top of page

Latest Security Updates

Cyber Career Pathways Tool

Cyber Career Pathways Tool

Welcome to the Cyber Career Pathways Tool! This tool presents a new and interactive way to explore work roles within the NICE Cybersecurity Workforce Framework. It depicts the Cyber Workforce according to five distinct, yet complementary, skill communities.

Date Published:

Wed Aug 26 2020 13:37:04 GMT+0000 (Coordinated Universal Time)

Cyber Career Pathways Tool

Cyber Career Pathways Tool

Welcome to the Cyber Career Pathways Tool! This tool presents a new and interactive way to explore work roles within the NICE Cybersecurity Workforce Framework. It depicts the Cyber Workforce according to five distinct, yet complementary, skill communities.

Date Published:

Tue Aug 25 2020 13:37:03 GMT+0000 (Coordinated Universal Time)

Vulnerability Summary for the Week of June 29, 2020

Vulnerability Summary for the Week of June 29, 2020

Original release date: July 6, 2020
High Vulnerabilities


<table>

<tr>
<th>Primary
Vendor -- Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source & Patch Info</th>
</tr>



<tr>
<td>adobe -- bridge</td>
<td>Adobe Bridge vers…

Date Published:

Mon Jul 06 2020 13:37:04 GMT+0000 (Coordinated Universal Time)

F5 Releases Security Advisory for BIG-IP TMUI RCE vulnerability, CVE-2020-5902

F5 Releases Security Advisory for BIG-IP TMUI RCE vulnerability, CVE-2020-5902

Original release date: July 4, 2020F5 has released a security advisory to address a remote code execution (RCE) vulnerability—CVE-2020-5902—in BIG-IP Traffic Management User Interface (TMUI). An attacker could exploit this vulnerability take control of an aff…

Date Published:

Sat Jul 04 2020 13:37:03 GMT+0000 (Coordinated Universal Time)

Samba Releases Security Updates

Samba Releases Security Updates

Original release date: July 3, 2020The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba. An attacker could exploit some of these vulnerabilities to take control of an affected system.


The Cybersecurity and I…

Date Published:

Fri Jul 03 2020 13:37:02 GMT+0000 (Coordinated Universal Time)

ABB System 800xA Information Manager

ABB System 800xA Information Manager

1. EXECUTIVE SUMMARY

CVSS v3 8.8
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: ABB
Equipment: System 800xA Information Manager
Vulnerability: Cross-site Scripting
2. RISK EVALUATION

Successful exploitation of this vulnerability coul…

Date Published:

Thu Jul 02 2020 13:37:01 GMT+0000 (Coordinated Universal Time)

Mozilla Releases Security Updates for Firefox and Firefox ESR

Mozilla Releases Security Updates for Firefox and Firefox ESR

Original release date: July 2, 2020Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructur…

Date Published:

Thu Jul 02 2020 13:37:01 GMT+0000 (Coordinated Universal Time)

OpenClinic GA

OpenClinic GA

This advisory contains mitigations for multiple vulnerabilities in OpenClinic GA, an open source integrated hospital information management system.

Date Published:

Thu Jul 02 2020 13:37:01 GMT+0000 (Coordinated Universal Time)

Nortek Linear eMerge 50P/5000P

Nortek Linear eMerge 50P/5000P

1. EXECUTIVE SUMMARY

CVSS v3 10.0
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Nortek
Equipment: Linear eMerge 50P/5000P
Vulnerabilities: Path Traversal, Command Injection, Unrestricted Upload of File with Dangerous Type, Cross-site…

Date Published:

Thu Jul 02 2020 13:37:01 GMT+0000 (Coordinated Universal Time)

Cisco Releases Security Updates for Multiple Products

Cisco Releases Security Updates for Multiple Products

Original release date: July 2, 2020Cisco has released security updates to address vulnerabilities in multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure …

Date Published:

Thu Jul 02 2020 13:37:01 GMT+0000 (Coordinated Universal Time)

AA20-183A: Defending Against Malicious Cyber Activity Originating from Tor

AA20-183A: Defending Against Malicious Cyber Activity Originating from Tor

Original release date: July 1, 2020SummaryThis advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) and Pre-ATT&CK framework. See the ATT&CK for Enterprise and Pre-ATT&CK frameworks for referenced threat actor techniques.

