---
title: VLCM Cybersecurity Alerts - September 2019
description: VLCM urges customers to stay informed, implement the recommended protections and let us help you stay secure!
---

[VLCM Blogs - Learn How To Get IT Right ](https://blog.vlcm.com/blog)

# [VLCM Cybersecurity Alerts - September 2019](https://blog.vlcm.com/blog/cybersecurity-september-2019)

 Written by [Joseph Warner](https://blog.vlcm.com/blog/author/joseph-warner) | Oct 1, 2019 10:16:17 PM

 

 

*The month of September came in with a Hurricane named Dorian and a flurry of fraudulent email scams following close behind.  There were lots of update notifications from the usual vendors, including a high-profile update for the Exim email server that fixes *[*critical vulnerabilities*](https://www.zdnet.com/article/millions-of-exim-servers-vulnerable-to-root-granting-exploit/)* that are being actively exploited.  There were also numerous articles provided by the FBI, Multi-State Information Sharing & Analysis Center (MS-ISAC), the Cybersecurity and Infrastructure Security Agency (CISA) and even the United Kingdom (UK) National Cyber Security Centre (NCSC) and the Canadian Centre for Cyber Security (CCCS) with guidance covering social media, more guidance on ransomware protection and information focused on helping students and children stay safe online.  The month of October is known for ghosts and goblins but it's also *[*National Cybersecurity Awareness Month (NCSAM)*](https://staysafeonline.org/ncsam/)* so check this blog often for related news!*

 

## Prepare for National Cybersecurity Awareness Month

September 30, 2019

October is National Cybersecurity Awareness Month (NCSAM), which is a collaborative effort between the Cybersecurity and Infrastructure Security Agency (CISA) and its public and private partners—[including the National Cyber Security Alliance (NCSA)](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstaysafeonline.org%2Fabout%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C981f2bd7fc434f33415508d745f56e40%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637054792733926901&sdata=T%2F1Ae9zSFHd3M2ZTlDY5Q4SPaaC6cc3A1yADSxMVF%2FI%3D&reserved=0)—to ensure every American has the resources they need to stay safe and secure online while increasing the resilience of the Nation against cyber threats. This year’s theme, “Own IT. Secure IT. Protect IT.,” focuses on promoting personal accountability and positive behavior when it comes to cybersecurity.

CISA encourages organizations to see the [NCSAM 2019 webpage](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fniccs.us-cert.gov%2Fnational-cybersecurity-awareness-month-2019&data=02%7C01%7Cjwarner%40vlcmtech.com%7C981f2bd7fc434f33415508d745f56e40%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637054792733926901&sdata=FFCVEy9VUPeJyNKTXJraJqlYl9MLyHAyGyzZQhKOesQ%3D&reserved=0) and the [NCSAM 2019 Toolkit](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fniccs.us-cert.gov%2Fsites%2Fdefault%2Ffiles%2Fdocuments%2Fpdf%2Fdhs_ncsam2019_toolkit_508c.pdf%3FtrackDocs%3Ddhs_ncsam2019_toolkit_508c.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7C981f2bd7fc434f33415508d745f56e40%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637054792733936900&sdata=kDIitTXZk9phRM%2FtGIPfqA9dxg90Zj42s8%2F2jXZTEbM%3D&reserved=0) for ways to participate in and promote NCSAM.

 

## MS-ISAC Releases Advisory on PHP Vulnerability

September 27, 2019

The Multi-State Information Sharing & Analysis Center (MS-ISAC) has released an advisory on a vulnerability in Hypertext Preprocessor (PHP). An attacker could exploit this vulnerability to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review MS-ISAC Advisory [2019-101](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisecurity.org%2Fadvisory%2Fa-vulnerability-in-php-could-allow-for-arbitrary-code-execution_2019-101%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cd5cb3328e3f345d8956508d743829a54%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637052100536872166&sdata=xEPsqK519N7Ih%2B%2Fq157GbtrBZAQUnDkcSqSbvChJ7pM%3D&reserved=0) and the [PHP Downloads](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.php.net%2Fdownloads.php%23gpg&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cd5cb3328e3f345d8956508d743829a54%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637052100536872166&sdata=kLnvvrvULbVW43zaR1eCsMLPWL%2B%2FpIhhr7X1TAmaI%2Fo%3D&reserved=0) page and apply the necessary update.

