Joint Cyber Alert Urges Organizations to Patch Known Vulnerabilities

Robinson+Cole Data Privacy + Security Insider
Contact

As we have pointed out before, it is cumbersome yet critical, to patch vulnerabilities on a timely basis. Cyber-attackers move swiftly to take advantage of known vulnerabilities and are aware of the challenges organizations have in closing those doors.

The Cybersecurity and Infrastructure Security Agency (CISA), along with its counterparts in other countries, issued a Joint Cybersecurity Advisory on April 27, 2022, outlining the most “routinely exploited vulnerabilities” in 2021, and urging companies to review those vulnerabilities and take action to patch them as soon as possible.

Key findings in the Alert include:

Globally, in 2021, malicious cyber actors targeted internet-facing systems, such as email servers and virtual private network (VPN) servers, with exploits of newly disclosed vulnerabilities. For most of the top exploited vulnerabilities, researchers or other actors released proof of concept (POC) code within two weeks of the vulnerability’s disclosure, likely facilitating exploitation by a broader range of malicious actors.

The Alert cautions organizations about how malicious actors continue to use older vulnerabilities, which “demonstrates the continued risk to organizations that fail to patch software in a timely manner or are using software that is no longer supported by a vendor.”

The Alert provides organizations with a list of the top 15 routinely exploited vulnerabilities in 2021 and mitigation guidance to address the continued risk the vulnerabilities pose.

It is worth taking the time to review the details of the vulnerabilities and confirm that appropriate mitigation steps have been taken. This is free information designed to assist organizations with their cybersecurity posture and is not a heavy lift to potentially dramatically reduce a known risk.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide