Tag

Known Exploited Vulnerabilities

All articles tagged with #known exploited vulnerabilities

technology4 hours ago

Risk-Based Patch Strategy Drives Federal Cyber Hygiene Under BOD 26-04

CISA's Binding Operational Directive 26-04 requires federal civilian agencies to prioritize vulnerability remediation based on risk, using the Known Exploited Vulnerabilities (KEV) Catalog and SSVC data while considering asset exposure, exploit automation, and technical impact. It establishes a three-phase rollout—immediate policy updates and automation (Phase I), process updates within 60 days (Phase II), and vulnerability remediation within 180 days (Phase III)—with automated reporting via the Continuous Diagnostics and Monitoring program and ongoing Cyber Hygiene practices. The directive supersedes BOD 19-02 and 22-01, aligns with OMB Circular A-130 and FISMA, and aims to harden federal networks against sophisticated cyber threats by focusing on high-risk vulnerabilities and maintaining asset tagging and exposure data.

"CISA Identifies High-Severity RCE and Apache Superset Vulnerabilities in Latest Warning"
cybersecurity2 years ago

"CISA Identifies High-Severity RCE and Apache Superset Vulnerabilities in Latest Warning"

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified six actively exploited vulnerabilities affecting products from Apple, Adobe, Apache, D-Link, and Joomla, urging federal agencies to patch them by January 29 or cease using the vulnerable products. These vulnerabilities have been leveraged in recent attacks, with some only being disclosed recently, and pose significant risks to organizations. CISA advises organizations to check for these flaws and apply available security updates or mitigation steps.