Original Article Text

Click to Toggle View

CISA warns of actively exploited Windows, Sophos, and Oracle bugs. The U.S. Cybersecurity & Infrastructure Security Agency has added to its catalog of known exploited vulnerabilities (KEV) three security issues that affect Microsoft devices, a Sophos product, and an enterprise solution from Oracle. The KEV catalog contains flaws confirmed to be exploited by hackers in attacks and serves as a repository for vulnerabilities that companies all over should treat with priority. The agency is urging federal agencies to apply available security updates for the three issues before December 7. The three vulnerabilities are tracked as follows: Microsoft addressed CVE-2023-36584 in the October 2023 Patch Tuesday bundle of security updates. However, it wasn't flagged as actively exploited in the disclosure and at the time of writing it's still marked as non exploited. The critical flaw in Sophos Web Appliance, fixed on April 4, 2023, is identified as CVE-2023-1671 and has a severity score of 9.8. It can lead to remote code execution (RCE) and affects versions of the software before 4.3.10.4. It is worth noting that Sophos Web Appliance reached end-of-life on July 20 and no longer receives any type of updates. The company notified customers that they should migrate to Sophos Firewall web protection. Although CISA's KEV catalog is mainly aimed at federal agencies in the U.S. companies across the world are advised to use it as an alert system for exploited vulnerabilities and take the necessary steps to update their systems or apply vendor-recommended mitigations.

Daily Brief Summary

CYBERCRIME // CISA Alerts of Exploit Risks for Windows, Sophos, Oracle Bugs

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) warns of new exploits targeting vulnerabilities in Microsoft, Sophos, and Oracle products.

CISA has updated its Known Exploited Vulnerabilities catalog to include these actively exploited flaws, emphasizing the need for prompt action.

Federal agencies are advised to apply security updates before December 7 to mitigate the risks associated with these vulnerabilities.

CVE-2023-36584, a vulnerability within Microsoft systems, was addressed in the October 2023 Patch Tuesday updates but was not initially marked as actively exploited.

A critical bug in Sophos Web Appliance, identified as CVE-2023-1671 and with a 9.8 severity score, allows for remote code execution on outdated software versions.

Sophos Web Appliance is no longer supported since July 20, and customers are urged to switch to Sophos Firewall for continued web protection.

While CISA's KEV catalog targets U.S. federal agencies, it also acts as a global alarm for companies to secure their systems against these vulnerabilities.