TT-CSIRT – 436.24.10.24. Missing Authentication in FortiManager fgfmd

TT-CSIRT – 436.24.10.24. Missing Authentication in FortiManager fgfmd

Fortinet has released a patch to address a critical vulnerability in their FortiManager product. This vulnerability allows threat actors to use a compromised FortiManager device to execute arbitrary code or commands via specially crafted requests against other FortiManager devices, through a missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon.   Reports have […]

TTCSIRT – 435.26.09.24: Phishing Alert

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is aware of a phishing email originating from a GovNeTT user’s compromised email “akesha.hazel@gov[.]tt’”. In this respect we are advising all persons not to engage with any emails received from the aforementioned email address with the following details: Persons who receive the email are advised […]

TTCSIRT 434.25.09.24: Keep Your Firewall Up to Date

Regularly updating your firewall is essential for maintaining a strong security posture, protecting your network and data, and mitigating the risks associated with cyber threats. From the Trinidad and Tobago perspective, the exploitation of outdated and unpatched firewall systems is one of the most successful attack vectors executed against local organizations. This email serves as […]

TTCSIRT – 433.23.09.24: Phishing Alert

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is aware of a phishing email originating from the Military Lead Training Academy’s (MiLAT) email “Milatacademydean@gov[.]tt’”. In this respect we are advising all persons not to engage with any emails received from the aforementioned email address with the following details: Persons who receive the email […]

TT-CSIRT – 432.10.09.24. SonicOS Improper Access Control Vulnerability

The TTCSIRT wishes to inform you of a recently identified vulnerability in SonicWall SonicOS. This improper access control issue affects SonicWall SonicOS management access and SSLVPN, potentially allowing unauthorized access to resources and, under certain conditions, causing the firewall to crash. The vulnerability impacts SonicWall Gen 5 and Gen 6 devices, as well as Gen […]

TTCSIRT 430.19.07.24: Global Outage Triggered by Faulty CrowdStrike Cybersecurity Update

A large-scale outage has occurred due to a broken CrowdStrike cybersecurity update, rendering Windows computers unable to start and affecting much of the world’s infrastructure. The problem stems from an issue with CrowdStrike’s Falcon Sensors, which encountered problems following an early Friday morning update.   PLEASE BE ADVISED: Only accept information from the CrowdStrike support […]

TT-CSIRT 429.10.07.24: Citrix Releases Security Updates for Multiple Products

Citrix has announced significant security updates to address vulnerabilities across multiple products. Administrators should promptly review and implement the following updates: NetScaler ADC and NetScaler Gateway: CVE-2024-5491, CVE-2024-5492 NetScaler Console, Agent, and SVM: CVE-2024-6235, CVE-2024-6236 Citrix Workspace app for HTML5: CVE-2024-6148, CVE-2024-6149 Citrix Provisioning: CVE-2024-6150 Windows Virtual Delivery Agent for CVAD and Citrix DaaS: CVE-2024-6151 […]

TT-CSIRT-408.31.10.22: Phishing Alert

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is aware of a phishing email originating from the Ministry of Foreign and CARICOM Affairs’ domain “foreign.gov.tt”. In this respect we are advising all persons not to open any emails received from the Ministry of Foreign and CARICOM Affairs with the following details: Subject: “Re: […]

TTCSIRT-406.30.09.22: Critical Microsoft Exchange 0-Day Vulnerability Actively Exploited

Critical Microsoft Exchange 0-Day Vulnerability Actively Exploited Description The two vulnerabilities for on-premise Microsoft Exchange have been discovered and are now being tracked as a Server-Side Request Forgery vulnerability, CVE-2022-41040, and a remote code execution vulnerability, CVE-2022-41082. The two vulnerabilities are being exploited together to remotely trigger arbitrary code execution which essentially allows threat actors […]

Increased Cyber Activity in Trinidad and Tobago and the Region

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) has observed a sharp increase in malicious cyber activity targeting local and regional entities over the past two (2) months. The TT-CSIRT is urging all entities (public and private) to adopt a heightened state of awareness and be guided by the following: Top Threats to […]