banner Expire 1 July 2024
Ad Ends 13 July 2024
banner Expire 15 July 2024
banner Expire 18 October 2024
ad End 18 October 2024
Ad Ends 13 July 2023
banner Expire 20 July 2024
What's new
Ad expire at 5 June 2024
UniCvv
CrdCrew.cc Carding forum
Western union transfer
Kfc CLub
Carding.pw carding forum
adv exp at 23 August 2024

ESCO

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,315
Reaction score
711
Points
212
Awards
2
  • Somebody Likes you
  • First post



In recent years, we have seen how hackers prey on those too lazy or ignorant to install security patches, which, if applied on time, would have prevented some devastating cyber attacks and data breaches that happened in major organisations.

The United States Department of Homeland Security (DHS) has ordered government agencies to more swiftly plug the critical security vulnerabilities found on their networks within 15 calendar days since the initial detection, a reduction from 30 days.

DHS's Cybersecurity and Infrastructure Security Agency (CISA) this week issued a new Binding Operational Directive (BOD) 19-02 instructing federal agencies and departments to address "critical" rated vulnerabilities within 15 days and "high" severity flaws within 30 days of initial detection.

The countdown to patch a security vulnerability will start when it was initially detected during CISA's weekly Cyber Hygiene vulnerability scanning, rather than it was the first report to the affected agencies.
"As federal agencies continue to expand their Internet presence through increased deployment of Internet-accessible systems, and operate interconnected and complex systems, it is more critical than ever for federal agencies to rapidly remediate vulnerabilities that otherwise could allow malicious actors to compromise federal networks through exploitable, externally-facing systems," reads the memo from CISA Director Chris Krebs.
"Recent reports from government and industry partners indicate that the average time between discovery and exploitation of a vulnerability is decreasing as today’s adversaries are more skilled, persistent, and able to exploit known vulnerabilities."
Therefore, to minimize the risk of unauthorized access to any federal information internal system and reduce the overall attack surface, the CISA wants government agencies to review and remediate critical vulnerabilities on Internet-facing systems before hackers and cybercriminals exploit them.

The recently created CISA agency provides regular reports to the federal agencies on Cyber Hygiene scanning results and current status, informing them of the detected vulnerabilities, classified based on their CVSSv2 score.

Agencies who do not complete their remediation within the allotted time period, CISA will send an additional reminder to agencies, asking them to submit the complete remediation plan within three working days to CISA.
BOD 19-02 replaces BOD 15-01—Critical Vulnerability Mitigation Requirement for Federal Civilian Executive Branch Departments and Agencies' Internet-Accessible Systems (May 21, 2015)—which gave federal agencies 30 days to patch critical vulnerabilities.
 
Ad End 1 July 2024
Top