The US Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management to its Known Exploited Vulnerabilities catalog. Evidence of active exploitation prompted the addition. Although patches for these vulnerabilities exist, there are currently no public reports about their exploitation.

Researchers Bypassed CrowdStrike Falcon Sensor to Execute Malicious Applications
SEC Consult identified a serious vulnerability in CrowdStrike’s Falcon Sensor, named “Sleeping Beauty,” which allows attackers to bypass detection by suspending EDR processes instead of