CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4294

As cited

Copy frozen at (site build).

vulnerabilities

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers identified a long-running campaign by North Korean hackers targeting the job application process and disclosed the vulnerability to Microsoft. CISA has directed federal agencies to patch the bug within two weeks.

Why it matters: Federal agencies and organizations using the affected Microsoft product face active exploitation by a nation-state actor and must prioritize patching to prevent credential theft and system compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers identified a long-running campaign by North Korean hackers targeting the job application process and disclosed the vulnerability to Microsoft. CISA has directed federal agencies to patch the bug within two weeks.

Why it matters: Federal agencies and organizations using the affected Microsoft product face active exploitation by a nation-state actor and must prioritize patching to prevent credential theft and system compromise.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary