FINRA publishes alert on critical software vulnerability

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

Recently, FINRA issued a cybersecurity alert bulletin to all member firms regarding a critical vulnerability within a software company’s transfer software, specifically affecting its Secure File Transfer Protocol module. The vulnerability could potentially allow for authentication bypass, FINRA warned. The software developer has released a security bulletin advising firms to upgrade to the latest version of the software to address this issue.

Additionally, a new risk has been identified in a third-party component within the company’s transfer software, which increases the risk of authentication bypass if not resolved. Firms are instructed to take precautionary measures, including blocking public inbound Remote Desktop Protocol access to the servers running the software and limiting outbound access to trusted endpoints only. The third-party will release a fix, which the software company will make available. The alert follows a similar incident in June 2023 for which FINRA also issued an advisory to member firms.

FINRA also reminds firms to reference Regulatory Notice 22-29 from December 2022, which provides guidance on ransomware risks and offers considerations for evaluating cybersecurity programs in response to ongoing threats.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Orrick, Herrington & Sutcliffe LLP | Attorney Advertising

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide