Aggregator
Perplexity 正式发布 macOS 客户端|基于 AI 的对话式搜索引擎
FortiJump: Fortinet признала 0Day в критической инфраструктуре
Читать после слепоты: новый имплантат вернул зрение пациентам
Cisco Releases Security Bundle for Cisco ASA, FMC, and FTD Software
Cisco released its October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication to address vulnerabilities in Cisco ASA, FMC, and FTD. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the following advisory and apply the necessary updates:
CISA, US, and International Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
Today, CISA—along with U.S. and international partners—released joint guidance, Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers. This guide aids software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC).
A well-designed software deployment process can help guarantee customers receive new features, security, and reliability while minimizing unplanned outages.
CISA encourages software and service manufacturers review this guide, evaluate their software deployment processes, and address them through a continuous improvement program.
To learn more about secure by design principles and practices, visit CISA’s Secure by Design webpage.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-20481 Cisco ASA and FTD Denial-of-Service Vulnerability
- CVE-2024-37383 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA Releases Four Industrial Control Systems Advisories
CISA released four Industrial Control Systems (ICS) advisories on October 24, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-298-01 VIMESA VHF/FM Transmitter Blue Plus
- ICSA-24-298-02 iniNet Solutions SpiderControl SCADA PC HMI Editor
- ICSA-24-298-03 Deep Sea Electronics DSE855
- ICSA-24-268-06 OMNTEC Proteus Tank Monitoring (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.