CISA warns agencies of fourth flaw used in Triangulation spyware attacks
ID: d551d4b1-b61d-50f9-b5b5-702cd3086bd0
STIX ID: report--d551d4b1-b61d-50f9-b5b5-702cd3086bd0
Feed Name: Bleeping Computer
CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalog — including critical ColdFusion deserialization flaws (CVE-2023-38203, CVE-2023-29300), an iMessage font RCE used in Operation Triangulation (CVE-2023-41990), an Apache Superset insecure default key (CVE-2023-27524), a Joomla improper access check (CVE-2023-23752), and a long-exploited D-Link command injection (CVE-2016-20017) — and has directed federal agencies to patch or stop using affected products by January 29 due to observed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
