Showing posts with label Medical Device Security. Show all posts
Showing posts with label Medical Device Security. Show all posts

Thursday, September 10, 2026

Review – 3 Advisories and 1 Update Published – 9-10-26

Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering. 

Advisories  

Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne. 

Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci 

NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal  

Updates  

ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities. 


For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required. 

Tuesday, June 30, 2026

Review – 8 Advisories Published – 6-30-26

Today CISA’s NCCIC-ICS published 7 control system security advisories for products from Delta Electronics, Stonefly, B&R Automation, Schneider (2) Frangoteam, and Mitsubishi. They also published a medical device security advisory for products from OFFIS. 

Advisories  

Delta Advisory - This advisory describes two vulnerabilities in the Delta Electronics DVP12SE PLC. 

StoneFly Advisory - This advisory This advisory describes five vulnerabilities in the StoneFly Storage Concentrator. 

B&R Advisory - This advisory discusses a race condition within a thread vulnerability in multiple B&R products.  

Schneider Advisory #1 - This advisory describes two vulnerabilities in the Schneider Electric EasyLogic T150 and Saitel DP RTU. 

Schneider Advisory #2 - This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider Electric EcoStruxure IT Data Center Expert. 

Frangoteam Advisory - This advisory describes an authentication bypass by spoofing vulnerability in the Frangoteam FUXA SCADA/HMI. 

Mitsubishi Advisory - This advisory discusses four vulnerabilities in the Mitsubishi MELSOFT Update Manager SW1DND-UDM-M.  

OFFIS Advisory - This advisory describes five vulnerabilities in the OFFIS DCMTK Toolkit. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-6-30-26 - subscription required. 

Thursday, August 21, 2025

Review – 2 Advisories and 1 Update Published – 8-21-25

Today CISA’s NCCIC-ICS published one control system security advisory and a medical device security advisory for products from Mitsubishi Electric and FUJIFILM. They also published an updated advisory for products from Mitsubishi.

Advisories

Mitsubishi Advisory - This advisory  describes an improper handling of length parameter inconsistency vulnerability in the Mitsubishi MELSEC iQ-F Series CPU module.

FUJIFILM Advisory - This advisory describes an external control of assumed-immutable web parameter vulnerability in the FUJIFILM Synapse Mobility product.

Updates

Mitsubishi Update - This update provides additional information on the Air Conditioning Systems advisory that was originally published on June 26th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-79a - subscription required.

Friday, January 10, 2025

Review - HHS Publishes HIPAA Cybersecurity NPRM – Medical Devices

On Monday the Department of Health and Human Services (HHS) published a notice of proposed rulemaking (NPRM) in the Federal Register (90 FR 898-1022) on “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information”. HHS is proposing to modify the Security Standards for the Protection of Electronic Protected Health Information (“Security Rule”) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act).

With its emphasis on Protected Health Information (PHI) the main focus of this proposed rule is on information technology, and generally falls outside the scope of this blog. Having said that, there are 52 mentions of the term ‘medical device’ in this NPRM, starting with the realization that:

“Almost every stage of modern health care relies on stable and secure computer and network technologies, including, but not limited to, the following: appointment scheduling, prescription orders, telehealth visits, medical devices, patient records, medical and pharmacy claims submissions and billing, insurance coverage verifications, payroll, facilities access and management, internal and external communications, and clinician resources. These tools and technologies are an integral part of the modern health care system, but they also present opportunities for bad actors to cause harm through hacking, ransomware, and other means.”

NOTE: A large number of those reference to ‘medical device’ are found in the footnotes, providing links to informational documents relating to medical device cybersecurity issues.

This means that personnel interested in the cybersecurity of medical devices, facility access controls, and building maintenance controls are going to have to pay attention to these proposed HIPPA cybersecurity rules.

Soliciting Comments

HHS is soliciting comments on this NPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #HHS-OCR-0945-AA22). Comments should be submitted by March 7th, 2025.

