CISA urges devs to weed out OS command injection vulnerabilities
ID: 4739ba52-7195-526b-b3b7-0f8e38890a4c
STIX ID: report--4739ba52-7195-526b-b3b7-0f8e38890a4c
Feed Name: Bleeping Computer
CISA and the FBI issued a joint advisory after Velvet Ant (a Chinese state‑sponsored group) exploited multiple OS command injection vulnerabilities (CVE-2024-20399, CVE-2024-3400, CVE-2024-21887) to compromise Cisco, Palo Alto, and Ivanti network edge devices and deploy custom malware for persistence; the advisory urges developers and leaders to adopt secure-by-design practices (input validation, parameterization, safe library functions, limited user-built command parts, code review and testing) to eliminate CWE-78 class flaws.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
