CISA Adds One Known Exploited Vulnerability to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-21762 Fortinet FortiOS Out-of-Bound Write Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established

Continue ReadingCISA Adds One Known Exploited Vulnerability to Catalog

JetBrains Releases Security Advisory for TeamCity On-Premises

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure

Continue ReadingJetBrains Releases Security Advisory for TeamCity On-Premises

Health data: the CNIL recalls the security and confidentiality measures for access to the computerized patient file (DPI)

  • Post author:
  • Post category:

La CNIL a mis en demeure plusieurs établissements de santé de prendre les mesures permettant d’assurer la sécurité du dossier patient informatisé, rappelant que les données des patients ne doivent être accessibles qu’aux personnes justifiant du besoin d’en connaître.

Continue ReadingHealth data: the CNIL recalls the security and confidentiality measures for access to the computerized patient file (DPI)

CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security

  • Post author:
  • Post category:

Today, CISA partnered with the Open Source Security Foundation (OpenSSF) Securing Software Repositories Working Group to publish the Principles for Package Repository Security framework. Recognizing the critical role package repositories play in securing open source software ecosystems, this framework lays out voluntary security maturity levels for package repositories. This publication supports Objective 1.2 of CISA's

Continue ReadingCISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security

CISA Releases Two Industrial Control Systems Advisories

  • Post author:
  • Post category:

CISA released two Industrial Control Systems (ICS) advisories on February 8, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-039-01 Qolsys IQ Panel 4, IQ4 HUB ICSA-23-082-06 ProPump and Controls Osprey Pump Controller (Update A) CISA encourages users and administrators to review the newly released ICS advisories for

Continue ReadingCISA Releases Two Industrial Control Systems Advisories