Threat Advisory

Threat Advisory: Increased Emotet Malware Activity Detected

Threat Advisory: Increased Emotet Malware Activity Detected

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory on the increasing use of targeted Emotet malware attacks. Emotet is a Trojan used by threat actors to act as a downloader, or dropper, of other malware. The most common delivery method for Emotet is via the use of spam emails that have a malicious Microsoft Word or Excel... Read More
January 23, 2020
Threat Advisory Update: US National Terrorism Advisory System

Threat Advisory Update: US National Terrorism Advisory System

Herjavec Group is aware of elevated concern around Iranian state-sponsored cyber threat actors. We continue to remain vigilant and will report any suspicious activity across our Managed Security Services Enterprise Base. As always, we will work with our partners to share and notify you with any new threat information as it is made available. Our operations team will continue to... Read More
January 6, 2020
Herjavec Group’s Threat Summary Analysis – Q3 2019

Herjavec Group’s Threat Summary Analysis – Q3 2019

DOWNLOAD THE LATEST THREAT SUMMARY HERE Herjavec Group’s Threat Management Team leverages this Quarterly Threat Summary to provide an overview of the most common threats and vulnerabilities seen in customer environments in recent months. In our Q2 2019 Threat Summary, our team addressed the uptick of business email compromise, credential stuffing, and web application attacks on enterprises.  For the Q3... Read More
November 4, 2019
Threat Advisory: URGENT/11 Zero-Day Vulnerability

Threat Advisory: URGENT/11 Zero-Day Vulnerability

News of the URGENT/11 zero-day vulnerabilities has begun to emerge.  These vulnerabilities affect the VxWorks real-time operating system created by Wind River and may allow a remote attacker to gain full control over an impacted device.  The VxWorks operating system is used by over 2 billion Internet of Things (IoT) devices globally including printers, VOIP phones, firewalls, routers, medical equipment,... Read More
July 30, 2019
Threat Advisory: OAuth Phishing Awareness

Threat Advisory: OAuth Phishing Awareness

Traditional phishing messages often target users to deliver malware or obtain credentials. New tools are being released that also enable OAuth abuse in phishing attacks. OAuth has become the de-facto protocol used by companies such as Google, Facebook, Amazon, and Microsoft to manage access to user data across their platforms.   However, this creates an opportunity for an attacker to... Read More
July 24, 2019
HG Q2 2019 Threat Summary Analysis

HG Q2 2019 Threat Summary Analysis

Stay ahead of the threat curve Most organizations developing a Threat Management program strive to stay ahead of the threat curve. At Herjavec Group, we partner with enterprises to map attack verticals, drive threat modelling, and conduct Red Team exercises. Herjavec Group’s Threat Management Team circulates a Quarterly Threat Summary to provide an overview of the most common threats and... Read More
July 21, 2019
Herjavec Group’s Threat Summary Analysis – Q2 2019

Herjavec Group’s Threat Summary Analysis – Q2 2019

DOWNLOAD THE LATEST THREAT SUMMARY HERE Herjavec Group’s Threat Management Team leverages this Quarterly Threat Summary to provide an overview of the most common threats and vulnerabilities seen in customer environments in recent months. While Phishing, Ransomware, Crypto-Jacking and IoT Vulnerabilities were prominent in 2018 and the early months of 2019, we have seen a recent uptick in Business Email... Read More
June 20, 2019
Threat Advisory: New Vulnerability Affecting Exim Servers

Threat Advisory: New Vulnerability Affecting Exim Servers

A critical remote code execution vulnerability is actively being scanned for and exploited across the Internet. Known as "Return of the WIZard", the vulnerability (tracked under CVE-2019-10149) affects the Exim mail transfer relays (versions 4.87-4.91), which currently operate on more than half of all mail servers on the Internet. The vulnerability was exploited as early as June 9, 2019. While... Read More
June 13, 2019
Threat Advisory: Remote Desktop Services Vulnerability

Threat Advisory: Remote Desktop Services Vulnerability

This week, Microsoft released a critical update for their Remote Desktop Services (formerly Terminal Services) impacting multiple Windows versions. It is critical that organizations apply the patch as soon as possible because this vulnerability is “wormable”, meaning it is pre-authentication and requires no user interaction. An exploit for this weakness could be used to create malware that would spread similarly... Read More
May 15, 2019
Threat Advisory: TrickBot Malware

Threat Advisory: TrickBot Malware

The Multi-State Information Sharing and Analysis Center (MS-ISAC) recently released a security primer on TrickBot. Originally developed in 2016 as a Windows-based banking Trojan, TrickBot has recently seen advancements in its capabilities. The developers behind it have continued to add more features via modules to this potent trojan. With its modular structure, it is able to download new modules from... Read More
March 15, 2019