 

## Apple Releases Security Updates

September 27, 2019

Apple has released security updates to address a vulnerability in multiple products. A remote attacker could exploit this vulnerability to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apple security pages for the following products and apply the necessary updates:

- [macOS Mojave 10.14.6 Supplemental Update 2, Security Update 2019-005 High Sierra, and Security Update 2019-005 Sierra](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fen-us%2FHT210589&data=02%7C01%7Cjwarner%40vlcmtech.com%7C1636e7f0e91a47ed079808d743657aa8%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637051975472481682&sdata=hK0N1q3AlEDPFuEmQDfUtLp600OksvMtdOf%2Ff2Ph9k0%3D&reserved=0)
- [watchOS 5.3.2](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fen-us%2FHT210589&data=02%7C01%7Cjwarner%40vlcmtech.com%7C1636e7f0e91a47ed079808d743657aa8%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637051975472491687&sdata=SBQS3J6mpMY7Pl3E0QpA3WBtvkGjRX2hcVZAk80CuIY%3D&reserved=0)
- [iOS 12.4.2](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fen-us%2FHT210590&data=02%7C01%7Cjwarner%40vlcmtech.com%7C1636e7f0e91a47ed079808d743657aa8%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637051975472491687&sdata=4SKKGSWHCiRmodh43IMFj%2B5NDmwCJmgUmlbMEkq4aBU%3D&reserved=0)

 

## Cisco Releases Security Advisories

September 26, 2019

Cisco has released security updates to address vulnerabilities affecting multiple Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Cisco [Security Advisories page](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2FpublicationListing.x&data=02%7C01%7Cjwarner%40vlcmtech.com%7C00b0c3f1849f421df97508d74294bed4%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637051078950272577&sdata=WK4WybFAO5%2FHIDkJPNVUTIPfrO6kxwkiw7R3Qq%2Bx0zA%3D&reserved=0) and apply the necessary updates.

 

## Canadian Centre for Cyber Security Releases Advisory on New Ransomware Campaign

September 25, 2019

The Canadian Centre for Cyber Security (CCCS) has released an advisory on a new ransomware campaign. The malware, named TFlower, may infect users via exposed, unpatched Remote Desktop Protocol (RDP) services.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages administrators to review CCCS’s [TFlower Ransomware Campaign Advisory](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcyber.gc.ca%2Fen%2Falerts%2Ftflower-ransomware-campaign&data=02%7C01%7Cjwarner%40vlcmtech.com%7C7da486233dd24cbdc7ed08d741eacb2c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637050349014085104&sdata=rL4igigscdMuNsDIDc8w7vAgsJM2UF14Y9AxdCZYq94%3D&reserved=0) for recommended mitigations and refer to [CISA’s resource page on ransomware](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2FRansomware&data=02%7C01%7Cjwarner%40vlcmtech.com%7C7da486233dd24cbdc7ed08d741eacb2c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637050349014085104&sdata=ScbWr7QhA0CBRj3tpt63Gg03VTZ4ccj5dzk%2FDG6wtMY%3D&reserved=0) for more information on protecting against ransomware.

## VMware Releases Security Updates

September 25, 2019

VMware has released security updates to address vulnerabilities in Cloud Foundation and Harbor Container Registry for Pivotal Cloud Foundry. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory [VMSA-2019-0015](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.vmware.com%2Fsecurity%2Fadvisories%2FVMSA-2019-0015.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cc840554a91cf4bcfe53508d741d9721b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637050274484461807&sdata=TbxkkM4Ra4jq5wn%2F3v35PP0Qud8srQygsz%2B2zLdIBAc%3D&reserved=0) and apply the necessary updates and workarounds.

 

## Adobe Releases Security Updates for ColdFusion

September 25, 2019

Adobe has released security updates to address vulnerabilities in ColdFusion. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Adobe Security Bulletin [APSB19-47](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fhelpx.adobe.com%2Fsecurity%2Fproducts%2Fcoldfusion%2Fapsb19-47.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7C062c6e2729f64b2a706b08d741d68e62%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637050262114180594&sdata=FYrGmwjwkvUupJzpn65TgbECPi%2FEFwQ1EfYPqnQ8OdE%3D&reserved=0) and apply the necessary updates.

 

## Microsoft Releases Out-of-Band Security Updates

September 23, 2019

Microsoft has released out-of-band security updates to address vulnerabilities in Microsoft software. A remote attacker could exploit of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Microsoft Security Advisories for [CVE-2019-1367](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fportal.msrc.microsoft.com%2Fen-US%2Fsecurity-guidance%2Fadvisory%2FCVE-2019-1367&data=02%7C01%7Cjwarner%40vlcmtech.com%7Caa19f19de8ac46b74e4908d7405e1b2f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637048645256633770&sdata=xFS76VsP%2FDnkhB8YuK0eMXM%2FA%2FMTW39KNwaFdLvzMis%3D&reserved=0), [CVE-2019-1255,](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fportal.msrc.microsoft.com%2Fen-US%2Fsecurity-guidance%2Fadvisory%2FCVE-2019-1255&data=02%7C01%7Cjwarner%40vlcmtech.com%7Caa19f19de8ac46b74e4908d7405e1b2f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637048645256643765&sdata=Ud8oKMW0bqC2tFZGpxYUlbO9tUER%2Bmn15wxws15tg0c%3D&reserved=0) and Microsoft’s [Cumulative security update for Internet Explorer](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F4522007%2Fcumulative-security-update-for-internet-explorer&data=02%7C01%7Cjwarner%40vlcmtech.com%7Caa19f19de8ac46b74e4908d7405e1b2f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637048645256643765&sdata=KBBeZv11rMCfkwyq0UKMcPb64D6Em9TB6dzsGK7NTnM%3D&reserved=0) and apply the necessary updates.

