3 min read

[Security Tip] Weekly Threats, Vulnerabilities, and Patches - Oct 17, 2021

By Prime Care Tech Security Team on Tue, Oct 19, 2021 @ 12:41 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective Week Ending October 17, 2021

High Impact

No new impacts since Oct 3, 2021 report.

 

Medium Impact

No new impacts since September 19, 2021 report.

 

Low Impact

Source

Product(s)

Type

Adobe Multiple Products Security updates 
Apple Multiple Security update to address CVE-2021-30883
Microsoft Multiple Security updates (Oct 2021)

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

Juniper Networks Multiple Security updates
NSA Multiple Guidance on avoiding dangers of wildcard Transport Layer Security (TLS) certificates and the exploitation of Application Layer Protocols Allowing Cross-Protocol Attacks (ALPACA)
U.S. Water and Wastewater Systems Sector Facilities n/a Ongoing Cyber Threats

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague

Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
3 min read

[Security Tip] Threats, Vulnerabilities, and Patches - Oct 10, 2021

By Prime Care Tech Security Team on Thu, Oct 14, 2021 @ 03:34 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective October 10, 2021

High Impact

No new impacts since Oct 3, 2021 report.

Medium Impact

No new impacts since September 19, 2021 report.

Low Impact

Source

Product

Type

Cisco

Multiple

Security Updates

Mozilla

Firefox, Firefox ESR

Security updates

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

CISA

Multiple

Security Advisory Honeywell Experion and ACE Controllers

Apache

HTTP Servers

Security update

Apache

Server

Address Vulnerabilities under exploitation

CISA

n/a

Advisory remote users

CISA

Multiple

Security advisory for Honeywell Experion and ACE controllers

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague
Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
2 min read

[Security Tip] Threats, Vulnerabilities, and Patches - Oct 3, 2021

By Prime Care Tech Security Team on Tue, Oct 12, 2021 @ 04:36 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective October 3, 2021

High Impact

Source

Product(s)

Type

ManageEngine

ADManager Plus

Security fix for critical vulnerability

VMware

n/a

Security update

 

Medium Impact

No new impacts since September 19, 2021 report.

Low Impact

No new impacts since September 19, 2021 report.

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

CISA/NSA

Multiple

Guidance on selecting and hardening VPNs

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague
Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
7 min read

[Security Tip] Weekly Threats, Vulnerabilities, and Patches - Sep 27, 2021

By Prime Care Tech Office of Compliance on Mon, Sep 27, 2021 @ 11:50 AM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective Week Ending September 19, 2021

High Impact

Source

Product(s)

Type

Microsoft

NTLM Relay

Mitigation advice for PetitPotam attacks 

AMD Ryzen

Chipset Driver

Patches for security vulnerabilities

 

Medium Impact

Source

Product(s)

Type

Intel

Multiple

Multiple security updates

FBI

n/a

Indicators of compromise associated with Hive ransomware

Google

Chrome

Security updates

Microsoft

Multiple

Mitigation advice and workarounds for zero-day threat CVE-2021-40444

 

Low Impact

Source

Product(s)

Type

ManageEngine

ServiceDesk Plus

Update for remote code execution (RCE) and server-side request forgery (SSRF) vulnerabilities

Pulse Secure

Secure Connect

Security update

 

NOTE: Remediation depends entirely on third-party, sole-source software supplier (Verizon Enterprise Solutions) and new hardware deployment (est. mid-October)

Microsoft

Multiple

Security updates (Aug 2021)

Atlassian

Confluence Server and Data Center

Security updates

Mozilla

Firefox, Firefox ESR, and Thunderbird 

Security updates

Microsoft

Multiple

Security updates (Sep 2021)

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

WordPress

WordPress

Security update

Fortinet

FortiManager
SD-WAN Orchestrator

Patch for improper access control vulnerability

Apple

iOS and iPadOS 14.8

Security updates

SAP

Multiple

Security updates (Sep 2021)

Citrix

ShareFile Storage Zones Controller

Security update

Drupal

n/a

Multiple security updates

Microsoft

Azure Linux Open Mgt Infrastructure

Security update

FBI-CISA-CGCYBER

ManageEngine
ADSelfService Plus

Advisory on advanced persistent threat (APT) exploitation of vulnerability

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague

Topics: cyber security security vulnerabilities cyber criminals security patches security threats

Featured

Posts by Tag

See all