Resources
Learn about CYREBRO’s platform, technology, and capabilities, read about industry insights, watch webinars with cyber experts, and much more in the resources below.
-
Guides & E-books
2022 Attack Vector Landscape Analysis
This report details this attack vector landscape analysis and provides readers with insights that can help inform their cybersecurity strategy in 2022 and beyond.
-
Threat Intelligence
‘OAuth’ Phishing Campaign Targeting ‘Microsoft 365’ Users & Adobe Patches 2 Zero-Days and 8 ACEs
January 27, 2022 Note: this CTI contains 2 alerts: Microsoft Advisory & Apple Updates Phishing Campaign Targeting ‘Microsoft 365’ Users Abuses ‘OAuth Request’ Links Microsoft has recently detected a ‘Consent Phishing’ campaign targeting ‘Microsoft 365’ users in which threat actors abuse ‘OAuth’ request links to allow a malicious app called ‘Upgrade’ to access victims’ email, contacts and…
-
Threat Intelligence
SolarWinds Patches Serv-U Vulnerability Actively Exploited for Log4J Attacks
January 20, 2022 SolarWinds released an update addressing an improper input validation vulnerability in Serv-U. The vulnerability has been actively exploited by threat actors to spread Log4J attacks to internal network devices. The Vulnerability CVE-2021-35247 (CVSS 3.1: 4.3) – Improper Input Validation: The Serv-U web login screen to LDAP authentication was allowing characters that were not…
-
Threat Intelligence
Microsoft Patches 6 Zero-Days & 29 RCEs, 97 Vulnerabilities Overall
January 12, 2022 As part of January’s monthly rollup updates, Microsoft has patched 6 Zero-Days and a total of 29 Remote Code Execution vulnerabilities. Overall, Microsoft has patched 97 vulnerabilities across Windows, Hyper-V, and Office. The Zero-Day Vulnerabilities CVE-2022-21919 (CVSS 3.1: 7.0, High Severity) – Windows User Profile Service Elevation of Privilege Vulnerability. CVE-2022-21874 (CVSS 3.1: 7.8, High Severity) – Windows…
-
Threat Intelligence
Google Patches 37 Chrome Vulnerabilities, 1 Critical RCE
January 06, 2022 Google has released Chrome version 97.0.4692.71, patching 37 vulnerabilities, including 1 Critical ‘use-after-free’ vulnerability, exploitation of which leads to remote code execution (RCE). The RCE Vulnerability CVE-2022-0096, Critical use-after-free in the Storage component. The vulnerability can be exploited remotely, which could have devastating effects ranging from corruption of valid data to the execution of malicious code on…
-
Threat Intelligence
New Log4j Remote Code Execution Vulnerability
Apache has released new patches addressing a Recently Disclosed a Log4j Remote Code Execution Vulnerability
-
Threat Intelligence
Google Patches Critical Vulnerabilities in Chrome
Google has released an emergency update to fix 3 vulnerabilities in Chrome, 2 of them are being exploited in the wild.
-
Threat Intelligence
Cisco Patches Critical IOS XE Software RCE, Apple Patches Zero-Day RCE in Catalina, Google Patches Zero-Day RCE in Chrome
Cisco IOS XE Software, Google Chrome and Apple macOS Catalina vulnerabilities
-
Threat Intelligence
Apple Patches 4 RCE Vulnerabilities in Safari, VMware Patches Critical vCenter Server RCE, NETGEAR Patches Critical RCE in 11 Routers
September 22, 2021 Please note this CTI alert contains 3 Sections – Apple’s Safari, VMware, and NETGEAR vulnerabilities Apple Patches 4 RCE Vulnerabilities in Safari Apple has released a security update to address 4 Remote Code Execution vulnerabilities in Safari. The patches are available for macOS Big Sur and macOS Catalina. The Vulnerabilities CVE-2021-30846 CVE-2021-30848 CVE-2021-30849…
-
Threat Intelligence
Voicenter Data Breach
On September 19th, Voicenter became a victim of a Data Breach and a Ransomware attack.
-
Threat Intelligence
Critical Vulnerability in Microsoft Azure Cosmos DB
August 29, 2021 Microsoft has fixed a critical vulnerability affecting Azure Cosmos DB. Azure Cosmos DB is a globally distributed and fully managed NoSQL database service. The vulnerability The vulnerability gives any Azure user full admin access (read, write, delete) to another customer’s Cosmos DB instances without authorization. The vulnerability has a trivial exploit that doesn’t…
-
Threat Intelligence
F5 Patches High Severity RCE Vulnerability in BIG-IP
August 26, 2021 As part of F5’s monthly security advisory, a high severity Remote Code Execution vulnerability affecting ALL BIG-IP modules was patched. Additionally, F5 has disclosed multiple other vulnerabilities affecting BIG-IP and BIG-IQ products. For the full list of addressed vulnerabilities and mitigations, review the full F5 Monthly Security Advisory. The Vulnerability CVE-2021-23025 (CVSSv3: 7.2, High) An authenticated…