 

## VMware Releases Security Updates for Multiple Products

September 20, 2019

VMware has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory [VMSA-2019-0014](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.vmware.com%2Fsecurity%2Fadvisories%2FVMSA-2019-0014.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7C880ca547e25d4be8584208d73df5c73b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637045998144606605&sdata=mZTlfmyllKYcq0WEaJIyRNfCjMvMYst3OubQSTeiAZg%3D&reserved=0) and apply the necessary updates.

 

## CISA Releases Four New Insights Products

September 20, 2019

The Cybersecurity and Infrastructure Security Agency (CISA) has released four new CISA Insights products informed by U.S. intelligence and real-world events. Each of the following products provides a description of the threat, lessons learned, recommendations, and additional relevant resources:

- [Mitigate DNS Infrastructure Tampering](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2FCISAInsights-Cyber-MitigateDNSInfrastructureTampering_S508C.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf244f88df21e4e4ba26c08d73ddd6056%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637045893326059344&sdata=OzYYBOA9dFnlHdIbHmmunV7DFIFE6NZP8mUaudXtGPs%3D&reserved=0)
- [Remediate Vulnerabilities for Internet-Accessible Systems](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2FCISAInsights-Cyber-RemediateVulnerabilitiesforInternetAccessibleSystems_S508C.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf244f88df21e4e4ba26c08d73ddd6056%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637045893326069337&sdata=tY8ryxSrbOj81aEFFveBu717HX52cZTaVt7htUyQXjY%3D&reserved=0)
- [Secure High Value Assets](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2FCISAInsights-Cyber-SecureHighValueAssets_S508C.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf244f88df21e4e4ba26c08d73ddd6056%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637045893326069337&sdata=XD7XZwGFlDbxlCRdI%2B13kEKDhMzvT3aloTHU39bK0dU%3D&reserved=0)
- [Enhance Email and Web Security](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2FCISAInsights-Cyber-EnhanceEmailandWebSecurity_S508C.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf244f88df21e4e4ba26c08d73ddd6056%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637045893326079330&sdata=ZbHwkofn1X4YZOe2OVjLKvKE%2FjcUe1VsG97wGdXJA2g%3D&reserved=0)

CISA urges organizations to review the updated [CISA Insights page](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisa.gov%2Finsights&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf244f88df21e4e4ba26c08d73ddd6056%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637045893326089323&sdata=3XZofTGUw5qxDmcOmkXnfUwgzxWJsESrRqVfl5DEDFE%3D&reserved=0) and implement the recommendations.

 

## Google Releases Security Updates for Chrome

September 19, 2019

Google has released Chrome 77.0.3865.90 for Windows, Mac, and Linux. This version addresses a vulnerability that an attacker can exploit to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the [Chrome Release](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fchromereleases.googleblog.com%2F2019%2F09%2Fstable-channel-update-for-desktop_18.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cb2dceb1284f5468de69f08d73d135043%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637045025479760922&sdata=Y8O5cSa8MmogOM7e30OOeBNaPE%2BKy6OPUZIHjQDeEi4%3D&reserved=0) and apply the necessary updates.

## VMware Releases Security Updates for Multiple Products

September 17, 2019

VMware has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security Advisory [VMSA-2019-0013](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.vmware.com%2Fsecurity%2Fadvisories%2FVMSA-2019-0013.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cb8384bcbc628474e011d08d73b8b380c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637043341437217919&sdata=yVIbM9n4AYe28GPcuLDh4hACxNTDeWygrpW4FSmsZno%3D&reserved=0) and apply the necessary updates and workarounds.

## 2019 CWE Top 25 Most Dangerous Software Errors

September 17, 2019

MITRE has released the 2019 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Errors list. The Top 25 is a compilation of the most frequent and critical errors that can lead to serious vulnerabilities in software. An attacker can often exploit these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the [Top 25 list](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcwe.mitre.org%2Ftop25%2Farchive%2F2019%2F2019_cwe_top25.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7C070067c521b4434c61ad08d73b80f7b2%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637043297408298624&sdata=v9L3fuCkR4qURNlnWsrx8SRfZJeBIPi%2Fg%2BMf8hjsCoQ%3D&reserved=0) and evaluate recommended mitigations to determine those most suitable to adopt.

