10 min read

[Security Tip] October's Security Threats Summarized

By Prime Care Tech Security Team on Fri, Oct 29, 2021 @ 02:51 PM

Each week our security team tracks threats, vulnerabilities, and patches announced by leading IT experts and vendors to ensure we prioritize and address them for our managed IT services clients. If you're not a client, make sure your team knows about these security events from October 2021, as well as future ones.

Subscribe Yourself or Colleague


High Impact

Source Product Type
AMD Ryzen Chipset Driver Patches for security vulnerabilities
Microsoft NTLM Relay Mitigation advice for PetitPotam attacks 
ManageEngine ADManager Plus Security fix for critical vulnerability
VMware n/a Security update

 

Medium Impact

Source Product Type
FBI n/a Indicators of compromise associated with Hive ransomware
Google Chrome Security updates
Intel Multiple Multiple security updates
Microsoft Multiple Mitigation advice and workarounds for zero-day threat CVE-2021-40444

 

Low Impact

Source Product Type
Atlassian Confluence Server and Data Center Security updates
ManageEngine ServiceDesk Plus Update for remote code execution (RCE) and server-side request forgery (SSRF) vulnerabilities
Microsoft Multiple Security updates (Aug 2021)
Microsoft Multiple Security updates (Sep 2021)
Mozilla Firefox, Firefox ESR, and Thunderbird  Security updates
Pulse Secure Secure Connect Security update
Cisco Multiple Security Updates
Mozilla Firefox, Firefox ESR Security updates
Adobe Multiple Security Updates 
Apple Multiple Security Update to Address CVE-2021-30883
Microsoft Multiple Security Updates (October 2021)
Google Chrome  v95.0.4638.54 for Windows, Mac, and Linux

 

No Impact

Source Product Type
Apple iOS and iPadOS 14.8 Security updates
Citrix ShareFile Storage Zones Controller Security update
Drupal n/a Multiple security updates
FBI-CISA-CGCYBER ManageEngine ADSelfService Plus Advisory on advanced persistent threat (APT) exploitation of vulnerability
Fortinet FortiManager SD-WAN Orchestrator Patch for improper access control vulnerability
Microsoft Azure Linux Open Mgt Infrastructure Security update
SAP Multiple Security updates (Sep 2021)
WordPress WordPress Security update
CISA/NSA Multiple Guidance on Selecting and Hardening VPNs
Apache HTTP Servers Security update
Apache Server Address vulnerabilities under exploitation
CISA Multiple Security Advisory Honeywell Experion and ACE Controllers
CISA n/a Advisory remote users
Juniper Networks Multiple Security Updates
NSA Multiple Guidance on Avoiding the Dangers of Wildcard TLS Certificates and ALPACA Techniques
U.S. Water and Wastewater Systems Sector Facilities Ongoing Cyber Threats
Apache Tomcat (multiple versions) Security advisory to address vulnerability
Cisco IOS XE SD-WAN Software Security updates to address vulnerability
GPSD  v3.20 (Dec 31, 2019) through v3.22 (Jan 8, 2021) GPS Daemon (GPSD) bug
Oracle Multiple Critical patch update (October 2021) to address vulnerabilities 

 

If you're not confident that your organization is on top of weekly security threats, vulnerabilities, and patches, it's time to conduct a cyber security audit.

Conduct Self-Audit Now

Or better, get in touch so we can walk you through the critical items for your security checklist.

Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
3 min read

[Security Tip] Weekly Threats, Vulnerabilities, Patches - Oct 24, 2021

By Prime Care Tech Security Team on Mon, Oct 25, 2021 @ 05:53 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective Week Ending October 24, 2021

High Impact

No new impacts since Oct 3, 2021 report.

 

Medium Impact

No new impacts since September 19, 2021 report.

 

Low Impact

Source

Product(s)

Type

Google Chrome v95.0.4638.54 for Windows, Mac, and Linux

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

Apache Tomcat (multiple versions) Security advisory to address vulnerability
Cisco IOS XE SD-WAN Software Security updates to address vulnerability
Oracle Multiple Critical patch update (October 2021) to address vulnerabilities 
CISA  GPSD v3.20 (Dec 31, 2019) through v3.22 (Jan 8, 2021) GPS (GPSD) Daemon bug alert

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague

Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
3 min read

[Security Tip] Weekly Threats, Vulnerabilities, and Patches - Oct 17, 2021

By Prime Care Tech Security Team on Tue, Oct 19, 2021 @ 12:41 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective Week Ending October 17, 2021

High Impact

No new impacts since Oct 3, 2021 report.

 

Medium Impact

No new impacts since September 19, 2021 report.

 

Low Impact

Source

Product(s)

Type

Adobe Multiple Products Security updates 
Apple Multiple Security update to address CVE-2021-30883
Microsoft Multiple Security updates (Oct 2021)

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

Juniper Networks Multiple Security updates
NSA Multiple Guidance on avoiding dangers of wildcard Transport Layer Security (TLS) certificates and the exploitation of Application Layer Protocols Allowing Cross-Protocol Attacks (ALPACA)
U.S. Water and Wastewater Systems Sector Facilities n/a Ongoing Cyber Threats

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague

Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
3 min read

[Security Tip] Threats, Vulnerabilities, and Patches - Oct 10, 2021

By Prime Care Tech Security Team on Thu, Oct 14, 2021 @ 03:34 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective October 10, 2021

High Impact

No new impacts since Oct 3, 2021 report.

Medium Impact

No new impacts since September 19, 2021 report.

Low Impact

Source

Product

Type

Cisco

Multiple

Security Updates

Mozilla

Firefox, Firefox ESR

Security updates

 

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

CISA

Multiple

Security Advisory Honeywell Experion and ACE Controllers

Apache

HTTP Servers

Security update

Apache

Server

Address Vulnerabilities under exploitation

CISA

n/a

Advisory remote users

CISA

Multiple

Security advisory for Honeywell Experion and ACE controllers

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague
Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats
2 min read

[Security Tip] Threats, Vulnerabilities, and Patches - Oct 3, 2021

By Prime Care Tech Security Team on Tue, Oct 12, 2021 @ 04:36 PM

Does your IT team track reported security threats, vulnerabilities, and patches as often as weekly? We do. In fact, our primeCLOUD customers receive notifications about the impact each week, along with an explanation of how our team is mitigating risk on their behalf. Review last week's summary to understand the potential impacts and interventions. 

Effective October 3, 2021

High Impact

Source

Product(s)

Type

ManageEngine

ADManager Plus

Security fix for critical vulnerability

VMware

n/a

Security update

 

Medium Impact

No new impacts since September 19, 2021 report.

Low Impact

No new impacts since September 19, 2021 report.

No Impact

*Prime Care Tech team assessed and determined our clients are not impacted/using product

Source

Product(s)

Type

CISA/NSA

Multiple

Guidance on selecting and hardening VPNs

 

The constantly increasing demands of securing your data against cyber criminals make it challenging to keep up. If you need help staying on top of your game, get in touch.

What's an IT Assessment?

Perhaps someone from your organization could also benefit from these security alerts?

Subscribe a Colleague
Topics: primeCLOUD cyber security security vulnerabilities cyber criminals security patches security threats

Featured

Posts by Tag

See all