2day.site

Wednesday, December 24

CISA KEV: Sierra Wireless RCE Flaw

Critical

CISA added CVE-2018-4063, an actively exploited RCE vulnerability in Sierra Wireless routers, to the Known Exploited Vulnerabilities catalog.

Action: Patch affected Sierra Wireless AirLink ALEOS routers immediately.
Source ↗

Apple Patches Two Exploited Zero-Days

Critical

Apple released emergency updates for all platforms (iOS, macOS, etc.) to fix two WebKit zero-day flaws being actively exploited in sophisticated attacks.

Action: Apply all available iOS, iPadOS, macOS, and Safari security updates now.
Source ↗

Fake GitHub Repos Spread PyStoreRAT

High

A new campaign uses seemingly benign OSINT or GPT utility GitHub repositories to silently deliver the PyStoreRAT JavaScript-based Remote Access Trojan.

Action: Audit developer environments and exercise extreme caution when cloning unknown Python/OSINT GitHub repos.
Source ↗