Cyber Guidance
Need the latest on cyber threats and the recommended remediation?
Check out our Cyber Guidance Cheat Sheets for the latest advice from our C-Suite team to secure your organisation today.
August 2023
Ivanti Patches Zero-Day Vulnerability- Cyber Guidance Issue 0335
Multiple Flaws in the WordPress Ninja Plugin - Cyber Guidance Issue 0336
CISA Uncovers Backdoor in ESG Appliances - Cyber Guidance Issue 0337
PaperCut Bug Exposes Servers to RCE- Cyber Guidance Issue 0338
Google Android OS Vulnerabilities Enable RCE- Cyber Guidance Issue 0339
Rilide Malware Targets Chromium Browsers- Cyber Guidance Issue 0400
SMS Scams Targeting New Zealanders - Cyber Guidance Issue 0401
Patch Tuesday - August 2023 - Cyber Guidance Issue 0402
Knight Ransomware Spreads via Fake Emails - Cyber Guidance Issue 0403
Zero-Day Vulnerability in Ivanti Sentry - Cyber Guidance Issue 0404
WinRAR Vulnerable to Remote Code Execution - Cyber Guidance Issue 0405
June 2023
Compromised M365 Accounts Phishing Campaign - Cyber Guidance Issue 0320
GitLab Patches 10.0 Critical Severity Flaw - Cyber Guidance Issue 0321
Google Releases 12 Security Updates - Cyber Guidance Issue 0322
MOVEit Transfer Zero-Day Vulnerability - Cyber Guidance Issue 0323
Barracuda Email Security RCE Flaw - Cyber Guidance Issue 0324
Critical Flaw in KeePass Exposes Master Password - Cyber Guidance Issue 0325
Fortinet Patches Critical RCE Flaw - Cyber Guidance Issue 0326
Cisco and VMware Patch Critical Flaw - Cyber Guidance Issue 0327
Patch Tuesday - June 2023 - Cyber Guidance Issue 0328
Microsoft Outages Caused by DDoS Attacks - Cyber Guidance Issue 0329
MOVEit Reveals a New Critical Vulnerability - Cyber Guidance Issue 0330
Fake Websites Harvesting Personal Data - Cyber Guidance Issue 0331
Fortinet Patches Critical RCE Flaw - Cyber Guidance Issue 0332
Apple Fixes Zero-Day Vulnerabilities - Cyber Guidance Issue 0333
Microsoft Teams Bug Allows Malware Delivery - Cyber Guidance Issue 0334
May 2023
New Zealanders Targeted by Phishing Scams - Cyber Guidance Issue 0311
ViperSoftX Targets Password Managers - Cyber Guidance Issue 0312
Cisco Discloses Zero-Day Vulnerability - Cyber Guidance Issue 0313
WordPress sites Vulnerable to XSS Attack - Cyber Guidance Issue 0314
April 2023
OneNote to Block Dangerous File Extensions - Cyber Guidance Issue 0299
Security Flaws in Reatek & Cacti Exploited - Cyber Guidance Issue 0300
WordPress Elementor Pro Vulnerability - Cyber Guidance Issue 0301
Apple Fixes Two Zero-Day Vulnerabilities - Cyber Guidance Issue 0302
Malicious Browser Extension Phishing Campaigns - Cyber Guidance Issue 0303
Sophos Critical Web Appliance Vulnerabilities - Cyber Guidance Issue 0304
April - Patch Tuesday - Cyber Guidance Issue 0305
Google Chrome Zero-Day Vulnerability - Cyber Guidance Issue 0306
Legion Credential Harvester - Cyber Guidance Issue 0307
Trigona Ransomware Targets MS SQL Servers - Cyber Guidance Issue 0308
Google Patches 2nd Zero-Day Vulnerability - Cyber Guidance Issue 0309
Cisco & VMWare Patch Critical Flaws - Cyber Guidance Issue 0310
March 2023
Customer Data Stolen in 3rd-Party Breach - Cyber Guidance Issue 0285
