You are here

Cybersecurity

NCSC Releases Advisory on Ongoing DNS Hijacking Campaign

The United Kingdom’s National Cyber Security Centre (NCSC) has released an advisory about an ongoing Domain Name System (DNS) hijacking campaign. The advisory details risks and mitigations for organizations to defend against this campaign, in which attackers use compromised credentials to modify the location to which an organization’s domain name resources resolve to redirect users, obtain sensitive information, and cause man-in-the-middle attacks.

Is ‘REvil’ the New GandCrab Ransomware?

Despite the cyber criminals behind GandCrab having announced they are shutting down their operation, cybersecurity expert Brian Krebs observes that a growing body of evidence suggests they have instead quietly regrouped behind a more exclusive and advanced ransomware program known variously as “REvil,” “Sodin,” and “Sodinokibi.” In late April, researchers at Cisco Talos discovered the REvil ransomware strain being used to deploy GandCrab.

Schneider Electric Floating License Manager (ICSA-19-192-07) – Product Used in the Energy Sector

The NCCIC has published an advisory on improper input validation and memory corruption vulnerabilities in Schneider Electric Floating License Manager. Versions 2.3.0.0 and earlier are affected. These vulnerabilities could allow an attacker to deny the acquisition of a valid license for legal use of the product. Schneider Electric has made a fix for these vulnerabilities available for download on its website. The NCCIC also advises of a series of measures for mitigating the vulnerabilities.

Schneider Electric Interactive Graphical SCADA System (ICSA-19-192-06) – Product Used in the Energy Sector

The NCCIC has published an advisory on an out-of-bounds write vulnerability in Schneider Electric Interactive Graphical SCADA System. IGSS Version 14 and prior are affected. Successful exploitation of this vulnerability could allow an attacker to achieve arbitrary code execution or crash the software. Schneider Electric recommends upgrading to Version 13.0.0.19140 or 14.0.0.19120. The NCCIC also advises of a series of measures for mitigating the vulnerabilities. Read the advisory at CISA.

AVEVA Vijeo Citect and Citect SCADA Floating License Manager (ICSA-19-192-05) – Product Used in the Energy Sector

The NCCIC has published an advisory on improper input validation and memory corruption vulnerabilities in Vijeo Citect and Citect SCADA Floating License Manager. Floating License Manager version 2.3.0.0 and earlier are affected. These vulnerabilities could allow an attacker to deny the acquisition of a valid license for legal use of the product. AVEVA recommends impacted users upgrade to Floating License Manager (FLM) Version 2.3.1.0 as soon as possible. The NCCIC also advises of a series of measures for mitigating the vulnerabilities.

Siemens SIMATIC RF6XXR (ICSA-19-192-04)

The NCCIC has published an advisory on improper input validation and cryptographic issues vulnerabilities in Siemens SIMATIC RF6XXR. All versions prior to 3.2.1 of RF615R and RF68XR are affected Successful exploitation of these vulnerabilities could allow access to sensitive information. Siemens recommends users upgrade to Version 3.2.1 or newer for both affected products and restrict network access to the device. The NCCIC also advises of a series of measures for mitigating the vulnerabilities.

Pages

Subscribe to Cybersecurity