CVE-2024-38094, has been recently incorporated into the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog. This adds urgency as CISA has flagged the issue, citing active exploitation in the wild. This high-severity vulnerability, which carries a CVSS score…

Read MoreCISA Alerts on Ongoing Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)

Fortinet Alerts Users to Critical Vulnerability in FortiManager Currently Being Actively Exploited

Fortinet Confirms Critical Vulnerability in FortiManager Under Active Exploitation Fortinet has identified a significant security vulnerability affecting its FortiManager product, designated as CVE-2024-47575, with a high CVSS score of 9.8. This vulnerability, also referred to as FortiJump, relates to the FGFM protocol utilized for communication between FortiGate devices and FortiManager.…

Read MoreFortinet Alerts Users to Critical Vulnerability in FortiManager Currently Being Actively Exploited

Top 30 Critical Security Vulnerabilities Frequently Targeted by Hackers

In a recent joint advisory, intelligence agencies from Australia, the U.K., and the U.S. have highlighted critical vulnerabilities that were actively exploited during 2020 and 2021. This report underscores how swiftly threat actors can capitalize on publicly disclosed weaknesses in software, posing a significant risk to various organizations worldwide. The…

Read MoreTop 30 Critical Security Vulnerabilities Frequently Targeted by Hackers