You are here

Cybersecurity

Microsoft Releases November 2019 Security Updates

Microsoft has released its monthly update to address vulnerabilities in its software. For this month, Microsoft has released security updates for Microsoft Windows, Internet Explorer, Microsoft Edge (EdgeHTML-based), ChakraCore, Microsoft Office and Microsoft Office Services and Web Apps, Open Source Software, Microsoft Exchange Server, Visual Studio, and Azure Stack. Read the update at Microsoft.

Holiday Shopping, Phishing, and Malware Scams

As this holiday season approaches, the DHS Cybersecurity and Infrastructure Security Agency (CISA) encourages users to be aware of potential holiday scams and malicious cyber campaigns, particularly when browsing or shopping online. Cyber actors may send emails and ecards containing malicious links or attachments infected with malware or may send spoofed emails requesting support for fraudulent charities or causes. CISA encourages users to remain vigilant and take the following precautions:

Fuji Electric V-Server (ICSA-19-311-02)

CISA has published an advisory on a heap-based buffer overflow vulnerability in Fuji Electric V-Server. Versions 4.0.6 and prior are affected. Successful exploitation of this vulnerability could crash the device being accessed; several heap-based buffer overflows have been identified. Fuji Electric has released Version 4.0.7.0 to mitigate the reported vulnerability. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.

Mitsubishi Electric MELSEC-Q Series and MELSEC-L Series CPU Modules (ICSA-19-311-01)

CISA has published an advisory on an uncontrolled resource consumption vulnerability in Mitsubishi Electric MELSEC-Q Series and MELSEC-L Series CPU Modules. Numerous versions of these products are affected. Successful exploitation of this vulnerability may prevent the FTP client from connecting to the FTP server on MELSEC-Q Series and MELSEC-L Series CPU module. Only FTP server function is affected by this vulnerability. Mitsubishi Electric has produced a new version of the firmware. It also strongly recommends that users operate the affected device behind a firewall.

U.S. Cyber Command Shares Seven New Malware Samples

U.S. Cyber Command has released seven malware samples to the malware aggregation tool and repository, VirusTotal. The Cybersecurity and Infrastructure Security Agency (CISA) and WaterISAC encourage users and administrators to review U.S. Cyber Command’s VirusTotal page to view the samples as well as the CISA Tip on Protecting Against Malicious Code for best practices on protecting systems and networks against malware.

Omron CX-Supervisor (ICSA-19-309-01) – Product Used in the Energy Sector

CISA has published an advisory on a use of obsolete function vulnerability in Omron CX-Supervisor. Versions 3.5 (12) and prior are affected. Successful exploitation of this vulnerability could result in information disclosure, total compromise of the system, and system unavailability. Omron recommends users update to CX-Supervisor 3.51 (9). CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.

DHS Releases Updated Tool for Assessing Cybersecurity

The U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) has just released version 9.2 of its Cyber Security Evaluation Tool (CSET). CSET is a desktop software tool intended to guide asset owners and operators through a consistent process for evaluating control system networks as part of a comprehensive cybersecurity assessment that uses recognized government and industry standards and recommendations.

Honeywell equIP and Performance Series IP Cameras (ICSA-19-304-03) – Products Used in the Energy Sector

CISA has published an advisory on a missing authentication for critical function vulnerability in Honeywell equIP and Performance Series IP Cameras. Honeywell reports the vulnerability affects the equIP series IP camera products listed fully Honeywell security notification 2019-09-13 01. Successful exploitation of this vulnerability could result in unauthenticated access. Honeywell has released firmware update packages for all affected products. CISA also recommends a series of measures to mitigate the vulnerability.

Honeywell equIP Series IP Cameras (ICSA-19-304-02) – Products Used in the Energy Sector

CISA has published an advisory on an improper input validation vulnerability in Honeywell equIP series IP cameras. Honeywell reports the vulnerability affects the equIP series IP camera products listed fully Honeywell security notification 2019-09-13 01. Successful exploitation of this vulnerability could result in denial-of-service conditions. Honeywell has released firmware update packages for all affected products listed above. CISA also recommends a series of measures to mitigate the vulnerability.

Pages

Subscribe to Cybersecurity