 

## Intel Releases Security Updates

September 10, 2019

Intel has released security updates to address vulnerabilities in multiple products. An attacker could exploit one of these vulnerabilities to gain an escalation of privileges on a previously infected machine.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Intel's Security Advisories [INTEL-SA-00290](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.intel.com%2Fcontent%2Fwww%2Fus%2Fen%2Fsecurity-center%2Fadvisory%2Fintel-sa-00290.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cc95771c6f01847cba8c108d7365ac3d4%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037635808182265&sdata=1lEDpiFRcX2WVGIAM3NjTIC83XIefoRBtB%2B41iP9j3w%3D&reserved=0) and [INTEL-SA-00285](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.intel.com%2Fcontent%2Fwww%2Fus%2Fen%2Fsecurity-center%2Fadvisory%2Fintel-sa-00285.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cc95771c6f01847cba8c108d7365ac3d4%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037635808192261&sdata=pW1%2F80%2BApXfY8lqpTmLy%2FuLOjFHGDrG6qcn6qgqdpOE%3D&reserved=0) and apply the necessary updates.

 

## Google Releases Security Updates for Chrome

September 10, 2019

Google has released Chrome version 77.0.3865.75 for Windows, Mac, and Linux. This version addresses multiple vulnerabilities that an attacker could exploit to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the [Chrome Releases](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fchromereleases.googleblog.com%2Fsearch%2Flabel%2FStable%2520updates&data=02%7C01%7Cjwarner%40vlcmtech.com%7C050f4d9997114490677508d7364bf733%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037572212398934&sdata=cz0sc969LJDJiolN1MIvd2bQHSlfPb38t9OUv9C9kGk%3D&reserved=0) page and apply the necessary updates.

 

## MS-ISAC Releases Security Event Primer on Malware

September 10, 2019

The Multi-State Information Sharing & Analysis Center (MS-ISAC) has released a Security Event Primer on Malware. The white paper outlines general malware operations and includes common malware event types and best practice recommendations. An attacker can use malware to gain access to a network, obtain sensitive data, and damage systems.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review MS-ISAC’s White Paper: [Security Event Primer – Malware](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisecurity.org%2Fwhite-papers%2Fsecurity-event-primer-malware%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cdc529cf8b0e144c32b9208d736338be5%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037467334607858&sdata=nTqw%2FyiwAZnyOefbyd5KgpHbYKFYGuZtxu2M5FRcm2M%3D&reserved=0), see CISA’s Tip on [Protecting Against Malicious Code](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST18-271&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cdc529cf8b0e144c32b9208d736338be5%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037467334617853&sdata=7L4oh%2FOytpdfJYOp8pfTy%2BHlO65hLSd0i19RRyOjZsk%3D&reserved=0), and implement the recommended best practices.

 

## Adobe Releases Security Updates

September 10, 2019

Adobe has released security updates to address vulnerabilities affecting Flash Player and Application Manager. An attacker could exploit these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Adobe Security Bulletins [APSB19-45](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fhelpx.adobe.com%2Fsecurity%2Fproducts%2Fapplication_manager%2Fapsb19-45.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cbf8fcc3f78834d7bca3c08d736259dee%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037407507415771&sdata=4CUpCOqdByH3u9lb4tgeVimpeHwY1zEcYihvSUQFKYQ%3D&reserved=0) and [APSB19-46](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fhelpx.adobe.com%2Fsecurity%2Fproducts%2Fflash-player%2Fapsb19-46.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cbf8fcc3f78834d7bca3c08d736259dee%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037407507425765&sdata=GasEPHCs1qMRO1T4NhN4hfPyYYA2%2Fxi2SwGepVr2FYs%3D&reserved=0) and apply the necessary updates.

 

## Microsoft Releases September 2019 Security Updates

September 10, 2019

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Microsoft’s September 2019 [Security Update Summary](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fportal.msrc.microsoft.com%2Fen-us%2Fsecurity-guidance%2Freleasenotedetail%2F24f46f0a-489c-e911-a994-000d3a33c573&data=02%7C01%7Cjwarner%40vlcmtech.com%7C69ccbcdacc5540786f3608d7361c2971%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037366900094720&sdata=alFxgRFA6V6jbveXwGomP25wjoqNSqwrUXjeNIExg1U%3D&reserved=0) and [Deployment Information](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F20190910%2Fsecurity-update-deployment&data=02%7C01%7Cjwarner%40vlcmtech.com%7C69ccbcdacc5540786f3608d7361c2971%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637037366900094720&sdata=Dl%2Fl6dKRWGlk1QmbV6fUcKpSKg%2Fqb1FI%2FXG%2FWriqbNs%3D&reserved=0) and apply the necessary updates.

## North Korean Malicious Cyber Activity

September 9, 2019

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have identified two malware variants—referred to as ELECTRICFISH and BADCALL—used by the North Korean government. The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDEN COBRA.

