CISA is changing the way they publizice alerts, including the KEV (known exploited vulnerabilities). These will no longer be shown on the "Alerts" overview, but must be subscribed to via GovAlert (or just scrape the JSON...).

The first vulnerability that is *not* being published as an alert is...drumroll... CVE-2025-47729. "The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL app users"

Isn't that a funny coincidence?

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://chaos.social/users/christopherkunz/statuses/114499214937727671 on your instance and quote it. (Note that quoting is not supported in Mastodon.)