 

For more information on the medical device involvement in this proposed rule, including comments on additional areas that should be further clarified, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hhs-publishes-hipaa-cybersecurity - subscription required.

Tuesday, November 26, 2024

Review – 5 Advisories and 1 Update Published – 11-26-24

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Hitachi Energy and Schneider Electric. They also published an update for a medical device security advisory for products from Philips.

Advisories

Hitachi Energy Advisory #1 - This advisory describes an improper input validation vulnerability in the Hitachi Energy RTU500 series products.

Hitachi Energy Advisory #2 - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro.

Schneider Advisory #1 - This advisory describes three vulnerabilities in multiple Schneider products.

Schneider Advisory #2 - This advisory describes the use of a broken or risky cryptographic algorithm in the Schneider owerLogic P5 product.

Schneider Advisory #3 - This advisory describes two vulnerabilities in the Schneider PowerLogic PM5500 and PowerLogic PM8ECC products.

Updates

Philips Update - This update provides additional information on the Vue PACS advisory that was originally published on July 18th, 2024.

 

For more information on these advisories, including when vendors released and updated their versions of these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-abe - subscription required.


Thursday, September 5, 2024

Review – 2 Advisories and 2 Updates Published – 9-5-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Hughes, and a medical device security advisory for products from Baxter. They also updated two advisories for products from Mitsubishi.

Advisories

Hughes Advisory - This advisory describes two vulnerabilities in the Hughes WL3000 Fusion Software.

Baxter Advisory - This advisory describes two vulnerabilities in the Baxter Connex Health Portal.

Updates

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on October 29th, 2020, and most recently updated on December 19th, 2023.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on December 22nd, 2022, and most recently updated on July 9th, 2024.

 

For more information on these advisories, including brief summaries of changes made in the updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-2-updates-published-371 - subscription required.

Thursday, July 18, 2024

Review – 3 Advisories Published – 7-18-24

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Subnet Solutions and Mitsubishi Electric. They also published a medical device security advisory for products from Philips.

Advisories

Subnet Advisory - This advisory discusses a prototype pollution vulnerability with known exploits in the Subnet PowerSYSTEM Center.

Mitsubishi Advisory - This advisory discusses an improper verification of cryptographic signature vulnerability in the Mitsubishi MELSOFT MaiLab.

Philips Advisory - This advisory discusses 13 vulnerabilities (2 with known exploits) in the Philips Vue PACS product.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-7-18-24 - subscription required.

Tuesday, June 11, 2024

Review – 5 Advisories and 1 Update Published – 6-11-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Intrado, AVEVA (2), and Rockwell Automation. They published a medical device security advisory for products from MicroDicom. They also updated an advisory for products from Schneider.

Advisories

Intrado Advisory - This advisory describes an SQL injection vulnerability in the Intrado 911 Emergency Gateway (EGW).

AVEVA Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA PI Asset Framework Client.

AVEVA Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA PI Web API.

Rockwell Advisory - This advisory describes an always-incorrect control flow implementation vulnerability in the Rockwell ControlLogix, GuardLogix, and CompactLogix controllers.

MicroDicom Advisory - This advisory describes two vulnerabilities in the MicroDicom DICOM Viewer medical image viewer.

Updates

Schneider Update - This update provides additional information on the APC Easy UPS advisory that was originally published on April 18th, 2023.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-43c - subscription required

Thursday, May 30, 2024

Review – 6 Advisories and 1 Update Published – 5-30-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Westermo, Inosoft, Fuji Electric, and Carrier. They also updated an advisory for products from Mitsubishi Electric. Finally, they published two medical devices security advisories for products from Baxter.

NIST published a brief update on the status of the problems with the National Vulnerability Database (NVD).

Advisories

Westermo Advisory - This advisory describes two vulnerabilities in the Westermo EDW-100 Serial to Ethernet converter.