CISA encourages users and administrators to review the [HIDDEN COBRA - North Korean Malicious Cyber Activity](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2FHIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cf73c607633a043d5f52508d735535c06%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637036504464258572&sdata=INrsLf%2B%2FZBn69nElq5Cqo2ouOGUIh7urYi8Ct2W%2B%2F38%3D&reserved=0) page, which contains links to Malware Analysis Reports MAR-10135536-21 and MAR-10135536-10, for more information.

 

## FBI Safe Online Surfing Challenge

September 9, 2019

The Federal Bureau of Investigation (FBI) has launched the Safe Online Surfing (SOS) Challenge, encouraging educators to promote web literacy and safety for students during the 2019-20 school year. FBI developed the program to educate children on how to navigate the web securely using activities that correspond with specific grade levels. Public, private, and home schools with at least five students are eligible to participate in the online challenge.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users to review the [FBI SOS Challenge Announcement](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.fbi.gov%2Fnews%2Fstories%2Fsafe-online-surfing-challenge-opens-090519&data=02%7C01%7Cjwarner%40vlcmtech.com%7C56d88a0894e445cb58f908d73541bb3f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637036428761201102&sdata=oewLqQhZwxoNV4%2Bf11JSP3tnHMTPNXyRiWz1raBhOIo%3D&reserved=0) and the CISA Tip [Keeping Children Safe Online](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST05-002&data=02%7C01%7Cjwarner%40vlcmtech.com%7C56d88a0894e445cb58f908d73541bb3f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637036428761201102&sdata=%2FxywPcszw16JX130IQbTJiTs24gpXQDyPZ9TKTbIUxw%3D&reserved=0).

 

## U.S. Cyber Command Shares 11 New Malware Samples

September 8, 2019

U.S. Cyber Command has released 11 malware samples to the malware aggregation tool and repository, VirusTotal. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review U.S. Cyber Command’s [VirusTotal page](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.virustotal.com%2Fen%2Fuser%2FCYBERCOM_Malware_Alert%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca765ce90301445888ff708d73483889f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637035611862091612&sdata=MfyxSO53m9l7%2BE695rBK%2Bos8gv52mB%2BkS5AnuEHC8bo%3D&reserved=0) to view the samples. CISA also recommends users and administrators review the CISA Tip on [Protecting Against Malicious Code](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST18-271&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca765ce90301445888ff708d73483889f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637035611862091612&sdata=4SYRf9%2B%2FLncFzD24gY9OSouGXfXQj9RL2XCqihJ6gzM%3D&reserved=0) for best practices on protecting systems and networks against malware.

 

## Ransomware Protection Strategies

September 6, 2019

The Cybersecurity and Infrastructure Security Agency (CISA) has observed an increase in ransomware attacks across the Nation. Helping organizations protect themselves from ransomware is a chief priority for CISA. Organizations are encouraged to review the following resources to help prevent, mitigate, and recover against ransomware:

- [CISA Insights: Ransomware Outbreak](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fsites%2Fdefault%2Ffiles%2F2019-08%2FCISA_Insights-Ransomware_Outbreak_S508C.pdf&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186671381&sdata=wHzlnnqSkT7rmznYEl8JpzH33yHZjXnaV0pK7v%2FHbqw%3D&reserved=0)
- [CISA resource page on ransomware](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2FRansomware&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186681376&sdata=BBPFlJaq5NSkdFZ8Yhw7mX3bhUH2HbQGYcp%2Bzv8wvd4%3D&reserved=0)
- [FireEye blog and report on ransomware protection and containment strategies](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.fireeye.com%2Fblog%2Fthreat-research%2F2019%2F09%2Fransomware-protection-and-containment-strategies.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186691377&sdata=kZ4%2B2GbxZJw43DA54Ao2TJJ%2FzSyuaQ1F9mCYpa5ZtUE%3D&reserved=0)

Victims of ransomware should report it immediately to [CISA](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.govwww.us-cert.gov%2Freport&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186691377&sdata=3Cx7RgJ3D%2FawW3sJo9i5U%2B6AO9ZuzbVLl0kYgdUuBBM%3D&reserved=0), a local [FBI Field Office](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.fbi.gov%2Fcontact-us%2Ffield-offices%2Ffield-offices&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186701374&sdata=PiJ6NBRwbxM5kRSBFHBTDp5eR2hdWsYYn%2FGpwb9hkf4%3D&reserved=0), or a [Secret Service Field Office](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.secretservice.gov%2Fcontact%2Ffield-offices%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C8084b2ca015b4d44afba08d732f666df%7Cd4c6fc04732f42258730f686adab6818%7C1%7C1%7C637033906186701374&sdata=U6Qe7r8GJav5C1jZVfhYZUZB4sw0wxeZWi4PJ5vi6%2FM%3D&reserved=0).