T…

Date Published:

Wed Jul 01 2020 13:37:06 GMT+0000 (Coordinated Universal Time)

Microsoft Releases Security Updates for Windows 10, Windows Server

Microsoft Releases Security Updates for Windows 10, Windows Server

Original release date: July 1, 2020Microsoft has released security updates to address vulnerabilities in Windows 10 and Windows Server. These vulnerabilities could allow a remote attacker to take control of an affected system.

The Cybersecurity and Infrastru…

Date Published:

Wed Jul 01 2020 13:37:06 GMT+0000 (Coordinated Universal Time)

EINSTEIN Data Trends – 30-day Lookback

EINSTEIN Data Trends – 30-day Lookback

Original release date: June 30, 2020Cybersecurity and Infrastructure Security Agency (CISA) analysts have compiled the top detection signatures that have been the most active over the month of May in our national Intrusion Detection System (IDS), known as EIN…

Date Published:

Tue Jun 30 2020 13:37:05 GMT+0000 (Coordinated Universal Time)

Industrial Control Systems

Industrial Control Systems

ICS Site Page

Date Published:

Tue Jun 30 2020 13:37:05 GMT+0000 (Coordinated Universal Time)

Delta Industrial Automation DOPSoft

Delta Industrial Automation DOPSoft

1. EXECUTIVE SUMMARY

CVSS v3 7.8
ATTENTION: Low skill level to exploit
Vendor: Delta Electronics
Equipment: Delta Industrial Automation DOPSoft
Vulnerabilities: Out-of-bounds Read, Heap-based Buffer Overflow
2. RISK EVALUATION

Successful exploitation of…

Date Published:

Tue Jun 30 2020 13:37:05 GMT+0000 (Coordinated Universal Time)

Mitsubishi Electric Factory Automation Engineering Software Products

Mitsubishi Electric Factory Automation Engineering Software Products

1. EXECUTIVE SUMMARY

CVSS v3 7.5
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Mitsubishi Electric
Equipment: Factory Automation Engineering Software Products
Vulnerabilities: Improper Restriction of XML External Entity Reference and…

Date Published:

Tue Jun 30 2020 13:37:05 GMT+0000 (Coordinated Universal Time)

Netgear Router Vulnerabilities

Netgear Router Vulnerabilities

Original release date: June 29, 2020Multiple Netgear router models contain vulnerabilities that a remote attacker can exploit to take control of an affected device. 
 
The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administra…

Date Published:

Mon Jun 29 2020 13:37:04 GMT+0000 (Coordinated Universal Time)

Palo Alto Releases Security Updates for PAN-OS

Palo Alto Releases Security Updates for PAN-OS

Original release date: June 29, 2020Palo Alto Networks has released security updates to address a vulnerability affecting PAN-OS. An unauthenticated attacker with network access could exploit this vulnerability to obtain sensitive information.

The Cybersecur…

Date Published:

Mon Jun 29 2020 13:37:04 GMT+0000 (Coordinated Universal Time)

Vulnerability Summary for the Week of June 22, 2020

Vulnerability Summary for the Week of June 22, 2020

Original release date: June 29, 2020 


High Vulnerabilities


<table>

<tr>
<th>Primary
Vendor -- Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source & Patch Info</th>
</tr>



<tr>
<td>apache -- shiro
 </td>
<td>Apache Shir…

Date Published:

Mon Jun 29 2020 13:37:04 GMT+0000 (Coordinated Universal Time)

Apache Releases Security Advisory for Apache Tomcat

Apache Releases Security Advisory for Apache Tomcat

Original release date: June 26, 2020The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An attacker could exploit this vulnerability to cause a denial-of-service condition.

The Cybersecurity and Infras…

Date Published:

Fri Jun 26 2020 13:37:02 GMT+0000 (Coordinated Universal Time)

bottom of page