Security Updates
Security Updates
23
January, 2024
0
NYSED Information Security Office LEA Data Security Review
In response to feedback received from various school districts, we have gathered the following information: The New York State Education Department's (NYSED) Information Security Office issued an important update impacting…
11
January, 2024
Security Alert: Ongoing Stealer Malware Campaigns
In the face of a notable surge in Info Stealer malware campaigns, the cybersecurity landscape demands heightened vigilance. Evolving in sophistication and prevalence, these threats target both individuals and businesses,…
28
September, 2023
High Severity Zero-Day Libwebp Vulnerability
The libwebp vulnerability is a critical issue that is currently being exploited by attackers. This vulnerability affects nearly all operating systems and applications utilizing the libwebp library, including those built…
06
September, 2023
The SEC’s New Cybersecurity Disclosure Requirements
The Securities and Exchange Commission (SEC) has recently introduced new cybersecurity disclosure requirements, also known as the "Final Rules," that apply to all SEC filers, including domestic issuers, foreign private…
24
July, 2023
Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-3519
Overview of CVE-2023-3519 Vulnerability A recent Citrix alert warns of multiple vulnerabilities impacting Citrix Netscaler AD and NetScaler Gateway products. Of those vulnerabilities, only CVE-2023-3519 is of critical severity, with…
21
July, 2023
The White House’s Implementation Plan for its National Cybersecurity Strategy
Overview: A Roadmap for the National Cybersecurity Strategy The White House released its implementation plan for the National Cybersecurity Strategy (the Strategy) unveiled in March 2023. The plan provides a…
27
June, 2023
NYC MOVEit Data Breach
MOVEit is a file-sharing software that private companies and government sectors use to transfer documents and data safely. However, it was recently hacked and leaked data of almost 45,000 students…
01
June, 2023
Custom Malware Infects Barracuda’s ESG
Zero-day vulnerability from 2022 has been used by threat actors to infect Barracuda's Email Security Gateway (ESG) with custom malware. Barracuda Networks, a popular email security appliance installed in over…
26
May, 2023
Apple’s Rapid Security Response Update
Apple recently released a Rapid Security Response update, which aims to provide important security improvements between software updates. This update addresses two zero-day vulnerabilities in Apple Webkit that were actively…
22
May, 2023
New .zip Top-Level Domain Used In Phishing Attacks
Recently, Google introduced eight new top-level domains available for purchase, including .zip. However, cybersecurity experts are concerned about the potential for malicious activity with this TLD. The similarity to the…