Tech

US government agencies told to patch these critical security flaws or face attack

Share
Share


  • CISA adds CVE-2023-28461 to its Known Exploited Vulnerabilities catalog
  • Federal agencies have until December 16 to patch up
  • The bug is being abused by a Chinese group known as Earth Kasha

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning federal agencies they have a three-week deadline to apply the available patch, or stop using the affected software altogether.

The agency added a missing authentication vulnerability to KEV tracked under CVE-2023-28461, which has a severity score of 9.8, and allows crooks to execute arbitrary code on remote devices.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Biden administration to loan .6B to EV maker Rivian to build Georgia factory that automaker paused
Tech

Biden administration to loan $6.6B to EV maker Rivian to build Georgia factory that automaker paused

A Rivian R1S is displayed outside of the auto manufacturer’s new space...

Researchers highlight Nobel-winning AI breakthroughs and call for interdisciplinary innovation
Tech

Researchers highlight Nobel-winning AI breakthroughs and call for interdisciplinary innovation

Through the WeightWatcher looking glass. Credit: Patterns (2024). DOI: 10.1016/j.patter.2024.101099 In 2024,...

Five ways you might already encounter AI in cities (and not realize it)
Tech

Five ways you might already encounter AI in cities (and not realize it)

Credit: Pixabay/CC0 Public Domain You’d probably notice if the car that cut...