Google Releases Security Updates for ChromeCISA All NCAS Products

Original release date: December 4, 2020Google has released Chrome version 87.0.4280.88 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Chrome Release and apply the necessary updates. This product […]

Google Releases Security Updates for ChromeCISA All NCAS Products Read More »

VMware Releases Security Updates to Address CVE-2020-4006CISA All NCAS Products

Original release date: December 3, 2020VMware has released security updates to address a vulnerability—CVE-2020-4006—in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker could exploit this vulnerability to take control of an affected system.  The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory

VMware Releases Security Updates to Address CVE-2020-4006CISA All NCAS Products Read More »

Heightened Awareness for Iranian Cyber ActivityCISA All NCAS Products

Original release date: December 3, 2020Iranian cyber threat actors have been continuously improving their offensive cyber capabilities. They continue to engage in more conventional offensive cyber activities ranging from website defacement, distributed denial of service (DDoS) attacks, and theft of personally identifiable information (PII), to more advanced activities—including social media-driven influence operations, destructive malware, and,

Heightened Awareness for Iranian Cyber ActivityCISA All NCAS Products Read More »

NCSC Releases 2020 Annual ReviewCISA All NCAS Products

Original release date: December 3, 2020The United Kingdom (UK) National Cyber Security Centre (NCSC) has released its Annual Review 2020, which focuses on its response to evolving and challenging cyber threats. Recognizing cybersecurity as a “team sport,” the publication includes highlights of NCSC’s collaboration with many partners, including the Cybersecurity and Infrastructure Security Agency (CISA).

NCSC Releases 2020 Annual ReviewCISA All NCAS Products Read More »

Apple Releases Security Updates for iCloud for WindowsCISA All NCAS Products

Original release date: December 3, 2020Apple has released security updates to address vulnerabilities in iCloud for Windows. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apple security page for iCloud for Windows 11.5 and

Apple Releases Security Updates for iCloud for WindowsCISA All NCAS Products Read More »

IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply ChainCISA All NCAS Products

Original release date: December 3, 2020IBM X-Force has released a report on malicious cyber actors targeting the COVID-19 cold chain—an integral part of delivering and storing a vaccine at safe temperatures. Impersonating a biomedical company, cyber actors are sending phishing and spearphishing emails to executives and global organizations involved in vaccine storage and transport to

IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply ChainCISA All NCAS Products Read More »

Xerox Releases Security Updates for DocuShareCISA All NCAS Products

Original release date: December 2, 2020Xerox has released security updates for DocuShare 6.6.1, 7.0, and 7.5 to address a vulnerability that could allow an unauthenticated attacker to obtain sensitive information. The Cybersecurity and Infrastructure Security Agency (CISA) urges users and administrators review Xerox Mini Bulletin XRX20W and apply the necessary updates. This product is provided

Xerox Releases Security Updates for DocuShareCISA All NCAS Products Read More »

Mozilla Releases Security Update for ThunderbirdCISA All NCAS Products

Original release date: December 2, 2020Mozilla has released a security update to address a vulnerability in Thunderbird. An attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisory for Thunderbird 78.5.1 and apply the necessary update.

Mozilla Releases Security Update for ThunderbirdCISA All NCAS Products Read More »

Advanced Persistent Threat Actors Targeting U.S. Think TanksCISA All NCAS Products

Original release date: December 1, 2020This Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have observed persistent continued cyber intrusions by advanced persistent threat

Advanced Persistent Threat Actors Targeting U.S. Think TanksCISA All NCAS Products Read More »

Vulnerability Summary for the Week of November 23, 2020CISA All NCAS Products

Original release date: November 30, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available.   High Vulnerabilities Primary Vendor

Vulnerability Summary for the Week of November 23, 2020CISA All NCAS Products Read More »

Scroll to Top