Inosoft Advisory - This advisory describes an incorrect default permissions vulnerability with known exploit in the Inosoft VisiWin HMI.

Fuji Advisory - This advisory describes two vulnerabilities in the Fuji Monitouch V-SFT screen configuration software.

Carrier Advisory - This advisory describes three vulnerabilities in the Carrier LenelS2 NetBox access control and event monitoring system.

Baxter Advisory #1 - This advisory describes a use of default cryptographic key vulnerability in the Baxter Welch Allyn Connex Spot Monitor.

Baxter Advisory #2 - This advisory describes an insufficiently protected credentials vulnerability in the Baxter Welch Allyn Configuration Tool.

Updates

Mitsubishi Update - This advisory provides additional information on the MELSEC iQ-R advisory that was originally published on December 22nd, 2022 and most recently updated on December 12th, 2023.

NVD Update

NVD Database Problem Update - Yesterday NIST updated the status of the problem with NVD maintenance issues.


For more information no these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-fa6 - subscription required.


Tuesday, March 5, 2024

Review – 2 Advisories and 1 Update Published – 3-5-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Nice and a medical device control system security advisory for products from Santesoft. They also updated a security advisory for products from Integration Objects. CISA also added a surveillance product vulnerability to their Known Exploited Vulnerabilities (KEV) catalog for products from Sunhillo.

Advisories

Nice Advisory - This advisory describes 12 vulnerabilities in the Nice Linear eMerge E3-Series access control products.

Santesoft Advisory - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging product.

Updates

Integration Update - This update provides additional information on the OPC UA Server Toolkit advisory that was originally published on January 16th, 2024.

KEV

New KEV Lising - CISA added CVE-2021-36380 Sunhillo SureLine OS command injection vulnerability to the KEV catalog.

 

For more information about these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-c77 - subscription required.

Tuesday, January 23, 2024

Review – 6 Advisories Published – 1-23-24

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Lantronix, Westermo, Voltronic Power, Crestron, and APsystems, and one medical device security advisory for products from Orthanc.

Advisories

Lantronix Advisory - This advisory describes a weak encoding for passwords vulnerability in the Lantronix XPort Device Server Configuration Manager.

Westermo Advisory - This advisory describes eight vulnerabilities in the Westermo Lynx 206-F2G layer-three industrial Ethernet switch.

Voltronic Advisory - This advisory describes four vulnerabilities in the Voltronic ViewPower Pro Uninterruptable Power Supply (UPS) management software.

APsystems Advisory - This advisory describes an improper access control vulnerability in the APsystems Energy Communication Unit (ECU-C) Power Control Software.

Orthanc Advisory - This advisory describes a cross-site scripting vulnerability in the Orthanc Osimis Web Viewer.

 

For more details about these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-1-23-24 - subscription required.

Tuesday, September 5, 2023

Review – 2 Advisories Published – 9-5-23

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Fujitsu and a medical device security advisory for products from Softneta.

Advisories

Fujitsu Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Fujitsu Real-time Video Transmission Gear "IP series".

Softneta Advisory - This advisory describes two vulnerabilities in the Softneta MedDream picture archiving and communication system (PACS).

 

For more details about these vulnerabilities, including a down-the-rabbit-hole look at Softneta vulnerability disclosure process, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-9-5-23 - subscription required.

Tuesday, March 28, 2023

OMB Approves Medical Device ‘Refusal’ Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice from the Food and Drug Administration on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. This notice was not listed in the Fall 2022 Unified Agenda. It was submitted to OMB on March 22nd, 2023.

As I noted in that earlier post, it appears that this notice is related to a recent amendment of 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

We will probably see this notice published in the Federal Register later this week.

Thursday, March 23, 2023

FDA Sends Medical Device Cybersecurity Notice to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had receive a notice from the Federal Drug Administration (FDA) on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. There is no listing for this action in the Fall 2022 Unified Agenda.

