Vulnerabilities CISA Warns of Apache Superset Vulnerability Exploitation CISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog. Ionut ArghireJanuary 9, 2024
Vulnerabilities CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities CISA has added to its Known Exploited Vulnerabilities Catalog four Qualcomm bugs, including three exploited as zero-days. Ionut ArghireDecember 6, 2023
Network Security Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks. Ryan NaraineNovember 30, 2023
Malware & Threats CISA Warns of Attacks Exploiting Sophos Web Appliance Vulnerability CISA adds Sophos, Oracle and Microsoft product security holes to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsNovember 17, 2023
Vulnerabilities CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days. Ionut ArghireOctober 11, 2023
Vulnerabilities CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws CISA has removed from its KEV catalog five Owl Labs video conferencing flaws that require the attacker to be in Bluetooth range. Eduard KovacsOctober 6, 2023
Risk Management Faster Patching Pace Validates CISA’s KEV Catalog Initiative CISA says Known Exploited Vulnerabilities Catalog has helped federal agencies significantly accelerate their vulnerability remediation pace. Ionut ArghireSeptember 22, 2023
Malware & Threats VMware Patches Major Security Flaws in Network Monitoring Product VWware patches critical flaws that allow hackers to bypass SSH authentication and gain access to the Aria Operations for Networks command line interface. Ryan NaraineAugust 29, 2023