The CISA fact sheet discusses the challenges in software security and provides recommendations to enhance the security and risk management of using open source software (OSS). It aims to improve the overall security posture of organizations dealing with OSS.
CISA Adds Apache, Microsoft Bugs to Know Exploited Vulnerabilities Database
The U.S. CISA updated its Known Exploited Vulnerabilities (KEV) Catalog, highlighting several critical vulnerabilities including Apache OFBiz (CVE-2024-45195), Microsoft .NET Framework (CVE-2024-29059), and Paessler PRTG