The new §524B was added to the Food, Drug, and Cosmetic Act by §3305 (pg 1374), Ensuring Cybersecurity of Medical Devices, of the Consolidated Appropriations Act, 2023 (PL 117-328, HR 2617). Subsection 3305(b) amended 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

It looks like this notice may be related to that section in relation to ‘§524B’.

Thursday, March 2, 2023

Review – 4 Advisories and 1 Update – 3-2-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rittal, Baicells, and Mitsubishi. They also published a medical device security advisory for products from Medtronic. They updated a control system security advisory for products from Mitsubishi.

Advisories

Rittal Advisory - This advisory describes an improper access control vulnerability in the Rittal CMC III locks.

Baicells Advisory - This advisory described a command injection vulnerability in the Baicells LTE TDD eNodeB devices.

Mitsubishi Advisory - This advisory describes a plain-text storage of a password vulnerability in the Mitsubishi Electric MELSEC iQ-F products.

Medtronic Advisory - This advisory describes an unverified password change vulnerability in the Medtronic Micros Clinician (A51200) app and InterStim X Clinician (A51300).

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on November 22nd, 2022.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-3-2-23 - subscription required.

Thursday, February 16, 2023

Review – 14 Advisories and 1 Update Published – 2-16-23

Today, CISA’s NCCIC-ICS published twelve control system security advisories for products from Sub-IoT and Siemens (12). They also published a medical device security advisory for products from BD. Finally, they updated an advisory for products from Delta Electronics.

NOTE 1: Siemens published one additional advisory on Tuesday that was not covered today by NCCIC-ICS. I will cover it this weekend.

NOTE 2: NCCIC-ICS continues to report on Siemens advisories that it will not report updated information on those advisories, so the seven updates published by Siemens this week will not be addressed by NCCIC-ICS.

Control System Advisories

Sub-IoT Advisory - This advisory describes an out-of-bounds write vulnerability in the Sub-IoT DASH 7 Alliance protocol implementation.

JY Open Advisory - This advisory describes three vulnerabilities in the Siemens JT Open Toolkit, JT Utilities, and Parasolid products.

Mendix Advisory - This advisory describes an improper access control vulnerability in the Siemens Mendix Applications.

COMOS Advisory - This advisory describes a classic buffer overflow vulnerability in the Siemens COMOS products.

SIMATIC Advisory - This advisory describes a TOCTOU race condition vulnerability in the Siemens SIMATIC industrial products.

RUGGEDCOM Advisory - This advisory describes seven TOCTOU race condition vulnerabilities in the Siemens RUGGEDCOM APE1808 product family.

TIA Project-Server Advisory - This advisory describes an untrusted search path vulnerability in the Siemens TIA Project-Server.

Simcenter Advisory - This advisory describes two vulnerabilities in the Siemens Simcenter Femap.

SiPass Advisory - This advisory describes an improper input validation vulnerability in the Siemens SiPass integrated AC5100, AC5102, AC5200, ACC-AP, Granta-MK3.

Brownfield Connectivity Advisory #1 - This advisory discusses eight vulnerabilities in the Siemens Brownfield Connectivity—Gateway products.

Brownfield Connectivity Advisory #2 - This advisory discusses four vulnerabilities in the Siemens Brownfield Connectivity Client.

SCALANCE Advisory - This advisory discusses an improper input validation vulnerability in the Siemens SCALANCE X200 IRT Products.

Medical Device Advisory

Solid Edge Advisory - This advisory describes 37 vulnerabilities in the Siemens Solid Edge products.

BD Advisory - This advisory this advisory describes a credentials management errors vulnerability in the BD Alaris Infusion Central.

Update

Delta Update - This update provides additional information on an advisory that was originally published on October 25th, 2022 and most recently updated on November 10th, 2022.

 

For more details about advisories, including links to researcher reports and 3rd-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-and-1-update-published - subscription required.

Thursday, December 1, 2022

Review – 3 Advisories Published – 12-1-22

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Horner Automation and Mitsubishi Electric. They also published a medical device security advisory for products from BD.

