{"id":2961,"date":"2023-05-23T00:30:40","date_gmt":"2023-05-23T00:30:40","guid":{"rendered":"https:\/\/krsp.co\/agency\/?p=2961"},"modified":"2023-05-23T00:30:40","modified_gmt":"2023-05-23T00:30:40","slug":"cisa-issued-a-directive-instructing-government-agencies-to-patch-for-iphone-vulnerabilities","status":"publish","type":"post","link":"https:\/\/krsp.co\/agency\/2023\/05\/cisa-issued-a-directive-instructing-government-agencies-to-patch-for-iphone-vulnerabilities\/","title":{"rendered":"CISA issued a directive instructing government agencies to patch for iPhone vulnerabilities"},"content":{"rendered":"\n<p>Today, the U.S. Cybersecurity &amp; Infrastructure Security Agency (CISA) took decisive action by issuing an order to federal agencies, mandating the resolution of three recently patched zero-day vulnerabilities. These vulnerabilities have been observed to impact iPhones, Macs, and iPads, making them susceptible to exploitation in malicious attacks. The specific vulnerabilities in question are identified as CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373, all of which are associated with the WebKit browser engine.<\/p>\n\n\n\n<p>While Apple has not provided comprehensive details regarding the specific attacks in which these bugs have been exploited, it has disclosed that CVE-2023-32409 was reported by Cl\u00e9ment Lecigne from Google&#8217;s Threat Analysis Group and Donncha \u00d3 Cearbhaill from Amnesty International&#8217;s Security Lab. These two notable researchers, along with their respective organizations, have been actively involved in sharing crucial information pertaining to state-sponsored campaigns that exploit zero-day vulnerabilities. The primary objective of these campaigns is to surreptitiously install surveillance spyware on the devices of targeted individuals, which includes politicians, journalists, dissidents, and other high-profile figures who find themselves at the center of highly-targeted attacks.<\/p>\n\n\n\n<p>Source: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-govt-agencies-to-patch-iphone-bugs-exploited-in-attacks\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-govt-agencies-to-patch-iphone-bugs-exploited-in-attacks\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, the U.S. Cybersecurity &#038; Infrastructure Security Agency (CISA) took decisive action by issuing an order to federal agencies, mandating the resolution of three recently patched zero-day vulnerabilities.<\/p>\n","protected":false},"author":2,"featured_media":2977,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[27],"class_list":["post-2961","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/posts\/2961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/comments?post=2961"}],"version-history":[{"count":2,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/posts\/2961\/revisions"}],"predecessor-version":[{"id":2978,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/posts\/2961\/revisions\/2978"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/media\/2977"}],"wp:attachment":[{"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/media?parent=2961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/categories?post=2961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/krsp.co\/agency\/wp-json\/wp\/v2\/tags?post=2961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}