MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #7

CISA adds five exploited server flaws to must-patch list

Original: 🔴 EXPLOITED CISA added five old self-hosted server bugs to its must-patch list: BIND, ProFTPD, Struts, ONLYOFFICE, Strap

CISA has added five actively exploited vulnerabilities in widely used self-hosted server software to its Known Exploited Vulnerabilities catalog: BIND, ProFTPD, Apache Struts, ONLYOFFICE and Strapi. Some of the flaws date back to 2015, and China-linked scanning activity is reported to be hitting them at scale. US federal agencies must apply fixes by October 11. Security practitioners are urging self-hosters to patch quickly.

Why now: Actively exploited, long-known server flaws being targeted at scale by China-linked actors make urgent patching a pressing concern for administrators.

CISABINDProFTPDApache StrutsONLYOFFICE

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1592357