Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Advisory 2020-004: Remote code execution vulnerability being actively exploited in vulnerable versions of Telerik UI by sophisticated actors Advisory 2020-004: Remote code execution vulnerability being actively exploited in vulnerable versions of Telerik UI by sophisticated actors 22 May 2020 Advisory This advisory is focused around the targeting of CVE-2019-18935 but has significant overlap to the previously released ACSC 2019-126 advisory.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / 2020-006 Detecting and mitigating exploitation of vulnerability in Microsoft Internet Information Services 2020-006 Detecting and mitigating exploitation of vulnerability in Microsoft Internet Information Services 22 May 2020 Advisory Advisory on detecting and mitigating exploitation of a Microsoft IIS vulnerability. Outlines attack methods, risks, and steps to secure affected systems and networks.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Active exploitation of vulnerability in Microsoft Internet Information Services Active exploitation of vulnerability in Microsoft Internet Information Services 22 May 2020 Alert Alert on sophisticated actors exploiting an IIS .NET deserialisation flaw via VIEWSTATE, enabling unauthorised remote code execution across all IIS versions.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / COVID-19 malicious cyber activity COVID-19 malicious cyber activity 13 Mar 2020 Alert Alert on COVID-19 themed scams and phishing targeting individuals and organisations, with attacks expected to increase in frequency and severity.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Summary of Tradecraft Trends for 2019-20 Summary of Tradecraft Trends for 2019-20 20 May 2020 Alert Alert on numerous cyber security incidents investigated and responded to by ASD’s ACSC across Australia during 2019 and 2020.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Summary of Tactics, Techniques and Procedures Used to Target Australian Networks Summary of Tactics, Techniques and Procedures Used to Target Australian Networks 20 May 2020 Advisory Advisory on detection methods for many listed TTPs. Partners should review their environments for exploited vulnerabilities and indicators.