Government of the Republic of Trinidad and Tobago
gov.tt

Securing the Nation's Digital Infrastructure

TTCSIRT-390.03.03.21:TTCSIRT ADVISORY – Critical Microsoft Exchange Server Security Updates

Updated for March 12, 2021   Microsoft has released out-of-band security updates to address multiple vulnerabilities affecting Microsoft Exchange Server 2013, 2016, and 2019. The United States Cyber and Infrastructure Security Agency (CISA) reports that successful exploitation of these vulnerabilities allows an attacker to execute arbitrary code on vulnerable Exchange Servers, enabling the attacker to …

TTCSIRT-389.02.04.21: TTCSIRT ADVISORY- SMA 100 SERIES 10.X FIRMWARE ZERO-DAY VULNERABILITY

Please be advised that SonicWall is announcing the availability of an SMA 100 series firmware 10.2.0.5-29sv update to patch a zero-day vulnerability on SMA 100 series 10.x code. All SMA 100 series users must apply this patch IMMEDIATELY to avoid potential exploitation. Affected SMA 100 Devices with 10.x Firmware that Require the Critical Patch: Physical Appliances: SMA 200, SMA 210, SMA 400, SMA …

TTCSIRT-388.01.19.21:TTCSIRT ADVISORY – Microsoft Defender Remote Code Execution Vulnerability

Please be advised that Microsoft has released a security advisory to address a remote code execution vulnerability, CVE-2021-1647, in Microsoft Defender. A remote attacker can exploit this vulnerability to take control of an affected system. This vulnerability was detected in exploits in the wild. TT-CSIRT is urging all entities (public and private) to download and install …

TTCSIRT-387.01.14.21:TTCSIRT ADVISORY – Microsoft Releases January 2021 Security Updates

Please be advised that Microsoft has released January 2021 Security Updates which prevents remote attackers from exploiting vulnerabilities to gain control of affected systems. The following software will be updated: Microsoft Windows Microsoft Edge (EdgeHTML-based) Microsoft Office and Microsoft Office Services and Web Apps Microsoft Windows Codecs Library Visual Studio SQL Server Microsoft Malware Protection …

TTCSIRT-THREAT ALERT: Supplemental Guidance for Emergency Directive on SolarWinds Orion Compromise

Please be advised, for situational awareness, the Cybersecurity and Infrastructure Security Agency (CISA) has released Emergency Directive (ED) 21-01 – Mitigate SolarWinds Orion Code Compromise – Supplemental Guidance Version 2, which provides additional guidance that supplements Emergency Directive (ED) 21-01 and Supplemental Guidance v1 issued on December 18, 2020. Can be accessed here: https://cyber.dhs.gov/ed/21-01/#supplemental-guidance. This guidance requires …

TTCSIRT-386.12.14.20:TTCSIRT ADVISORY – SUNBURST BACKDOOR

FireEye has uncovered a widespread campaign that they are tracking as UNC2452. The actors behind this campaign gained access to numerous public and private organizations around the world. They gained access to victims via trojanized updates to SolarWind’s Orion IT monitoring and management software. FireEye stated that this campaign may have begun as early as …

TTCSIRT-385.12.07.20: TT-CSIRT ADVISORY – Google Releases Security Updates for Chrome

Google has released Chrome version 87.0.4280.88 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. It is encouraged that users and administrators review and apply the necessary updates. For further information and support, please visit:Chrome Release

TTCSIRT-384.12.07.20: TT-CSIRT ADVISORY – Cisco Security Advisory for Vulnerability in AnyConnect

Cisco has released a security advisory on an Arbitrary Code Execution vulnerability—CVE-2020-3556—affecting Cisco AnyConnect Secure Mobility Client devices. A remote attacker could exploit this vulnerability to take control of an affected system. It is encouraged that users and administrators to review and apply the necessary updates or workarounds. For further information and support, please visit the following link:Cisco …

TTCSIRT-383.12.07.20: TT-CSIRT ADVISORY – Apache Releases Security Advisory for Apache Tomcat

The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An attacker could exploit this vulnerability to cause a denial-of-service condition. It is encouraged that users and administrators review the Apache security advisory and upgrade to the appropriate version. Please visit the link below for further support:CVE-2020-17527

TTCSIRT-THREAT ALERT: Russian State-Sponsored Malicious Cyber Actors Exploiting CVE-2020-4006

Please be advised, Russian state-sponsored actors exploiting CVE-2020-4006, a command-injection vulnerability in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. The actors were found exploiting this vulnerability to access protected data on affected systems via a Command Injection Vulnerability in the administrative configurator. VMware has evaluated this issue to be of ‘Important‘ …