• So what’s being exploited?

    Ever wonder what’s REALLY being exploited? The government publishes a web site that lists known exploited vulnerabilities.  I like to keep an eye on it to see what’s really being exploited.

    Case in point, Firefox has a vulnerability being exploited in the wild, CVE-2024-9680 that impacts Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.  Specifically it impacts the animation-timeline CSS property specifies the timeline that is used to control the progress of a CSS animation. Bottom line it’s a component used on a web site that attackers are targeting to gain access or as they put it in the bug “code execution”.

    While I’m not ready to change the DefCon for the operating system patches, on browser updates I always recommend you install them as soon as you can. I ensure that several browsers are installed on every machine – even Mac computers – to ensure that should the odd bug or issue get introduced, I can use a different browser.  I’ll be digging into more of these Exploited bugs in future newsletters and why you should pay attention to some of them.   More in future newsletters…. in the meantime, ensure you keep your browsers up to date.