Aggregator
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability
- CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
- CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
- CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Cloud Security Posture Management: silver bullet or another piece in the cloud puzzle?
OpenClaw 的超轻量级替代品:nanobot,只有 4000 行代码
AT&T breach data resurfaces with new risks for customers
【马年礼盒】2025您的年终荣耀请签收!
OpenClaw曝出严重漏洞,黑客可一键获取用户权限
Каждые 0,03 секунды – новая атака. Как Тайвань выживает под гнетом 2,4 млн ударов в день
16-31 January 2026 Cyber Attacks Timeline
Firefox to let users manage and block AI features
Mozilla will add a set of controls in Firefox that let users manage and block GenAI features in the desktop browser. The controls will be included in Firefox version 148 on February 24, 2026. “We believe choice is more important than ever as AI becomes a part of people’s browsing experiences. What matters to us is giving people control, no matter how they feel about AI,” Ajit Varma, Head of Firefox, said. Each of these … More →
The post Firefox to let users manage and block AI features appeared first on Help Net Security.
黄仁勋与安卓盒子的故事:我们想支持这东西多久?只要我们活着那么久。
Snowflake makes enterprise data AI-ready with native Postgres in its AI Data Cloud
Snowflake announced advancements that make data AI-ready by design, enabling enterprises to rely on data that is continuously available, usable, and governed as AI transitions from experimentation into real-world production systems. With new enhancements to Snowflake Postgres, the database now runs natively in the AI Data Cloud, allowing enterprises to consolidate transactional, analytical, and AI use cases on a single, secure platform. To help ensure AI systems are trusted at enterprise scale, Snowflake is further … More →
The post Snowflake makes enterprise data AI-ready with native Postgres in its AI Data Cloud appeared first on Help Net Security.