CISA Adds 13 Known Exploited Vulnerabilities to Catalog

Original release date: January 18, 2022CISA has added 13 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in…

Comments Off on CISA Adds 13 Known Exploited Vulnerabilities to Catalog

Oracle Releases January 2022 Critical Patch Update

Original release date: January 18, 2022Oracle has released its Critical Patch Update for January 2022 to address 497 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities…

Comments Off on Oracle Releases January 2022 Critical Patch Update

CISA Urges Organizations to Implement Immediate Cybersecurity Measures to Protect Against Potential Threats

Original release date: January 18, 2022In response to recent malicious cyber incidents in Ukraine—including the defacement of government websites and the presence of potentially destructive malware on Ukrainian systems—CISA has…

Comments Off on CISA Urges Organizations to Implement Immediate Cybersecurity Measures to Protect Against Potential Threats

Microsoft Releases January 2022 Security Updates

Original release date: January 11, 2022Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker could exploit some of these vulnerabilities to take control of an affected…

Comments Off on Microsoft Releases January 2022 Security Updates

CISA Adds 15 Known Exploited Vulnerabilities to Catalog

Original release date: January 10, 2022CISA has added 15 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the…

Comments Off on CISA Adds 15 Known Exploited Vulnerabilities to Catalog

Apache Releases Security Update for HTTP Server

Original release date: December 22, 2021The Apache Software Foundation has released Apache HTTP Server 2.4.52. This version addresses vulnerabilities—CVE-2021-44790 and CVE-2021-44224—one of which may allow a remote attacker to take…

Comments Off on Apache Releases Security Update for HTTP Server

Mitigating Log4Shell and Other Log4j-Related Vulnerabilities

Original release date: December 22, 2021CISA, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the cybersecurity authorities of Australia, Canada, New Zealand, and the United Kingdom…

Comments Off on Mitigating Log4Shell and Other Log4j-Related Vulnerabilities