Article Details

Scrape Timestamp (UTC): 2025-03-04 04:55:55.943

Source: https://thehackernews.com/2025/03/cisco-hitachi-microsoft-and-progress.html

Original Article Text

Click to Toggle View

Cisco, Hitachi, Microsoft, and Progress Flaws Actively Exploited—CISA Sounds Alarm. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting software from Cisco, Hitachi Vantara, Microsoft Windows, and Progress WhatsUp Gold to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The list of vulnerabilities is as follows - There are little-to-no reports about how some of the aforementioned flaws are weaponized in the wild, but French cybersecurity company Sekoia revealed last week that threat actors are abusing CVE-2023-20118 to rope susceptible routers into a botnet called PolarEdge. As for CVE-2024-4885, the Shadowserver Foundation said it has observed exploitation attempts against the flaw as of August 1, 2024. Data from GreyNoise shows that as many as eight unique IP addresses from Hong Kong, Russia, Brazil, South Korea, and the United Kingdom are linked to the malicious exploitation of the vulnerability. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are urged to apply the necessary mitigations by March 24, 2025, to secure their networks.

Daily Brief Summary

CYBERCRIME // CISA Warns of Active Exploits in Cisco, Microsoft, and Others

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploitations targeting software flaws in products from Cisco, Hitachi Vantara, Microsoft, and Progress.

Five security vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog, prompting urgent mitigation actions.

Sekoia, a French cybersecurity firm, reported that CVE-2023-20118 is being used to incorporate routers into the PolarEdge botnet.

The Shadowserver Foundation has observed activities exploiting CVE-2024-4885, with attacks detected as recently as August 1, 2024.

Analysis from GreyNoise identifies exploitation attempts from multiple countries including Hong Kong, Russia, Brazil, South Korea, and the United Kingdom.

Federal Civilian Executive Branch agencies are directed to implement necessary security measures by March 24, 2025, to protect against these threats.