Security News > 2023 > March > CISA orders agencies to patch bugs exploited to drop spyware
The Cybersecurity and Infrastructure Security Agency has ordered federal agencies today to patch security vulnerabilities exploited as zero-days in recent attacks to install commercial spyware on mobile devices.
One month later, a complex chain of multiple 0-days and n-days was exploited to target Samsung Android phones running up-to-date Samsung Internet Browser versions.
The cybersecurity agency gave Federal Civilian Executive Branch Agencies agencies three weeks, until April 20, to patch vulnerable mobile devices against potential attacks that would target these five security flaws.
According to the BOD 22-01 binding operational directive issued in November 2021, FCEB agencies must secure their networks against all bugs added to CISA's list of vulnerabilities known to be exploited in attacks.
While the BOD 22-01 directive only applies to FCEB agencies, CISA strongly urged today all organizations to prioritize packing these bugs to thwart exploitation attempts.
"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned.