Resources

Learn about CYREBRO’s platform, technology, and capabilities, read about industry insights, watch webinars with cyber experts, and much more in the resources below.

  • SolarWinds Patches Serv-U Vulnerability Actively Exploited for Log4J Attacks
    Threat Intelligence

    SolarWinds Patches Serv-U Vulnerability Actively Exploited for Log4J Attacks

    January 20, 2022  SolarWinds released an update addressing an improper input validation vulnerability in Serv-U.  The vulnerability has been actively exploited by threat actors to spread Log4J attacks to internal network devices.  The Vulnerability CVE-2021-35247 (CVSS 3.1: 4.3) – Improper Input Validation: The Serv-U web login screen to LDAP authentication was allowing characters that were not…

  • Microsoft Patches 6 Zero-Days & 29 RCEs, 97 Vulnerabilities Overall
    Threat Intelligence

    Microsoft Patches 6 Zero-Days & 29 RCEs, 97 Vulnerabilities Overall

    January 12, 2022 As part of January’s monthly rollup updates, Microsoft has patched 6 Zero-Days and a total of 29 Remote Code Execution vulnerabilities. Overall, Microsoft has patched 97 vulnerabilities across Windows, Hyper-V, and Office. The Zero-Day Vulnerabilities CVE-2022-21919 (CVSS 3.1: 7.0, High Severity) – Windows User Profile Service Elevation of Privilege Vulnerability. CVE-2022-21874 (CVSS 3.1: 7.8, High Severity) – Windows…

  • Google Patches 37 Chrome Vulnerabilities, 1 Critical RCE
    Threat Intelligence

    Google Patches 37 Chrome Vulnerabilities, 1 Critical RCE

    January 06, 2022 Google has released Chrome version 97.0.4692.71, patching 37 vulnerabilities, including 1 Critical ‘use-after-free’ vulnerability, exploitation of which leads to remote code execution (RCE). The RCE Vulnerability CVE-2022-0096, Critical use-after-free in the Storage component. The vulnerability can be exploited remotely, which could have devastating effects ranging from corruption of valid data to the execution of malicious code on…

  • New Log4j Remote Code Execution Vulnerability
    Threat Intelligence

    New Log4j Remote Code Execution Vulnerability

    Apache has released new patches addressing a Recently Disclosed a Log4j Remote Code Execution Vulnerability

  • Threat Actors Using Omicron COVID-19 Phishing Lures
    Threat Intelligence

    Threat Actors Using Omicron COVID-19 Phishing Lures

    Recently, CYREBRO has observed an increase in phishing campaigns exploiting the recently emerging ‘Omicron’ Covid-19 variant.

  • Critical Ransomware Risk to Unpatched SonicWall SRA & SMA 8.X
    Threat Intelligence

    Critical Ransomware Risk to Unpatched SonicWall SRA & SMA 8.X

    SonicWall has released an URGENT security notice considering a risk to unpatched end-of-life SRA & SMA remote access devices