Tech

US government agencies told to patch these critical security flaws or face attack

Share
Share


  • CISA adds CVE-2023-28461 to its Known Exploited Vulnerabilities catalog
  • Federal agencies have until December 16 to patch up
  • The bug is being abused by a Chinese group known as Earth Kasha

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning federal agencies they have a three-week deadline to apply the available patch, or stop using the affected software altogether.

The agency added a missing authentication vulnerability to KEV tracked under CVE-2023-28461, which has a severity score of 9.8, and allows crooks to execute arbitrary code on remote devices.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
HR departments could soon be set for a major shake-up as AI takes hold
Tech

HR departments could soon be set for a major shake-up as AI takes hold

Agentic AI adoption will rise by 327% by 2027, boosting productivity by...

ChatGPT is getting smarter, but its hallucinations are spiraling
Tech

ChatGPT is getting smarter, but its hallucinations are spiraling

OpenAI’s latest AI models, GPT o3 and o4-mini, hallucinate significantly more often...

You can now edit images in Gemini directly
Tech

You can now edit images in Gemini directly

Google’s Gemini can now edit both AI-generated and personal images using text...