Site icon TheCyberThrone

CISA KEV Update Part I – April 2023

Advertisements

The US CISA has added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog.

Five of the issues added by CISA to its catalog are part of the exploits used by surveillance vendors to target mobile devices with their commercial spyware:

Based on the recent report published by Google’s Threat Analysis Group that shared details about two distinct campaigns that used several zero-day exploits against Android, iOS, and Chrome. The experts pointed out that both campaigns were limited and highly targeted. The threat actors behind the attacks used both zero-day and n-day exploits in their exploits.

Advertisements

The exploits were used to install commercial spyware and malicious apps on targets’ devices.

The remaining flaws added to the catalog are:

CISA orders federal agencies to fix this flaw by April 20, 2023.

Exit mobile version