Cisco Critical Bugs in IP Phones - Cyber Guidance Issue 0286
New Flaws in TPM 2.0 Library - Cyber Guidance 0287
GoBruteforcer Targets Webservers - Cyber Guidance Issue 0288
Fortinet Patches New RCE Vulnerability - Cyber Guidance Issue 0289
Emotet Now Spread Via OneNote Attachments - Cyber Guidance Issue 0292
Adobe Acrobat Sign - Phishing Emails - Cyber Guidance Issue 0293
Hinatabot Botnet Exploits Servers - Cyber Guidance Issue 0294
MacStealer Targets Apple Devices - Cyber Guidance Issue 0295
ShellBot Variants Target Linux Servers - Cyber Guidance Issue 0296
Windows Snipping Tool Vulnerability - Cyber Guidance Issue 0297
3CX Desktop App Compromised in Supply Chain Attack - Cyber Guidance Issue 0298
February 2023
Atlassian Patches Critical from in Jira - Cyber Guidance Issue 0273
ESXiArgs Ransomware Targets VMWare Servers - Cyber Guidance Issue 0274
OpenSSH Releases Security Patch - Cyber Guidance Issue 0275
Turkey Earthquake Prompts Donation Scams - Cyber Guidance Issue 0276
VMWare ESXi Server Ransomware Evolves - Cyber Guidance Issue 0277
Fortinet Fixes Critical RCE Vulnerability - Cyber Guidance Issue 0279
Cryptominers Target MS Exchange ProxyShell - Cyber Guidance Issue 0280
Mirai Targets Linux Servers to Launch DDoS - Cyber Guidance Issue 0281
New StealC Malware-as-a-Service - Cyber Guidance Issue 0282
Exploit Guide Released for Fortinet RCE Bug - Cyber Guidance Issue 0283
Critical Wordpress Flaw Allows Site Takeover - Cyber Guidance Issue 0284
January 2023
March 2022
SquirrelWaffle New Exploit for ProxyLogon - Cyber Guidance Issue 0248
Emotet Spreads Through Malicious Excel Files - Cyber Guidance 0249
‘Cuba’ Ransomware Gang Exploits ProxyShell - Cyber Guidance Issue 250
Patch Tuesday - March 2022 - Cyber Guidance Issue 0251
Lapsus$ Gang Moves in on NVIDIA, Samsung & Ubisoft - Cyber Guidance Issue 0252
TLStorm Vulnerabilities in APC Smart UPS - Cyber Guidance Issue 0253
‘Dirty Pipe’ Linux Flaw Affects QNAP NAS - Cyber Guidance Issue 0254
Sandworm & Cyclops Blink Botnet Hunt ASUS Routers - Cyber Guidance Issue 0255
Facestealer Trojan Spys on Facebook Accounts - Cyber Guidance Issue 0256
Urgent: Google Chrome Under Active Attack - Cyber Guidance Issue 0257
Lapsus$ Strikes Again: Okta & Microsoft - Cyber Guidance Issue 0258
February 2022
January 2022
December 2021
November 2021
HashThemes Bug in Wordpress Allows Site Wipe - Cyber Guidance Issue 0217
Numerous Apple iOS Vulnerabilities - Cyber Guidance Issue 0218
Cisco ASA & FirePower Allow Security Bypass - Cyber Guidance Issue 0219
‘BrakTooth’ Bluetooth Flaws Affects Billions - Cyber Guidance Issue 0220
Patch Tuesday - Cyber Guidance Issue 0221
Proofpoint Brand Used by Phishing Scammers - Cyber Guidance Issue 222
New Botenago Malware Targets IoT Devices - Cyber Guidance Issue 0223
Palo Alto VPN/Firewall Critical Vulnerability - Cyber Guidance Issue 0224
Phishers use Tiny Fonts to Fool Email Filters - Cyber Guidance 0225
MICROP Ransomware Spread via Google Drive - Cyber Guidance Issue 0226
Emotet Resurfaces after Extermination - Cyber Guidance Issue 0227
Intel Security Bug Exposes Encryption Keys - Cyber Guidance Issue 0228
October 2021
