Aggregator
Читать после слепоты: новый имплантат вернул зрение пациентам
Cisco Releases Security Bundle for Cisco ASA, FMC, and FTD Software
Cisco released its October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication to address vulnerabilities in Cisco ASA, FMC, and FTD. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the following advisory and apply the necessary updates:
CISA, US, and International Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
Today, CISA—along with U.S. and international partners—released joint guidance, Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers. This guide aids software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC).
A well-designed software deployment process can help guarantee customers receive new features, security, and reliability while minimizing unplanned outages.
CISA encourages software and service manufacturers review this guide, evaluate their software deployment processes, and address them through a continuous improvement program.
To learn more about secure by design principles and practices, visit CISA’s Secure by Design webpage.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-20481 Cisco ASA and FTD Denial-of-Service Vulnerability
- CVE-2024-37383 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA Releases Four Industrial Control Systems Advisories
CISA released four Industrial Control Systems (ICS) advisories on October 24, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-298-01 VIMESA VHF/FM Transmitter Blue Plus
- ICSA-24-298-02 iniNet Solutions SpiderControl SCADA PC HMI Editor
- ICSA-24-298-03 Deep Sea Electronics DSE855
- ICSA-24-268-06 OMNTEC Proteus Tank Monitoring (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
Building an “HF Helper” for Improving RTL-SDR HF Reception
CVE-2024-45031 | Apache Syncope up to 2.1.14/3.0.8 Console cross site scripting
CVE-2024-5608 | Zoho ManageEngine ADAudit Plus up to 8120 Technician Reports sql injection
CVE-2024-49683 | Schema & Structured Data for WP & AMP Plugin up to 1.3.5 on WordPress authorization
CVE-2024-49682 | smp7 Simple Membership Plugin up to 4.5.3 on WordPress redirect
Лазер против ракет: британцы создали непробиваемый небесный щит
【黑产大数据】汽车贷款欺诈产业链解构
美国颁布史上最严数据安全规定
假冒LockBit,勒索软件滥用 AWS S3窃取数据
思科披露其ASA和FTD软件中存在被主动利用的漏洞 CVE - 2024 - 20481
В тени Sky Global: США тайно охотились за миллионами в Европе
【在野利用】Fortinet FortiManager 身份认证绕过漏洞(CVE-2024-47575)安全风险通告
用飞书多维表格和扫码枪,快速构建个人图书管理系统
Notifications in Threat Intelligence Lookup
We are thrilled to announce a significant enhancement to Threat Intelligence Lookup — Notifications. The new functionality allows users to subscribe to real-time notifications for new results related to their specified queries. Tracking emerging and evolving cyber threats has never been easier. What Are Lookup Notifications? Lookup Notifications enable users to receive timely updates on […]
The post Notifications in Threat Intelligence Lookup appeared first on ANY.RUN's Cybersecurity Blog.