/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CISA creates a catalog of known exploited vulnerabilities, including in Apple and Google products, and orders federal agencies to patch within timeframes

Binding Operational Directive (BOD) 22-01 establishes timeframes for mitigation of known exploited vulnerabilities and requires improvements in vulnerability management programs: https://www.cisa.gov/... https://twitter.com/... Eric Geller / @ericgeller : New: CISA orders all federal agencies to rapidly patch hundreds of known vulnerabilities. https://cyber.dhs.gov/... Agencies have two weeks to patch flaws discovered before 2021, and six months for flaws discovered this year. Here's the catalog of vulns: https://www.cisa.gov/... https://twitter.com/... @cisagov : ❗️ Today we issued Binding Operational Directive 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities: https://www.cisa.gov/... This establishes priorities for vulnerability management & will help improve Federal Agency vulnerability management practices. https://twitter.com/... Ryan Kovar / @meansec : Here @splunk we are often asked “what should we focus on for defenses” here is a great list from @CISAgov of places to start. #SURGe wanted to help so worked with our #STRT breathren. CVE tags are now part of our security content. Read our blog here: https://splunk.com/... https://twitter.com/... Drew Church / @drewchurch : Vulnerability management is a passion of mine. I'm so glad that @splunk got to work with JCDC on helping get this message out. CVE tags are now part of our security content. Read more here: https://www.splunk.com/... https://twitter.com/... Audra Streetman / @audrastreetman : Splunk's Threat Research Team (STRT) and #SURGe have worked together to amplify @CISAgov's Known Exploited Vulnerability Catalog with added functionality in @Splunk Enterprise Security Content Updates (ESCU). Read more here: https://www.splunk.com/... https://twitter.com/... Nicole Sganga / @nicolesganga : CISA Director Jen Easterly on today's cyber directive: “For the first time, we've given timelines to remediate those specific vulnerabilities that we know have been actively exploited by adversaries... the ones we think are most dangerous.” https://www.cisa.gov/... https://twitter.com/... Matthew Olney / @kpyke : Bold and welcome action by @CISAJen and the crew at @CISAgov with an escalation in patching requirements by way of https://cyber.dhs.gov/.... If a patch is available and the vulnerability is being exploited in the wild, every agency now has a 2 week timeline to complete patching. @daveaitel : CISA should release tools that help with compliance. Like is there a version of metasploit or canvas or core impact or something that has all of these vulnerabilities in it? https://twitter.com/... Eric Geller / @ericgeller : Sorry, I tweeted the deadlines backwards. It's two weeks for flaws discovered in 2021 and six months for flaws discovered earlier. https://twitter.com/... @cisainfrasec : The BOD is for federal agencies, however, @CISAgov also created a catalog of the most common CVE's to help all organizations take action against known exploited vulnerabilities: https://cisa.gov/... #CVE https://twitter.com/... Jim Langevin / @jimlangevin : 🚨BOD alert! @CISAgov has issued a binding operational directive requiring Federal agencies to patch vulnerabilities that bad actors have exploited in the wild. Check out the list and patch your systems! https://www.cisa.gov/... Catalin Cimpanu / @campuscodi : CISA launched today a catalog of known exploited vulnerabilities It also issued a binding operational directive ordering US federal agencies to patch publicly exploited bugs by: -Nov 17, 2021 (CVE-2021 exploits) -May 3, 2022 (older exploits) https://therecord.media/... https://twitter.com/... Kevin Beaumont / @gossithedog : This is the right thing to do... and also a B-I-G ask for those who have managed security departments. https://twitter.com/...

The Record Catalin Cimpanu

Discussion

  • @cisajen Jen Easterly on x
    BIG step forward today in protecting Federal Civilian Networks—Binding Operational Directive (BOD) 22-01 establishes timeframes for mitigation of known exploited vulnerabilities and requires improvements in vulnerability management programs: https://www.cisa.gov/... https://twitt…
  • @ericgeller Eric Geller on x
    New: CISA orders all federal agencies to rapidly patch hundreds of known vulnerabilities. https://cyber.dhs.gov/... Agencies have two weeks to patch flaws discovered before 2021, and six months for flaws discovered this year. Here's the catalog of vulns: https://www.cisa.gov/... …
  • @cisagov @cisagov on x
    ❗️ Today we issued Binding Operational Directive 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities: https://www.cisa.gov/... This establishes priorities for vulnerability management & will help improve Federal Agency vulnerability management practices. https…
  • @meansec Ryan Kovar on x
    Here @splunk we are often asked “what should we focus on for defenses” here is a great list from @CISAgov of places to start. #SURGe wanted to help so worked with our #STRT breathren. CVE tags are now part of our security content. Read our blog here: https://splunk.com/... https:…
  • @drewchurch Drew Church on x
    Vulnerability management is a passion of mine. I'm so glad that @splunk got to work with JCDC on helping get this message out. CVE tags are now part of our security content. Read more here: https://www.splunk.com/... https://twitter.com/...
  • @audrastreetman Audra Streetman on x
    Splunk's Threat Research Team (STRT) and #SURGe have worked together to amplify @CISAgov's Known Exploited Vulnerability Catalog with added functionality in @Splunk Enterprise Security Content Updates (ESCU). Read more here: https://www.splunk.com/... https://twitter.com/...
  • @nicolesganga Nicole Sganga on x
    CISA Director Jen Easterly on today's cyber directive: “For the first time, we've given timelines to remediate those specific vulnerabilities that we know have been actively exploited by adversaries... the ones we think are most dangerous.” https://www.cisa.gov/... https://twitte…
  • @kpyke Matthew Olney on x
    Bold and welcome action by @CISAJen and the crew at @CISAgov with an escalation in patching requirements by way of https://cyber.dhs.gov/.... If a patch is available and the vulnerability is being exploited in the wild, every agency now has a 2 week timeline to complete patching.
  • @daveaitel @daveaitel on x
    CISA should release tools that help with compliance. Like is there a version of metasploit or canvas or core impact or something that has all of these vulnerabilities in it? https://twitter.com/...
  • @ericgeller Eric Geller on x
    Sorry, I tweeted the deadlines backwards. It's two weeks for flaws discovered in 2021 and six months for flaws discovered earlier. https://twitter.com/...
  • @cisainfrasec @cisainfrasec on x
    The BOD is for federal agencies, however, @CISAgov also created a catalog of the most common CVE's to help all organizations take action against known exploited vulnerabilities: https://cisa.gov/... #CVE https://twitter.com/...
  • @jimlangevin Jim Langevin on x
    🚨BOD alert! @CISAgov has issued a binding operational directive requiring Federal agencies to patch vulnerabilities that bad actors have exploited in the wild. Check out the list and patch your systems! https://www.cisa.gov/...
  • @campuscodi Catalin Cimpanu on x
    CISA launched today a catalog of known exploited vulnerabilities It also issued a binding operational directive ordering US federal agencies to patch publicly exploited bugs by: -Nov 17, 2021 (CVE-2021 exploits) -May 3, 2022 (older exploits) https://therecord.media/... https://tw…
  • @gossithedog Kevin Beaumont on x
    This is the right thing to do... and also a B-I-G ask for those who have managed security departments. https://twitter.com/...