US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three new security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that hackers are actively using them in real-world attacks. The affected products include ownCloud (a file-sharing platform), the Linux kernel, and JFrog Artifactory (a software package management tool).
While the KEV Catalog is primarily designed to guide US federal agencies on which vulnerabilities to patch first, it's a valuable resource for any business worldwide. Vulnerabilities on this list aren't theoretical risks — they are actively being exploited by cybercriminals right now, making them a priority for any organisation using the affected software.
If your business uses ownCloud for file sharing, runs Linux-based servers, or relies on JFrog Artifactory for managing software packages, it's important to check with your IT provider or software vendor whether you're running a vulnerable version and apply the necessary security updates as soon as possible.