New CISA guidance seeks to standardize federal agencies' cyber defenses
Under the FOCAL plan, federal agencies have been urged to prioritize asset management, vulnerability management, defensible architecture, cyber supply chain risk management, and incident detection and response, as well as adhere to alignment goals...
Updated CISA exploited vulnerabilities catalog adds several flaws
Most recent of the newly added vulnerabilities is a critical remote command execution issue in Apache HugeGraph-Server, tracked as CVE-2024-27348, which could be leveraged to facilitate sandbox restriction evasion.