Number: AL24-006
Date: April 24, 2024
Audience
This Alert is intended for IT professionals and managers of notified organizations.
Purpose
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.
Details
On April 24, 2024, the Canadian Centre for Cyber Security (Cyber Centre), Australian Signals Directorate's Australian Cyber Security Centre and The UK's National Cyber Security Centre (NCSC) released a joint Cyber Security AdvisoryFootnote 1 to bring awareness of newly published information by Cisco on the vulnerabilities exploited in recent incidents worldwide.
On the same day, Cisco Talos published a blog postFootnote 2 containing the latest technical details of these vulnerabilities affecting Cisco ASA devices, as well as information on two additional newly discovered vulnerabilities (CVE-2024-20353Footnote 3 and CVE-2024-20359Footnote 4) leveraged during these incidents.
Please refer to these documents for additional details and recommendations.