CISA creates a catalog of known exploited vulnerabilities, including in Apple and Google products, and orders federal agencies to patch within timeframes
Binding Operational Directive (BOD) 22-01 establishes timeframes for mitigation of known exploited vulnerabilities and requires improvements in vulnerability management programs: https://www.cisa.gov/... https://twitter.com/... Eric Geller / @ericgeller : New: CISA orders all federal agencies to rapidly patch hundreds of known vulnerabilities. https://cyber.dhs.gov/... Agencies have two weeks to patch flaws discovered before 2021, and six months for flaws discovered this year. Here's the catalog of vulns: https://www.cisa.gov/... https://twitter.com/... @cisagov : ❗️ Today we issued Binding Operational Directive 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities: https://www.cisa.gov/... This establishes priorities for vulnerability management & will help improve Federal Agency vulnerability management practices. https://twitter.com/... Ryan Kovar / @meansec : Here @splunk we are often asked “what should we focus on for defenses” here is a great list from @CISAgov of places to start. #SURGe wanted to help so worked with our #STRT breathren. CVE tags are now part of our security content. Read our blog here: https://splunk.com/... https://twitter.com/... Drew Church / @drewchurch : Vulnerability management is a passion of mine. I'm so glad that @splunk got to work with JCDC on helping get this message out. CVE tags are now part of our security content. Read more here: https://www.splunk.com/... https://twitter.com/... Audra Streetman / @audrastreetman : Splunk's Threat Research Team (STRT) and #SURGe have worked together to amplify @CISAgov's Known Exploited Vulnerability Catalog with added functionality in @Splunk Enterprise Security Content Updates (ESCU). Read more here: https://www.splunk.com/... https://twitter.com/... Nicole Sganga / @nicolesganga : CISA Director Jen Easterly on today's cyber directive: “For the first time, we've given timelines to remediate those specific vulnerabilities that we know have been actively exploited by adversaries... the ones we think are most dangerous.” https://www.cisa.gov/... https://twitter.com/... Matthew Olney / @kpyke : Bold and welcome action by @CISAJen and the crew at @CISAgov with an escalation in patching requirements by way of https://cyber.dhs.gov/.... If a patch is available and the vulnerability is being exploited in the wild, every agency now has a 2 week timeline to complete patching. @daveaitel : CISA should release tools that help with compliance. Like is there a version of metasploit or canvas or core impact or something that has all of these vulnerabilities in it? https://twitter.com/... Eric Geller / @ericgeller : Sorry, I tweeted the deadlines backwards. It's two weeks for flaws discovered in 2021 and six months for flaws discovered earlier. https://twitter.com/... @cisainfrasec : The BOD is for federal agencies, however, @CISAgov also created a catalog of the most common CVE's to help all organizations take action against known exploited vulnerabilities: https://cisa.gov/... #CVE https://twitter.com/... Jim Langevin / @jimlangevin : 🚨BOD alert! @CISAgov has issued a binding operational directive requiring Federal agencies to patch vulnerabilities that bad actors have exploited in the wild. Check out the list and patch your systems! https://www.cisa.gov/... Catalin Cimpanu / @campuscodi : CISA launched today a catalog of known exploited vulnerabilities It also issued a binding operational directive ordering US federal agencies to patch publicly exploited bugs by: -Nov 17, 2021 (CVE-2021 exploits) -May 3, 2022 (older exploits) https://therecord.media/... https://twitter.com/... Kevin Beaumont / @gossithedog : This is the right thing to do... and also a B-I-G ask for those who have managed security departments. https://twitter.com/...
BIG step forward today in protecting Federal Civilian Networks—Binding Operational Directive (BOD) 22-01 establishes timeframes for mitigation of known exploited vulnerabilities and requires improvements in vulnerability management programs: https://www.cisa.gov/... https://twitt…
New: CISA orders all federal agencies to rapidly patch hundreds of known vulnerabilities. https://cyber.dhs.gov/... Agencies have two weeks to patch flaws discovered before 2021, and six months for flaws discovered this year. Here's the catalog of vulns: https://www.cisa.gov/... …
❗️ Today we issued Binding Operational Directive 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities: https://www.cisa.gov/... This establishes priorities for vulnerability management & will help improve Federal Agency vulnerability management practices. https…
Here @splunk we are often asked “what should we focus on for defenses” here is a great list from @CISAgov of places to start. #SURGe wanted to help so worked with our #STRT breathren. CVE tags are now part of our security content. Read our blog here: https://splunk.com/... https:…
Vulnerability management is a passion of mine. I'm so glad that @splunk got to work with JCDC on helping get this message out. CVE tags are now part of our security content. Read more here: https://www.splunk.com/... https://twitter.com/...
Splunk's Threat Research Team (STRT) and #SURGe have worked together to amplify @CISAgov's Known Exploited Vulnerability Catalog with added functionality in @Splunk Enterprise Security Content Updates (ESCU). Read more here: https://www.splunk.com/... https://twitter.com/...
CISA Director Jen Easterly on today's cyber directive: “For the first time, we've given timelines to remediate those specific vulnerabilities that we know have been actively exploited by adversaries... the ones we think are most dangerous.” https://www.cisa.gov/... https://twitte…
Bold and welcome action by @CISAJen and the crew at @CISAgov with an escalation in patching requirements by way of https://cyber.dhs.gov/.... If a patch is available and the vulnerability is being exploited in the wild, every agency now has a 2 week timeline to complete patching.
CISA should release tools that help with compliance. Like is there a version of metasploit or canvas or core impact or something that has all of these vulnerabilities in it? https://twitter.com/...
Sorry, I tweeted the deadlines backwards. It's two weeks for flaws discovered in 2021 and six months for flaws discovered earlier. https://twitter.com/...
The BOD is for federal agencies, however, @CISAgov also created a catalog of the most common CVE's to help all organizations take action against known exploited vulnerabilities: https://cisa.gov/... #CVE https://twitter.com/...
🚨BOD alert! @CISAgov has issued a binding operational directive requiring Federal agencies to patch vulnerabilities that bad actors have exploited in the wild. Check out the list and patch your systems! https://www.cisa.gov/...
CISA launched today a catalog of known exploited vulnerabilities It also issued a binding operational directive ordering US federal agencies to patch publicly exploited bugs by: -Nov 17, 2021 (CVE-2021 exploits) -May 3, 2022 (older exploits) https://therecord.media/... https://tw…