Aggregator
CVE-2021-40736 | Adobe Audition up to 14.4 memory corruption (apsb21-92 / Nessus ID 209482)
CVE-2021-40738 | Adobe Audition up to 14.4 WAV File Parser memory corruption (apsb21-92 / Nessus ID 209482)
CISA Releases Two Industrial Control Systems Advisories
CISA released two Industrial Control Systems (ICS) advisories on May 1, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-121-01 KUNBUS GmbH Revolution Pi
- ICSMA-25-121-01 MicroDicom DICOM Viewer
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-38475 Apache HTTP Server Improper Escaping of Output Vulnerability
- CVE-2023-44221 SonicWall SMA100 Appliances OS Command Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CVE-2021-40740 | Adobe Audition up to 14.4 M4A File Parser memory corruption (apsb21-92 / Nessus ID 209482)
CVE-2021-40777 | Adobe Media Encoder up to 15.4.1 memory corruption (apsb21-99 / Nessus ID 209464)
CVE-2021-40763 | Adobe Character Animator up to 4.4 WAF File Parser memory corruption (apsb21-95 / Nessus ID 209377)
CVE-2021-40764 | Adobe Character Animator up to 4.4 M4A File Parser memory corruption (apsb21-95 / Nessus ID 209377)
CVE-2021-40765 | Adobe Character Animator up to 4.4 M4A File Parser memory corruption (apsb21-95 / Nessus ID 209377)
CVE-2021-40779 | Adobe Media Encoder up to 15.4.1 memory corruption (apsb21-99 / Nessus ID 209464)
Recommended contract clauses for security operations centre procurement (ITSM.00.500)
Supply Chain Cybersecurity – CISO Risk Management Guide
In today’s hyper-connected business environment, supply chains are no longer just about the physical movement of goods they are digital ecosystems linking organizations, suppliers, partners, and service providers. This interdependence brings efficiency and innovation, but also introduces significant cybersecurity risks. Attackers increasingly target supply chains, exploiting the weakest links to infiltrate even the most secure […]
The post Supply Chain Cybersecurity – CISO Risk Management Guide appeared first on Cyber Security News.
Researchers Find Way to Bypass Phishing-Resistant MFA in Microsoft Entra ID
Cybersecurity researchers have uncovered a sophisticated technique to bypass Microsoft’s phishing-resistant multi-factor authentication (MFA) by exploiting the device code authentication flow and Primary Refresh Tokens (PRTs). This method allows attackers to register Windows Hello for Business keys, effectively creating a persistent backdoor even in environments with strict MFA policies. The technique was initially developed for […]
The post Researchers Find Way to Bypass Phishing-Resistant MFA in Microsoft Entra ID appeared first on Cyber Security News.