CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) that provides an overview of Russian state-sponsored cyber operations, including commonly observed tactics, techniques, and procedures. The CSA also provides detection actions, incident response guidance, and mitigations. CISA, the FBI, and … [Read more...] about CISA, FBI, and NSA Release Cybersecurity Advisory on Russian Cyber Threats to U.S. Critical Infrastructure
Uncategorized
Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird
Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Mozilla security advisories for [Firefox 96], [Firefox ESR 91.5], and [Thunderbird 91.5] and apply the necessary … [Read more...] about Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird
Microsoft Releases January 2022 Security Updates
Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s January 2022 Security Update Summary and Deployment Information and apply the necessary updates. Original release date: … [Read more...] about Microsoft Releases January 2022 Security Updates
Adobe Releases Security Updates for Multiple Products
Original release date: January 11, 2022 Adobe has released security updates to address vulnerabilities in multiple Adobe products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the following Adobe Security Bulletins and apply the necessary updates. Acrobat and … [Read more...] about Adobe Releases Security Updates for Multiple Products
CNMF Identifies and Discloses Malware used by Iranian APT MuddyWater
Original release date: January 12, 2022 U.S. Cyber Command’s Cyber National Mission Force (CNMF) has identified multiple open-source tools used by an Iranian advanced persistent threat (APT) group known as MuddyWater. According to CNMF, “MuddyWater has been seen using a variety of techniques to maintain access to victim networks. These include side-loading DLLs in order to … [Read more...] about CNMF Identifies and Discloses Malware used by Iranian APT MuddyWater