logo

CISA warns agencies of fourth flaw used in Triangulation spyware attacks

ID: d551d4b1-b61d-50f9-b5b5-702cd3086bd0

STIX ID: report--d551d4b1-b61d-50f9-b5b5-702cd3086bd0

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalog — including critical ColdFusion deserialization flaws (CVE-2023-38203, CVE-2023-29300), an iMessage font RCE used in Operation Triangulation (CVE-2023-41990), an Apache Superset insecure default key (CVE-2023-27524), a Joomla improper access check (CVE-2023-23752), and a long-exploited D-Link command injection (CVE-2016-20017) — and has directed federal agencies to patch or stop using affected products by January 29 due to observed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.