About Stacey Ehling

This author has not yet filled in any details.
So far Stacey Ehling has created 68 blog entries.

Chrome Vulnerabilities Reported

By |2026-09-08T09:55:26-04:00September 8th, 2026|

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution TLP: CLEAR September 8, 2026 This Multi-State Information Sharing and Analysis Center (MS-ISAC) Advisory is being provided to assist agencies, organizations, and individuals in guarding against the persistent malicious actions of cybercriminals. NOTE: In an effort to reduce duplicate emails, if you currently receive cybersecurity advisories direct [...]

Beware: Device Code Phishing

By |2026-09-08T09:40:10-04:00September 8th, 2026|

The Rise of Device Code Phishing Companies, such as Microsoft, Google, and Apple, offer device login codes through a legitimate OAuth 2.0 Device Authorization Grant  that is designed for devices with limited input capabilities, like TVs, printers, and game consoles. For example, if a user wants to log in to a streaming app on a new Smart [...]

Medusa Ransomware Alert

By |2026-08-18T15:01:36-04:00August 18th, 2026|

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) have released an updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service [...]

Zoom Vulnerability

By |2026-08-12T13:44:37-04:00August 12th, 2026|

A vulnerability has been discovered in Zoom Clients. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and install malware. Threat Intelligence There are currently [...]

Microsoft Product Vulnerabilities

By |2026-08-11T16:09:59-04:00August 11th, 2026|

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; [...]

IT Help Desk Staff Targeted

By |2026-08-06T13:52:02-04:00August 7th, 2026|

Beware of Threat Actors Targeting IT Help Desk Staff Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms [...]

You DON’T Want this UPS Delivery!

By |2026-08-06T13:52:28-04:00August 6th, 2026|

The NJCCIC observed a phishing campaign impersonating UPS delivery notifications. These messages use subject lines such as “Parcel Arrival Notification,” “Your Package Is Ready for Pickup,” and “Your Parcel Has Arrived” and are purported to be from the following sender(s): "UPS Parcel Services" <contact[@]shipfasts[.]com> "UPS Delivery Support" <contact[@]learnstax[.]com> Messages include an Adobe PDF attachment that [...]

Water & Wastewater System Attacks in NJ

By |2026-08-05T15:34:42-04:00August 5th, 2026|

NJ.com is reporting that at least two New Jersey water systems were hit by cyberattacks similar to those reported in several other states in recent days, officials said Monday. The New Jersey Office of Homeland Security and Preparedness said the incidents affected some automated controls, but did not cause any interruption in service. The attack temporarily limited operators’ ability [...]

Threats Target NJ Critical Infrastrcucture & Public Sector

By |2026-07-30T13:08:56-04:00July 30th, 2026|

The NJCCIC observed a recent uptick in threat actors targeting New Jersey critical infrastructure and public sector organizations, including local municipalities, school districts, and police departments. Threat actors send phishing emails with links intended to capture account credentials and compromise accounts, and then send additional phishing emails from legitimate accounts to avoid suspicion and keep [...]

Malicious Zoom Extensions

By |2026-07-23T14:39:58-04:00July 23rd, 2026|

Organizations Beware: Requests for Assistance Prompting Malicious Zoom Extension Downloads Public and private sector organizations post available services on their websites and online platforms. They may also provide referrals and offer an online search feature to find local assistance. Threat actors exploit this feature to send supposed requests for assistance and trick their targets into [...]

Go to Top