New Cyber Nightmares: ARM and PHP Vulnerabilities Added to CISA’s Exploited List

CISA has added two new vulnerabilities, including the ARM Mali GPU Kernel Driver Use-After-Free Vulnerability, to its Known Exploited Vulnerabilities Catalog. These are frequent attack vectors posing significant risks to the federal enterprise.

Pro Dashboard

Hot Take:

Looks like CISA’s Known Exploited Vulnerabilities Catalog just got two new unwanted guests! It’s like a VIP list, but for cyberattacks. Forget red carpets, these vulnerabilities bring drama right to your doorstep—if your doorstep is a federal network.

Key Points:

  • Two new vulnerabilities added to CISA’s Known Exploited Vulnerabilities Catalog.
  • CVE-2024-4610 targets ARM Mali GPU Kernel Driver with a Use-After-Free vulnerability.
  • CVE-2024-4577 affects PHP-CGI with an OS Command Injection vulnerability.
  • Binding Operational Directive (BOD) 22-01 mandates FCEB agencies to address these vulnerabilities.
  • CISA recommends all organizations to prioritize timely remediation of cataloged vulnerabilities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?