FluBot Reaches NZ & Targets Android Phones - Cyber Guidance Issue 0205
Telegram Bots Steal OTP Tokens for PayPal etc - Cyber Guidance Issue 0206
Conti Ransomware Destroys Backups - Cyber Guidance Issue 0207
UEFI Bootkit Malware Known as ESPecter - Cyber Guidance Issue 0208
Apache HTTP Server Path Traversal Attacs - Cyber Guidance Issue 0209
VMWare ESXi Servers Encrypted by Python Script - Cyber Guidance Issue 0210
Apple Patches Bug - Now Under Active Exploit - Cyber Guidance Issue 0211
Patch Tuesday - Cyber Guidance Issue 0212
Mozilla Thunderbird Email Client Vulnerability - Cyber Guidance Issue 0213
Oracle’s Quarterly Update - Cyber Guidance Issue 0214
NPM Package ua-parser-js Hijacked for RCE - Cyber Guidance Issue 0215
Glupteba Trojan Proves Prolific & Very Sneaky - Cyber Guidance Issue 0216
September 2021
Confluence Server & Data Centre Vulnerability - Cyber Guidance Issue 0192
LockFile Unique Encryption Avoids Detection - Cyber Guidance Issue 0193
Brute-Force Attack Scouring for Email Accounts - Cyber Guidance Issue 0194
Microsoft MSHTML Vulnerability Exploit - Cyber Guidance Issue 0195
Zoho Password Manager Under Attack - Cyber Guidance Issue 0196
Azurescape Cross-Container Compromise - Cyber Guidance Issue 0197
URGENT: OMIGOD Critical Vulnerabilities in Azure - Cyber Guidance Issue 0198
Patch Tuesday - Cyber Guidance Issue 0199
ZLoader Trojan Spreads by Google Ads - Cyber Guidance Issue 0200
Microsoft MSHTML Exploited by Ryuk Gang - Cyber Guidance Issue 0201
Vulnerabilities in VMWare vCenter Server - Cyber Guidance Issue 0202
MS Exchange Credentials Leak in Autodiscover - Cyber Guidance Issue 0203
TangleBot Malware Gets Full Access to Android - Cyber Guidance Issue 0204
August 2021
LemonDuck Malware Targets Microsoft & Linux - Cyber Guidance Issue 0177
PetitPotam Credential Stealing Attacks - Cyber Guidance Issue 0178
Praying Mantis Targets Windows IIS - Cyber Guidance Issue 0179
Racoon Stealer-as-a-Service Platform Updates - Cyber Guidance Issue 0180
Critical Cisco VPN Bugs - Cyber Guidance Issue 0181
Update Apple Devices Now - Cyber Guidance Issue 0182
Patch Tuesday - Cyber Guidance Issue 0183
Chaos Malware - Wiper or Ransomware? - Cyber Guidance Issue 0184
New Ransomware Targets NAS Devices - Cyber Guidance Issue 0185
Microsoft Races to Fix EoP Flaw - Cyber Guidance Issue 0186
Linux & MS Servers Vulnerable to HolesWord - Cyber Guidance Issue 0187
FortiNet Bug Allows Firewall Takeover - Cyber Guidance Issue 0188
Cosmos DB Critical Microsoft Azure Bug - Cyber Guidance Issue 0189
Realtek Chipsets SDK Under Active Exploit - Cyber Guidance Issue 0190
LockBit Ransomware New Features & RaaS - Cyber Guidance Issue 0191
July 2021
Print Spooler PrintNightmare & Many More - Cyber Guidance Issue 0164
Kaseya VSA Used to Deploy Ransomware Attacks - Cyber Guidance Issue 0165
TrickBot Add Man-in-the-Browser Capabilities - Cyber Guidance Issue 0166
New Malware Protection Bypass in Office - Cyber Guidance Issue 0167
Fake Kaseya VSA Updates Release CobaltStrike - Cyber Guidance Issue 0168
Cisco ASA, BPA & WSA Vulnerabilities - Cyber Guidance Issue 0169
Further Print Spooler Vulnerabilities - Cyber Guidance Issue 0170
