「CISAは自動タンクゲージシステムのセキュリティ強化を要請」: #CISA

「サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)と政府機関は 本日、米国を拠点とする自動タンクゲージ(ATG)システムを標的とするサイバー攻撃者による侵害からATGシステムを保護するための推奨対策をまとめた共同ファクトシートを公表 した。所有者および運用者が実施すべき推奨対策には、強力なパスワードの使用、ATGシステムのインターネット接続の切断、ログの監査および監視などが含まれる。

TGシステムは、エネルギー、化学、食品・農業、輸送システムといった分野で、燃料や液体のレベル、温度、漏洩検知など、貯蔵タンクの各種パラメータを自動かつ遠隔で監視するために広く利用されています。ATGシステムが侵害された場合、サイバー攻撃者は重要な機能を妨害または操作し、漏洩の未検出、環境汚染、物理的損傷のリスクを高める可能性があります。 」

日本ではどうなのですかね?

https://www.cisa.gov/news-events/news/cisa-urges-stronger-security-automatic-tank-gauge-systems

#prattohome

A two-year-old Oracle WebLogic Server flaw (CVE-2024-21182), patched in July 2024, is now actively exploited, prompting a CISA directive for federal agencies to patch by June 4. This 'zombie vulnerability' phenomenon underscores persistent challenges in enterprise patch management, legacy systems, and visibility gaps, leaving critical data exposed.

https://www.tpp.blog/euker5u

#cybersecurity #cisa #oracle

🤖 This post was AI-generated.

CISA Flags Oracle WebLogic Flaw as Actively Exploited

The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged a high-severity Oracle WebLogic flaw, CVE-2024-21182, as actively exploited, prompting federal agencies to apply fixes by June 4, 2026. This critical vulnerability, rated 7.5 by CVSS, was added to CISA's Known Exploited Vulnerabilities Catalog after evidence…

https://osintsights.com/cisa-flags-oracle-weblogic-flaw-as-actively-exploited?utm_source=mastodon&utm_medium=social

#OracleWeblogic #Cve202421182 #Cisa #KnownExploitedVulnerabilities #EmergingThreats

CISA Flags Oracle WebLogic Flaw as Actively Exploited

Learn how CISA flags Oracle WebLogic flaw CVE-2024-21182 as actively exploited and take immediate action to apply fixes by June 4, 2026 to secure your network now.

OSINTSights

CISA has added to the KEV catalogue.

CVE-2025-48595: Android Framework Integer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-48595

CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2022-0492 #CISA #infosec #Linux #Android #vulnerability

Review - CISA Publishes ChemLock Initial 30-day ICR Notice – Would support the basic information collection needs of the voluntary ChemLock program - https://tinyurl.com/54d7nhf8 #ChemLock #CISA #ICR
Review - CISA Publishes ChemLock Initial 30-day ICR Notice

Today, CISA published a 30-day information collection request (ICR) notice in the Federal Register ( 91 FR 32993-32994 ) for a new ICR for t...

U.S. CISA adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog - Security Affairs

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog.

Security Affairs

CISA Warns of Actively Exploited Oracle WebLogic Server Vulnerability

The US Cybersecurity and Infrastructure Security Agency (CISA) is sounding the alarm on a highly exploitable Oracle WebLogic Server vulnerability, CVE-2024-21182, that's being actively targeted by threat actors. Over 1,592 vulnerable servers are currently exposed online, making it a pressing concern for organizations…

https://osintsights.com/cisa-warns-of-actively-exploited-oracle-weblogic-server-vulnerability?utm_source=mastodon&utm_medium=social

#Cve202421182 #OracleWeblogicServer #ExploitedVulnerability #EmergingThreats #Cisa

CISA Warns of Actively Exploited Oracle WebLogic Server Vulnerability

Protect your Oracle WebLogic Server from CVE-2024-21182 exploits. Learn how to patch and prevent attacks with our expert guidance and stay secure now.

OSINTSights

Irgendwie habe ich gerade das Gefühl, dass der Finger auf die Falschen gezeigt wird ...

#CVSS: #NIST schränkt Bewertung von IT-Sicherheitslücken ein | Security https://www.heise.de/news/CVSS-NIST-schraenkt-Bewertung-von-IT-Sicherheitsluecken-ein-11314492.html #CISA

CVSS: NIST schränkt Bewertung von IT-Sicherheitslücken ein

Das US-amerikanische NIST betreibt die Schwachstellendatenbank NVD. Der Rückstau an Analysen ist groß, die Kritik des Rechnungshofes harsch.

heise online