CISA Adds One Known Exploited JetBrains Vulnerability, CVE-2024-27198, to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-27198 JetBrains TeamCity Authentication Bypass Vulnerability CISA urges organizations to review the following JetBrains blog post and apply the necessary updates: Additional Critical Security Issues Affecting TeamCity On-Premises (CVE-2024-27198 and CVE-2024-27199) – Update to 2023.11.4 Now. These types

Continue ReadingCISA Adds One Known Exploited JetBrains Vulnerability, CVE-2024-27198, to Catalog

CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure

Continue ReadingCISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices

CISA Releases One Industrial Control Systems Advisory

  • Post author:
  • Post category:

CISA released one Industrial Control Systems (ICS) advisory on March 7, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-067-01 Chirp Systems Chirp Access CISA encourages users and administrators to review the newly released ICS advisory for technical details and mitigations.

Continue ReadingCISA Releases One Industrial Control Systems Advisory

ICS Advisory: Chirp Systems Chirp Access

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.1 ATTENTION: Exploitable remotely/low attack complexity Vendor: Chirp Systems Equipment: Chirp Access Vulnerability: Use of Hard-coded Credentials 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to take control and gain unrestricted physical access to systems using the affected product. 3. TECHNICAL DETAILS 3.1 AFFECTED

Continue ReadingICS Advisory: Chirp Systems Chirp Access

Cisco Releases Security Updates for Secure Client

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure

Continue ReadingCisco Releases Security Updates for Secure Client