APT “LuminousMoth” Drops Fake Zoom App - Cyber Guidance Issue 0171
Microsoft Discovers SolarWinds Vulnerability - Cyber Guidance Issue 0172
Patch Tuesday - Cyber Guidance Issue 0173
MosaicLoader Zero-Day Windows Malware 0 Cyber Guidance Issue 0174
Printer Vulnerability in HP, Xerox, & Samsung - Cyber Guidance Issue 0175
SeriousSAM Workaround Issued by Microsoft - Cyber Guidance Issue 0176
June 2021
Epsilon Red Target MS Exchange Servers - Cyber Guidance Issue 0152
Siloscape Malware Targets Containers - Cyber Guidance Issue 0153
Multiple Vulnerabilities in Android - Cyber Guidance Issue 0154
Intel Fixes 73 Bugs in CPU Firmware - Cyber Guidance Issue 0155
Patch Tuesday - Cyber Guidance Issue 0156
Ransomware Triple Threat Evolution - Cyber Guidance Issue 0157
Vishing Attacks Bypass Email Security - Cyber Guidance Issue 0158
Linux System Root Security Bug - Cyber Guidance Issue 0159
Cisco 220 Series Smart Switch Vulnerabilities - Cyber Guidance Issue 0160
WD My Book Storage Attack Wipes Data - Cyber Guidance Issue 0161
Dell Security Bug Remote BIOS RCE Attack - Cyber Guidance Issue 0162
May 2021
Patch Tuesday - Cyber Guidance Issue 0142
Wi-Fi Researchers Uncovers “FragAttacks” - Cyber Guidance Issue 0143
Apple Gatekeeper Security Bypass Exploited - Cyber Guidance Issue 0144
Rust Language Gaining Traction for Malware - Cyber Guidance Issue 0145
Microsoft SharePoint Ransomware Phishing - Cyber Guidance Issue 0146
25 Critical IoT Device Vulnerabilities - Cyber Guidance Issue 0147
Hewlett Packard Zero-Day RCE Flaw - Cyber Guidance Issue 0148
VMWare Critical vCenter RCE Flaw - Cyber Guidance Issue 0149
Fake Ransomware StrRAT Spread by Email - Cyber Guidance Issue 0150
Apple Mac Zero-Day Allows Sneaky Screenshots - Cyber Guidance Issue 0151
April 2021
PHP Project Infiltrated by Attackers - Cyber Guidance Issue 0128
LinkedIn Spear Phishing Targets Job Seekers - Cyber Guidance Issue 0129
Apple Emergency Updates - Cyber Guidance Issue 0130
Fortinet Flaw Ransomware Attack - Cyber Guidance Issue 0131
Azure Functions Allow Privilege Escalation - Cyber Guidance Issue 0132
SAP Bugs Under Active Attack - Cyber Guidance Issue 0133
Unpatched Exchange Servers Cryptojacking - Cyber Guidance Issue 0136
Web Forms Used to Circulate IcedID Malware - Cyber Guidance Issue 0137
Mirai Inspire Gafgyt Botnet DDoS - Cyber Guidance Issue Cyber Guidance Issue 0138
Phishing Scam Uses .TXT Attachments - Cyber Guidance Issue 0139
Exchange ProxyLogon used to Establish APT - Cyber Guidance Issue 0140
Urgent Security Update: QNAP NAS - Cyber Guidance Issue 0141
March 2021
Cisco RCE Flaw in Nexus Switches - Cyber Guidance Issue 0111
VMWare Patches Critical RCE Flaw - Cyber Guidance Issue 0112
Malicious Mozilla Extension GMail Takeover - Cyber Guidance Issue 0113
URGENT: Microsoft Exchange - Cyber Guidance Issue 0114
Ryuk Ransomware’s Terrifying Evolutions - Cyber Guidance Issue 0115
Attackers use SEO to Deploy Malware - Cyber Guidance Issue 0116
ObliqueRAT Hides with Steganography - Cyber Guidance Issue 0117
Patch Tuesday - Cyber Guidance Issue 0118
Ransomware Deployed in Exchange Attacks - Cyber Guidance Issue 0119
QNAP NAS Susceptible to Cryptomining - Cyber Guidance Issue 0120
