Resources
Learn about CYREBRO’s platform, technology, and capabilities, read about industry insights, watch webinars with cyber experts, and much more in the resources below.
-
Threat Intelligence
Atlassian Patches Critical Jira Authentication Bypass Vulnerability
April 24, 2022 Atlassian Patches Critical Jira Authentication Bypass Vulnerability Atlassian has issued a security advisory addressing a critical authentication bypass vulnerability affecting Jira and Jira Service Management (non-cloud versions). Exploiting the vulnerability may lead to remote code execution on the affected system. The Vulnerability CVE-2022-0540 (CVSS 3.1: 9.9, Critical) – A vulnerability in Jira…
-
Threat Intelligence
Microsoft Patches Zero-Day Vulnerability in Edge browser Exploited in the Wild
April 17, 2022 Microsoft Patches Zero-Day Vulnerability in Edge browser Exploited in the Wild Following the update of Google Chrome, Microsoft has released an emergency update for Edge, addressing an actively exploited Zero-Day. The updated version is 100.0.1185.44 for Windows, Mac, and Linux. The Vulnerability CVE-2021-4102, High Severity – type confusion weakness in the Chrome V8…
-
Threat Intelligence
Google Chrome 0-Day Vulnerability Exploited in the Wild
April 17, 2022 Google Chrome 0-Day Vulnerability Exploited in the Wild Google has released an emergency update for Chrome, addressing an actively exploited Zero-Day. The updated version is 100.0.4896.127 for Windows, Mac and Linux. The Vulnerability CVE-2021-4102, High Severity – type confusion weakness in the Chrome V8 JavaScript engine. While type confusion vulnerabilities typically cause browser…
-
Threat Intelligence
Microsoft Patches 2 0-Days & 47 RCE Vulnerabilities, Google Patches 5 Chrome RCEs, Apache Patches RCE in ‘Struts 2’
April 14, 2022 Microsoft Patches 2 0-Days & 47 RCE Vulnerabilities, Google Patches 5 Chrome RCEs, Apache Patches RCE in ‘Struts 2’ Microsoft Patches 2 0-Days & 47 RCE Vulnerabilities As part of April’s monthly security rollup updates, Microsoft has patched 2 0-Day and 47 Remote Code Execution vulnerabilities. Overall, Microsoft has patched 119 vulnerabilities across…
-
Threat Intelligence
VMware Patches 3 RCEs & 2 Authentication Bypass Vulnerabilities Affecting Multiple Products
April 7, 2022 VMware Patches 3 RCEs & 2 Authentication Bypass Vulnerabilities Affecting Multiple Products VMware has patched 3 remote code execution vulnerabilities and 2 authentication bypass vulnerabilities. In total, VMware has patched 8 vulnerabilities affecting ‘Workspace One Access’, ‘Identity Manager’, ‘vRealize Automation’, ‘vRealize Suite Lifecycle Manager’, and ‘Cloud Foundation’. The Vulnerabilities CVE-2022-22954 (CVSS 3.1: 9.8, Critical) – Server-side Template Injection. A malicious…
-
Threat Intelligence
Zyxel Patches a Critical Firewall Authentication Bypass Vulnerability
April 5, 2022 Zyxel Patches a Critical Firewall Authentication Bypass Vulnerability Zyxel has released a security advisory addressing a critical authentication bypass vulnerability affecting several firewall models. The Vulnerability CVE-2022-0342 (CVSS 3.1: 9.8, Critical) – An authentication bypass vulnerability which could allow an attacker to bypass the web authentication and obtain administrative access of the device. Vulnerable Products The following…
-
Threat Intelligence
New Log4j Remote Code Execution Vulnerability
Apache has released new patches addressing a Recently Disclosed a Log4j Remote Code Execution Vulnerability
-
Threat Intelligence
Threat Actors Using Omicron COVID-19 Phishing Lures
Recently, CYREBRO has observed an increase in phishing campaigns exploiting the recently emerging ‘Omicron’ Covid-19 variant.
-
Threat Intelligence
Critical Ransomware Risk to Unpatched SonicWall SRA & SMA 8.X
SonicWall has released an URGENT security notice considering a risk to unpatched end-of-life SRA & SMA remote access devices
-
Threat Intelligence
Critical Microsoft Windows Print Spooler Point and Print Arbitrary Code Execution Zero-Day Vulnerability
A new Windows Print Spooler Zero-Day Vulnerability has been detected which allows for non-admin users to be able to install printer drivers via Point and Print.
-
Threat Intelligence
NVIDIA Releases Security Advisory Regarding Log4Shell Affected Products
December 23, 2021 NVIDIA has released a security advisory addressing multiple products vulnerable to the recently reported Log4Shell Vulnerability. The affected products are multiple enterprise environment tools and components. No consumer-grade applications are known to be affected at this point. Affected Products CUDA Toolkit Nsight Eclipse Edition – Prior to version ‘11.0’. DGX Systems –…
-
Threat Intelligence
New Log4j Denial-of-Service Vulnerability
Apache has released Log4j 2.17.0 (Java 8), addressing a newly disclosed denial-of-service vulnerability.