Horner Advisory - This advisory describes three vulnerabilities in the Horner Remote Compact Controller (RCC) 972.

Mitsubishi Advisory - This advisory describes an improper input validation vulnerability in the Mitsubishi MELSEC iQ-R Series products.

BD Advisory - This advisory describes a missing protection mechanism for alternate hardware interface vulnerability in the BD BodyGuard Pumps.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-12-1-22 - subscription required.


Tuesday, November 22, 2022

Review – 5 Advisories and 3 Updates Published – 11-22-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Moxa, GE, Phoenix Contact, Digital Alert Systems, and AVEVA. They updated two control system advisories for products from Moxa and one medical device security advisory for products from Hillrom.

Security Advisories

Moxa Advisory - This advisory describes an execution with unnecessary privilege vulnerability in the Moxa ARM-Based Computers.

GE Advisory - This advisory describes five vulnerabilities in the GE CIMPLICITY HMI/SCADA software.

Phoenix Contact Advisory - This advisory describes two vulnerabilities in the Phoenix Contact Automation Worx Software Suite.

NOTE: I briefly discussed these vulnerabilities on November 13th, 2022.

Digital Alert Advisory - This advisory describes two cross-site scripting vulnerabilities (one with known exploit) in the Digital Alert Systems DASDEC emergency messaging devices.

AVEVA Advisory - This advisory describes four vulnerabilities in the AVEVA Edge (InduSoft Web Studio).

Security Updates

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on August 2nd, 2022.

I briefly discussed the Mitsubishi update last weekend.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on February 18th, 2021 and most recently updated on August 2nd, 2022.

I briefly discussed the Mitsubishi update last weekend.

Hillrom Update - This update provides additional information on an advisory that was originally published on June 1st, 2021 and most recently updated on September 8th, 2022.

Thursday, October 20, 2022

Review – 1 Advisory and 2 Updates Published – 10-20-22

Today CISA’s NCCIC-ICS published a control system security advisory for products from Bentley Systems. They also updated two medical device security advisories for products from Braun.

Bentley Advisory - This advisory describes two vulnerabilities in the Bentley MicroStation Connect.

Braun Update #1 - This update provides additional information on an advisory that was originally published on October 22nd, 2020.

Braun Update #2 - This update provides additional information on an advisory that was originally published on October 21st, 2021.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-2-updates-published-e54 - subscription required.


Thursday, September 8, 2022

Review – 2 Advisories and 2 Updates Published – 9-8-22

Today, CISA’s NCCIC-ICS published a control system security advisory for products from MZ Automation and a medical device security advisory for products from Baxter. They also updated advisories for products from PTC and Hillrom.

MZ Advisory - This advisory describes four vulnerabilities in the MZ Automation libIEC61850, a library for IEC 61850 implementation.

NOTE: Since this is a library product, the vulnerabilities are only exploitable in a product in which the library is used. So, we can expect to see this show up as third-party vulnerabilities in products from other vendors.

Baxter Advisory - This advisory discusses four vulnerabilities (with proof-of-concept code available) in the Sigma and Baxter Spectrum Infusion Pumps. The Baxter advisory notes that the vulnerabilities only affect the Spectrum Wireless Battery Module (WBM) that may be used by the infusion pumps.

PTC Update - This update provides new information on an advisory that was originally published on August 30th, 2022.

Hillrom Update - This update provides new information on an advisory that was originally published on June 1st, 2021 and most recently updated on December 14th, 2021.

NOTE: The Hillrom advisory is nearly a duplicate of the CISA advisory (including the questionable use of the CISA seal), but it specifically mentions the December 14th, 2021 update where the CISA advisory does not directly. I also like their use of the ‘Unclassified’ document marking.

 

For more details about these advisories and updates, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-2-updates-published - subscription required.

 
/* Use this with templates/template-twocol.html */