New Intel Side-Channel Attacks - Cyber Guidance Issue 0121
Business Social Media Accounts Targeted - Cyber Guidance Issue 0122
o365 Phishing Targets Financial Execs - Cyber Guidance Issue 0123
Steganography on Twitter using PNG Files - Cyber Guidance Issue 0124
Purple Fox Malware has Worming Capabilities - Cyber Guidance Issue 0125
Android Spyware Masquerades as Updates - Cyber Guidance Issue 0126
Netmask Networking Bug Affects Thousands - Cyber Guidance Issue 0127
February 2021
Linux Sudo Bug Still Exists 10years On - Cyber Guidance Issue 0098
New NAT Slipstreaming Attack 2.0 - Cyber Guidance Issue 0099
Active Zero-Day Exploits in Apple iOS - Cyber Guidance Issue 0100
Cisco Privilege Escalation Bugs - Cyber Guidance Issue 0101
Dependency Confusion Attacks - Cyber Guidance Issue 0102
Patch Tuesday - Cyber Guidance Issue 0103
LodaRAT Moves from Windows to Android - Cyber Guidance Issue 0104
Adobe Exploit Targets Windows Users - Cyber Guidance Issue 0105
Matryosh Botnet uses Android for DDoS - Cyber Guidance Issue 0106
Agent Tesla RAT Disables Microsoft ASMI - Cyber Guidance Issue 0107
Tracker Pixels & Privacy Issues - Cyber Guidance Issue 0108
New Version of Masslogger Trojan - Cyber Guidance Issue 0109
Silver Sparrow Awaits on Mac Chipsets - Cyber Guidance Issue 0110
January 2021
2021 New Babuk Locker Ransomware - Cyber Guidance Issue 0087
Windows Zero-Day Remains Unfixed - Cyber Guidance Issue 0088
Critical Android RCE Bug - Cyber Guidance Issue 0089
Patch Tuesday - Cyber Guidance Issue 0090
MFA Bypassed in Cloud-Based Attacks - Cyber Guidance Issue 0091
Watering-Hole Attacks Exploit Flaws - Cyber Guidance Issue 0092
Mimecast Certificates Hacked - Cyber Guidance Issue 0093
SonicWall VPN Vulnerability Exploited - Cyber Guidance Issue 0094
Microsoft RDP Used in DDoS Attacks - Cyber Guidance Issue 0095
Google Forms Used to Perpetuate BEC - Cyber Guidance Issue 0096
New FreakOut Malware Targets Linux - Cyber Guidance Issue 0097
December 2020
Magecart Strikes Again Impersonate PayPal - Cyber Guidance Issue 0075
Zoom Impersonation Phishing Campaign - Cyber Guidance Issue 0076
Social Media Buttons Hide Malware - Cyber Guidance Issue 0077
FireEye Suffers Suspected State Attack - Cyber Guidance Issue 0078
SolarWinds Orion Active Exploit - Cyber Guidance Issue 0079
PGMiner Innovative New Botnet Discovered - Cyber Guidance Issue 0080
D-Link Router Zero-Day Flaw - Cyber Guidance Issue 0081
Patch Tuesday - Cyber Guidance Issue 0082
Second Stage SolarWinds Attack - Cyber Guidance Issue 0083
Fax Alert Emails Phish Microsoft Office 365 - Cyber Guidance Issue 0084
Malicious Web Browser Extensions - Cyber Guidance Issue 0085
SystemBC Backdoor Leveraged for Ransomware - Cyber Guidance Issue 0086
November 2020
Parked Domains & Typosquatting - Cyber Guidance Issue 0059
Oracle WebLogic Servers Under Active Attack - Cyber Guidance Issue 0060
Apple Patches Zero-Day Flaws - Cyber Guidance Issue 0061
Gitpaste-12 Worm Targets Linux Servers & IoT Devices - Cyber Guidance Issue 0062
VMWare Issues Update for Previous Fix - Cyber Guidance Issue 0063
Google Drive Employed by Attackers - Cyber Guidance Issue 0064
