CISA warns of actively exploited Windows, Sophos, and Oracle bugs

November 17, 2023 at 09:15AM The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three security issues affecting Microsoft devices, a Sophos product, and an Oracle solution to its known exploited vulnerabilities catalog. CISA advises federal agencies to install available security updates for these vulnerabilities by December 7. The three vulnerabilities are listed as … Read more

CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

November 17, 2023 at 01:06AM The U.S. CISA has added three security flaws to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The vulnerabilities include a Microsoft Windows security bypass, a Sophos command injection, and an unspecified Oracle vulnerability. A critical command injection bug has also been disclosed in FortiSIEM report server. … Read more