news.mlab.sh
Back to the feed
threat-intel

CISA: Most exploited vulnerabilities should have been eradicated decades ago

Medium
Summary

This article highlights a concerning trend: many vulnerabilities that should have been addressed long ago are still being actively exploited. The Register points to a situation where tech companies are now selling solutions to problems they themselves created, driven by increasing memory constraints and the rising cost of AI processing. The piece also touches on broader security issues, including phishing attacks, ransomware, and vulnerabilities in open-source software.

The Register reports on a persistent problem within the tech industry – that numerous vulnerabilities, many of which should have been patched decades ago, continue to be exploited. This is largely due to the increasing demand for AI processing power, leading to a need for more expensive hardware and driving up costs. Companies like Nvidia and Cerebras are now offering solutions to this problem, but the underlying issue remains: a backlog of outdated security flaws.

Beyond hardware, the article mentions broader security concerns. Russian actors are leveraging the Signal support persona to conduct phishing attacks, and Microsoft is struggling to fully address a zero-day vulnerability in its on-prem SharePoint system. Furthermore, China is upgrading smartphone surveillance tools, and Ring is easing its stance on anti-snooping measures.

The Register also notes the ongoing threat of ransomware, a decade after the first corporate attack, and highlights the success of the DEF CON Franklin project in hardening critical infrastructure. Acronis, a Swiss cybersecurity firm, was acquired by EQT, representing a significant investment in the sector. Finally, the article mentions vulnerabilities in open-source extensions, specifically iCagenda and Balbooa Forms, impacting a large number of websites powered by CMS like Joomla.

Read the full article at The Register