A vulnerability in Samsung Galaxy S24 devices, identified as CVE-2024-49421, allows network-adjacent attackers to create arbitrary files via the Quick Share feature due to improper path validation. With a CVSS score of 5.9, the flaw requires attackers to be in close proximity to the target. Samsung has issued a patch as of December 2024, urging users to update.

CISA extends CVE program contract for 11 months
The Department of Homeland Security has extended funding for the CVE Program, vital for cybersecurity and managed by MITRE. This program helps organizations manage vulnerabilities