CISA cyber security advisories

The US government Cybersecurity and Infrastructure Security Agency (CISA) is one of my go to places for advice on product vulnerabilities and patching. There were two this week for VMware and Mozilla Firefox.

VMware Releases Security Update for Aria Operations for Networks | CISA

Mozilla Releases Security Updates for Multiple Products | CISA

Known Exploited Vulnerabilities Catalog

CISA also maintains a database of exploits that it knows are being exploited. This week they have posted about an issue with Google Chromium.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

My advice: Either you or your IT support need to check whether these issues impact your systems. You need to have a master document that details your systems, hardware, software, online, networks, back-ups, suppliers etc – so when cyber security (or operational) issues arise you and your support teams can quickly check if you are affected. From there you can take fast, effective action.

CISA also releases industrial control system advisories – if you are responsible for these types of systems you should monitor their news page:

Current Activity | CISA

Clive Catton MSc (Cyber Security) – by-line and other articles