## Exim Releases Security Patches

September 6, 2019

Exim has released patches to address vulnerabilities affecting Exim 4.92.1 and prior versions. A remote attacker could exploit this vulnerability to take control of an affected email server.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Exim [CVE-2019-15846](https://nam01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fexim.org%2Fstatic%2Fdoc%2Fsecurity%2FCVE-2019-15846.txt&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cc7d0535e993643589c5508d732efb32d%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637033877419402509&sdata=GLIWwGamUA1BATGIctPHHJB2AmlWGA%2FzxIGxQMdwH%2F4%3D&reserved=0) page and upgrade to Exim 4.92.2 or apply the necessary patches.

 

## WordPress Releases Security Update

September 6, 2019

WordPress 5.2.2 and prior versions are affected by multiple vulnerabilities. An attacker could exploit some of these vulnerabilities to take control of an affected website.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the [WordPress Security and Maintenance Release](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwordpress.org%2Fnews%2F2019%2F09%2Fwordpress-5-2-3-security-and-maintenance-release%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C5546b1573a4245eee00e08d732e57a9f%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637033833489180684&sdata=ZoPNw4zo8RhPW9cAqAO31%2B52fKTLvW%2FxU1Hh3FOXmRo%3D&reserved=0) and upgrade to WordPress 5.2.3.

 

## FBI Releases Article on Think Before You Post Campaign

September 5, 2019

The Federal Bureau of Investigation (FBI) has released an article on their Think Before You Post campaign, designed to educate students on the use of social media and how to avoid making poor choices when posting, texting, or emailing thoughts or grievances that could lead to disruptive behavior, including threats. The FBI article stresses that this type of online behavior could result in serious consequences to the individual as well as the community.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users to review the [FBI article](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.fbi.gov%2Fcontact-us%2Ffield-offices%2Fportland%2Fnews%2Fpress-releases%2Foregon-fbi-tech-tuesday-building-a-digital-defense-with-thinkbeforeyoupost&data=02%7C01%7Cjwarner%40vlcmtech.com%7C43e7042642b242d3209208d732244475%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637033003659024204&sdata=2lBoPWIeMHpeLTyub3fQjnkK2MKf63A8yDSrvV24lIc%3D&reserved=0) for information about the Think Before You Post campaign. CISA also recommends users review the CISA Tip [Identifying Hoaxes and Urban Legends](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST04-009&data=02%7C01%7Cjwarner%40vlcmtech.com%7C43e7042642b242d3209208d732244475%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637033003659034197&sdata=9gH8x9IazLdYp2YHuPbj6tekuc0%2FF43Mt7xFK1n6rAQ%3D&reserved=0) for information on the potential dangers of viral emails. CISA encourages users to report suspicious activity to their local FBI field office and to FBI CyWatch at [cywatch@fbi.gov](mailto:cywatch@fbi.gov). 

 

## MS-ISAC Releases Advisory on PHP Vulnerabilities

September 5, 2019

The Multi-State Information Sharing & Analysis Center (MS-ISAC) has released an advisory on multiple Hypertext Preprocessor (PHP) vulnerabilities. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review MS-ISAC Advisory [2019-087](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisecurity.org%2Fadvisory%2Fmultiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2019-087%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ccadd13a3dae14cea623b08d7321dc9b9%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032975831734482&sdata=Qi80LU2b%2BxZJtsrzcvh1EfmiB9sEK9HKwENfIGcbTzM%3D&reserved=0) and the [PHP Downloads](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.php.net%2Fdownloads.php%23gpg&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ccadd13a3dae14cea623b08d7321dc9b9%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032975831744474&sdata=9EwmjgRiILZdnZNgjhGatP6o%2BxTiG7ZcKzCNKUcyrnM%3D&reserved=0) page and apply the necessary updates.

 

## Cisco Releases Security Updates

September 5, 2019

Cisco has released security updates to address vulnerabilities affecting Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the following Cisco Advisories and apply the necessary updates:

- Webex Teams Logging Feature Command Execution Vulnerability [cisco-sa-20190904-webex-teams](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-webex-teams&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847440102&sdata=OVLe4L3NTJK9HcTjWJJ7mHwsHCab68sq5BlGIPJbBYY%3D&reserved=0)
- Industrial Network Director Configuration Data Information Disclosure Vulnerability [cisco-sa-20190904-ind](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-ind&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847440102&sdata=CPDBFdh9%2BMJpBqMokGiorJ%2BDu1I7uuQF0vR3zqJBmIc%3D&reserved=0)
- Unified Contact Center Express Request Processing Server-Side Request Forgery Vulnerability [cisco-sa-20190904-unified-ccx-ssrf](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-unified-ccx-ssrf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847450091&sdata=FM5sUpv9oU3C245A9BVRXSj2HeDZto2nQHj4FyvC9Xk%3D&reserved=0)
- Content Security Management Appliance Information Disclosure Vulnerability [cisco-sa-20190904-sma-info-dis](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-sma-info-dis&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847460087&sdata=bxxtonYvGKqQ%2BCtjVNudrxYGXsIQoGJ5ARpvpSa68KM%3D&reserved=0)
- Jabber Client Framework for Mac Code Execution Vulnerability [cisco-sa-20190904-jcf-codx](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-jcf-codex&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847460087&sdata=yyO0Id8HRp8PXIxWCyklKYNbpgUmYOGWCFHD32gcjmo%3D&reserved=0)
- Identity Services Engine Cross-Site Scripting Vulnerability [cisco-sa-20190904-ise-xss](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-ise-xss&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847470081&sdata=%2FFgFaP6Wu%2BlFbU5CjmyJFehCKcs%2FkcoCVbUBGtczMFs%3D&reserved=0)
- Finesse Request Processing Server-Side Request Forgery Vulnerability [cisco-sa-20190904-finesse-ssrf](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.cisco.com%2Fsecurity%2Fcenter%2Fcontent%2FCiscoSecurityAdvisory%2Fcisco-sa-20190904-finesse-ssrf&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cde466ed758c44150250f08d732143d8b%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032934847470081&sdata=q%2BWs%2FEyKjxL%2Bt9vESSsMzZdxrA0QE12kE5zdLlwyz90%3D&reserved=0)

## NCSC Releases UK Cyber Incident Trends Report

September 4, 2019

The United Kingdom (UK) National Cyber Security Centre (NCSC) has released a report detailing cyber incident trends in the UK from October 2018 to April 2019. The report provides technical guidance on how to defend against, and recover from, the following cyber threats: ransomware, phishing, vulnerability scanning, and attacks targeting supply chain and Office 365 cloud services.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages administrators to review the [NCSC report](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ncsc.gov.uk%2Freport%2Fincident-trends-report&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222442211&sdata=iQlGJUelZZa2URzVxJGJWCa%2FyUtizqapxMP2lwWboN0%3D&reserved=0) and the following CISA resources for more information on improving cybersecurity posture:

- [Ransomware page](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2FRansomware&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222452207&sdata=7SVUU%2BeF8B6KoVE7iekoLZXj4l54aQJ5G9xi4Ahsok8%3D&reserved=0)
- [Avoiding Social Engineering and Phishing Attacks](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST04-014&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222462207&sdata=iF2%2B6oZHIfdVKQ%2BsCCGwJNrLTpqjw81S3T5JZFTJ1ik%3D&reserved=0)
- [Securing Network Infrastructure Devices](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST18-001&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222462207&sdata=UgfC2HcySYCBUQg1KIMEKrI%2FbEY1M6%2Bv6kET1tsZlJk%3D&reserved=0)
- [APTs Targeting IT Service Provider Customers](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2FAPTs-Targeting-IT-Service-Provider-Customers&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222472199&sdata=ReshGvfeRTyC%2BT9Y%2BsvW1wBdbeAYofgaQhKiWdoo04c%3D&reserved=0)
- [Microsoft Office 365 Security Observations](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Fanalysis-reports%2FAR19-133A&data=02%7C01%7Cjwarner%40vlcmtech.com%7C52b825da6b2944eba16308d7316c3a7c%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032213222482195&sdata=dV6maRLL%2ByA5KIp6QWQHnDU1i%2BWLdGXMCFkVB1amtEo%3D&reserved=0)

 

## Samba Releases Security Updates

September 4, 2019

The Samba Team has released security updates to address a vulnerability in all versions of Samba from 4.9.0 onward. An attacker could exploit this vulnerability to obtain sensitive information.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Samba Security Announcement for [CVE-2019-10197](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.samba.org%2Fsamba%2Fsecurity%2FCVE-2019-10197.html&data=02%7C01%7Cjwarner%40vlcmtech.com%7C023a0317ebd942a2efc808d73163cbd3%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032177003526058&sdata=7e6w3RjES93z38TiiZxc%2BSQFL4C%2BtswJ%2BHuKhhEzxUw%3D&reserved=0) and apply the necessary updates and workarounds.

 

## Mozilla Releases Security Updates for Firefox and Firefox ESR

September 4, 2019

Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisories for [Firefox 69](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.mozilla.org%2Fen-US%2Fsecurity%2Fadvisories%2Fmfsa2019-25%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C2193f30a84c246af98d108d7315c2695%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032144164886578&sdata=7mxdfWjlb00SDYr%2Fzivm9d8t7Vw9o6FbcX1I6%2FDD8Y8%3D&reserved=0), [Firefox ESR 68.1](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.mozilla.org%2Fen-US%2Fsecurity%2Fadvisories%2Fmfsa2019-26%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C2193f30a84c246af98d108d7315c2695%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032144164886578&sdata=L%2BODGVYcaIp5bxGn2dPWPxXQx1QC9hPP7c77F2mI7zQ%3D&reserved=0), and [Firefox ESR 60.9](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.mozilla.org%2Fen-US%2Fsecurity%2Fadvisories%2Fmfsa2019-27%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7C2193f30a84c246af98d108d7315c2695%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032144164896570&sdata=2FaO2yObAMzuXbPCcxqTZDehcvOFtx28rSiLBCgejls%3D&reserved=0).

