Skip to content

20250313001-Fake-CAPTCHA-Prompts-Installing-InfoStealer-Malware #1258

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 25 commits into from
Closed
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
767c05e
20250206001-CISA-Adds-One-Known-Exploited-Vulnerability
TWangmo Feb 6, 2025
215117c
Format markdown docs
TWangmo Feb 6, 2025
e62db0b
Merge branch 'wagov:main' into main
TWangmo Feb 10, 2025
f85cfae
Annual Implementation Report 1
TWangmo Feb 11, 2025
e7f2650
Merge branch 'wagov:main' into main
TWangmo Feb 13, 2025
ef1566a
20250213002-Google-Chrome-Multiple-Vulnerability-Updates
TWangmo Feb 13, 2025
7cf5ff0
Format markdown docs
TWangmo Feb 13, 2025
655f804
20250213002-Google-Chrome-Multiple-Vulnerability-Updates
TWangmo Feb 13, 2025
5f3bd0f
Format markdown docs
TWangmo Feb 13, 2025
e356889
Update annual-implementation-reporting.md
DamoOne Feb 13, 2025
023f434
Merge branch 'wagov:main' into main
TWangmo Feb 14, 2025
8e36798
20250214001-CISA-New-ICS-Advisories
TWangmo Feb 14, 2025
feec382
Merge branch 'wagov:main' into main
TWangmo Feb 21, 2025
e6785d8
20250221001-CISA-Releases-New-ICS-Advisories
TWangmo Feb 21, 2025
071ccae
Format markdown docs
TWangmo Feb 21, 2025
12753cb
Merge branch 'wagov:main' into main
TWangmo Mar 7, 2025
0cb8a56
Merge branch 'wagov:main' into main
TWangmo Mar 13, 2025
9e765f6
20250313001-Fake-CAPTCHA-Prompts-Installing-InfoStealer-Malware
TWangmo Mar 13, 2025
e9c8643
Format markdown docs
TWangmo Mar 13, 2025
8fb7ff1
20250313001-Fake-CAPTCHA-Prompts-Installing-InfoStealer-Malware
TWangmo Mar 13, 2025
05c36ee
Format markdown docs
TWangmo Mar 13, 2025
b36bf27
20250313001-Fake-CAPTCHA-Prompts-Installing-InfoStealer-Malware
TWangmo Mar 13, 2025
1f93439
Format markdown docs
TWangmo Mar 13, 2025
2093b31
Delete docs/advisories/20250313001-Fake-CAPTCHA-Prompts-Installing-In…
TWangmo Mar 13, 2025
7c7444d
Merge branch 'wagov:main' into main
TWangmo Apr 3, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# Adobe and Oracle Known Exploited Vulnerabilities - 20250225001

## Overview

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | ---- | ------------ |
| Adobe ColdFusion | <br/> - ColdFusion 2016 Update 3 and earlier <br/> - ColdFusion 11 update 11 and earlier <br/> -ColdFusion 10 Update 22 and earlier | [CVE-2017-3066](https://nvd.nist.gov/vuln/detail/CVE-2017-3066) | 9.8 | **Critical** |

## What has been observed?

CISA added this vulnerability in their [Known Exploited Vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) catalog. There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):

## Additional References

- CISA: <https://www.cisa.gov/news-events/alerts/2025/02/24/cisa-adds-two-known-exploited-vulnerabilities-catalog>