{"id":16411,"date":"2023-01-21T09:14:48","date_gmt":"2023-01-21T16:14:48","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=patch_watch&p=16411"},"modified":"2023-03-16T09:26:05","modified_gmt":"2023-03-16T16:26:05","slug":"dhs-cisa-kevs-weekly-edition-26-patch-before-you-hit-the-deadline","status":"publish","type":"patch_watch","link":"https:\/\/webdev.securin.xyz\/patch_watch\/dhs-cisa-kevs-weekly-edition-26-patch-before-you-hit-the-deadline\/","title":{"rendered":"DHS CISA KEVs Weekly Edition 26: Patch Before You Hit the Deadline"},"content":{"rendered":"
The US Cyber Security department is taking an aggressive approach in tackling cyber attacks including counter attacks on cybercriminals, imposing mandatory cybersecurity regulations for sectors commonly under attack, strengthening cyber security for energy pipelines, etc. There are totally 870 vulnerabilities in the KEV catalog right now. 7 of them need your attention this week.<\/p>\n
<\/p>\n
From our analysis, we found that<\/p>\n
All 7 vulnerabilities are weaponized and have been exploited in the wild.<\/p>\n<\/li>\n
CVE-2018-18809 and CVE-2018-5430 are TIBCO vulnerabilities that were discovered in 2018. These two vulnerabilities were recently exploited in attacks following which\u00a0CISA added them<\/a>\u00a0to the KEV.<\/p>\n<\/li>\n CVE-2022-42475<\/a>\u00a0is a FortiOS vulnerability which is actively being exploited by suspected Chinese threat actors deploying a new malware known as BOLDMOVE.<\/p>\n<\/li>\n