Patch Tuesday - Cyber Guidance Issue 0067
Two More Zero-Day‘s for Google Chrome - Cyber Guidance Issue 0068
DoS Flaw in Cisco ASR Routers - Cyber Guidance Issue 0069
PLATYPUS Attack Steals Data from Intel CPUs - Cyber Guidance Issue 0070
PowerShell Backdoors Revealed in Microsoft Exchange - Cyber Guidance Issue 0071
Magecart Website Credit Card Skimming - Cyber Guidance Issue 0072
Blackrota Golang Backdoor in Docker - Cyber Guidance Issue 0073
Malware that Associates with Ransomware - Cyber Guidance Issue 0074
October 2020
Special Edition: Changes to New Zealand’s Privacy Laws
Attackers Using CAPTCHA for Phishing - Cyber Guidance Issue 0046
InterPlanetary Storm Hits Common Operating Systems - Cyber Guidance Issue 0047
Azure App Server-Side Forgery Requests - Cyber Guidance Issue 0048
New HEH Botnet Infecting All Endpoint Types - Cyber Guidance Issue 0049
Google Chrome86 Fixes Critical Flaws - Cyber Guidance Issue 0050
Zero-Click Vulnerability in Linux-based IoT Devices - Cyber Guidance Issue 0052
Patch Tuesday - Cyber Guidance Issue 0053
Active Zero-Day Exploit in Google Chrome - Cyber Guidance Issue 0054
Oracle October Patched Total 402 - Cyber Guidance Issue 0055
Microsoft Teams Under Phishing Threat - Cyber Guidance Issue 0056
Microsoft APT’s Target Enterprise Platforms - Cyber Guidance Issue 0057
Ryuk Ransomware Exploit ‘ZeroLogon’ Flaw - Cyber Guidance Issue 0058
September 2020
File Manager WordPress Plugin Flaw - Cyber Guidance Issue 0029
Active Exploitation of Cisco Carrier-Grade Routers - Cyber Guidance Issue 0030
Critical Cisco Jabber Flaw for Windows - Cyber Guidance Issue 0031
6 Bugs Revealed in WhatsApp - Cyber Guidance Issue 0032
Phishing for Microsoft Outlook Credentials - Cyber Guidance Issue 0033
Patch Tuesday - Cyber Guidance Issue 0034
TeamTNT Take Over Kubernetes & Docker Cloud Instances - Cyber Guidance Issue 0035
Increased DDoS Attacks with Covid-19 - Cyber Guidance Issue 0036
Malicious QR Code Security Concerns - Cyber Guidance Issue 0038
‘ZeroLogon’ Critical Exploit in Windows - Cyber Guidance Issue 0039
Android Malware Evolution - Cyber Guidance Issue 0040
Firefox High-Severity Flaws - Cyber Guidance Issue 0041
Microsoft Revamps Patch Tuesday - Cyber Guidance Issue 0042
Misconfigurations in Google Cloud Buckets Lead to Public Access - Cyber Guidance Issue 0043
Citrix Workspace Vulnerability Re-Opened - Cyber Guidance Issue 0044
Cisco Tackled 29 High-Severity Bugs - Cyber Guidance Issue 0045
August 2020
July 2020
TikTok Security Concerns & Covert Data Harvesting - Cyber Guidance Issue 0007
Android Malware on Google Play - Cyber Guidance Issue 0008
Advertising Plug-in on WordPress Sites - Cyber Guidance Issue 0009
Citrix ADC & Gateway Bugs - Cyber Guidance Issue 0010
Critical SAP NetWeaver Java Flaw - Cyber Guidance Issue 0011
Cisco Critical Small Business Series Vulnerabilites - Cyber Guidance Issue 0013
Emotet Botnet & Trojan Resurgence - Cyber Guidance Issue 0014
Ancestry.com Potential Data Leak - Cyber Guidance Issue 0015
New Lokibot Variant: BlackRock for Android - Cyber Guidance Issue 0016
Cisco Network Device Security Flaw ASA & FTD - Cyber Guidance Issue 0017