 

## Supermicro Releases Security Updates

September 4, 2019

Supermicro has released security updates to address vulnerabilities affecting the Baseboard Management Controller (BMC) component of Supermicro X9, X10, and X11 platforms. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages administrators to review Supermicro’s [Security Advisory](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.supermicro.com%2Fsupport%2Fsecurity_BMC_virtual_media.cfm&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cebb8f9b6d8234812065008d73154c3b8%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032112449416771&sdata=t4qfgmQ1bm%2B09BO%2BzP13xCjkEXPx63%2BODlwlRo82W%2Fk%3D&reserved=0) and [Security Vulnerabilities Table](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.supermicro.com%2Fsupport%2Fsecurity_Intel-SA.cfm&data=02%7C01%7Cjwarner%40vlcmtech.com%7Cebb8f9b6d8234812065008d73154c3b8%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032112449416771&sdata=98XrktjeYt%2Buc6YdGalPOev7WRExgvKJfqvptetgmHM%3D&reserved=0) and apply the necessary updates and recommended mitigations.

 

## Potential Hurricane Dorian Cyber Scams

September 4, 2019

The Cybersecurity and Infrastructure Security Agency (CISA) warns users to remain vigilant for malicious cyber activity targeting Hurricane Dorian disaster victims and potential donors. Fraudulent emails commonly appear after major natural disasters and often contain links or attachments that direct users to malicious websites. Users should exercise caution in handling any email with a hurricane-related subject line, attachment, or hyperlink. In addition, users should be wary of social media pleas, texts, or door-to-door solicitations relating to severe weather events.

To avoid becoming victims of malicious activity, users and administrators should review the following resources and take preventative measures:

- [Staying Alert to Disaster-related Scams](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.consumer.ftc.gov%2Ffeatures%2Fdealing-weather-emergencies%23stayingalert&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca40bd11156c24c5ebb3008d73142cbdc%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032035281768834&sdata=FlACh6%2Foa%2BhFYTSJ2LeMG%2B4ilhE9GntK1Nz%2BAl9NJ8U%3D&reserved=0)
- [Before Giving to a Charity](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.consumer.ftc.gov%2Farticles%2F0074-giving-charity&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca40bd11156c24c5ebb3008d73142cbdc%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032035281768834&sdata=K086AM%2BE7HMyUclFHkTww%2F4xkXMomtDxvP6R0znW7to%3D&reserved=0)
- [Staying Safe on Social Networking Sites](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST06-003&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca40bd11156c24c5ebb3008d73142cbdc%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032035281778825&sdata=MdsnC5xnScg4yMWIAjgapM1xvQ4zzSGrd6sv2M4MEHU%3D&reserved=0)
- [Avoiding Social Engineering and Phishing Attacks](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fncas%2Ftips%2FST04-014&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca40bd11156c24c5ebb3008d73142cbdc%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032035281788822&sdata=vmw5mNwWM4zgTU4IwLUnASqSE9oHbMBLRxqZNg7YBuw%3D&reserved=0)

If you believe you have been a victim of cybercrime, file a complaint with the Federal Bureau of Investigation Internet Crime Complaint Center at [www.ic3.gov](https://nam01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.ic3.gov%2F&data=02%7C01%7Cjwarner%40vlcmtech.com%7Ca40bd11156c24c5ebb3008d73142cbdc%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637032035281788822&sdata=j%2F8sl3dIlPF4vaI%2Fhix7Kpqyxd0pIpfnK1gPIOvoj2E%3D&reserved=0).

 

 

 

[View full post](https://blog.vlcm.com/blog/cybersecurity-september-2019)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Joseph Warner"
  },
  "dateModified" : "2019-10-01T22:31:18.283Z",
  "datePublished" : "2019-10-01T22:16:17Z",
  "headline" : "VLCM Cybersecurity Alerts - September 2019",
  "image" : {
    "@type" : "ImageObject",
    "height" : 627,
    "url" : "https://go.vlcmtech.com/hubfs/cybersecurity---september.jpg",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://blog.vlcm.com/blog/cybersecurity-september-2019",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://go.vlcmtech.com/hubfs/_vlcmlogos/vlcm-logo.png",
      "width" : 60.000004
    },
    "name" : "VLCM Blogs"
  }
}
```