Article Details

Scrape Timestamp (UTC): 2024-01-10 04:51:56.012

Source: https://thehackernews.com/2024/01/cisa-flags-6-vulnerabilities-apple.html

Original Article Text

Click to Toggle View

CISA Flags 6 Vulnerabilities - Apple, Apache, Adobe , D-Link, Joomla Under Attack. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability impacting the Apache Superset open-source data visualization software that could enable remote code execution. It was fixed in version 2.1. Details of the issue first came to light in April 2023, with Horizon3.ai's Naveen Sunkavally describing it as a "dangerous default configuration in Apache Superset that allows an unauthenticated attacker to gain remote code execution, harvest credentials, and compromise data." It's currently not known how the vulnerability is being exploited in the wild. Also added by CISA are five other flaws - It's worth noting that CVE-2023-41990, patched by Apple in iOS 15.7.8 and iOS 16.3, was used by unknown actors as part of Operation Triangulation spyware attacks to achieve remote code execution when processing a specially crafted iMessage PDF attachment. Federal Civilian Executive Branch (FCEB) agencies have been recommended to apply fixes for the aforementioned bugs by January 29, 2024, to secure their networks against active threats. The Ultimate Enterprise Browser Checklist Download a Concrete and Actionable Checklist for Finding a Browser Security Platform. Master Cloud Security - Get FREE eBook Comprehensive eBook covering cloud security across infrastructure, containers, and runtime environments for security professionals

Daily Brief Summary

CYBERCRIME // CISA Updates KEV Catalog with Six Actively Exploited Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six security flaws to its Known Exploited Vulnerabilities catalog due to active exploitation evidence.

Vulnerabilities affect various products: Apple iOS, Apache, Adobe, D-Link, and Joomla, with one high-severity flaw in Apache Superset enabling remote code execution.

Apache Superset's vulnerability (CVE-2023-27524) has a CVSS score of 8.9 and was addressed in version 2.1; it presents a risk of credentials compromise and data exfiltration.

CVE-2023-41990, a flaw in Apple's iOS, was exploited in Operation Triangulation attacks to execute remote code via a malicious iMessage PDF attachment.

CISA has mandated Federal Civilian Executive Branch agencies to patch these vulnerabilities by January 29, 2024, to protect against these active threats.

The agency's emphasis on these vulnerabilities highlights the ongoing risks and the importance of timely security updates in mitigating potential cyber attacks.