Skip to content

Commit

Permalink
20250128 001, 002 + template updates
Browse files Browse the repository at this point in the history
  • Loading branch information
JadonWill authored Jan 28, 2025
1 parent c71edac commit 3d4feb4
Show file tree
Hide file tree
Showing 6 changed files with 50 additions and 4 deletions.
26 changes: 26 additions & 0 deletions docs/advisories/20250128001-Apple-Known-Exploited-Vulnerability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Apple Patches Known Exploited Vulnerability - 20250128001

## Overview

VENDOR have released a critical security advisory relating to a vulnerability impacting PRODUCTS.

## What is vulnerable?

| Product(s) Affected | CVE | CVSS | Severity |
| ------------------- | --- | ---- | -------- |
| iOS < 18.3 <br> iPadOS < 18.3 <br> macOS Sequoia < 15.3 | [CVE-2025-24085](https://nvd.nist.gov/vuln/detail/CVE-2025-24085) | TBD | TBD |

## What has been observed?

Apple is aware of exploitation in the wild.
There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 Hours...* (refer [Patch Management](../guidelines/patch-management.md)):

- Apple Security Releases: <https://support.apple.com/en-us/100100>

### Additional Resources

- SecurityOnline: <https://securityonline.info/cve-2025-24085-apple-patches-actively-exploited-zero-day-vulnerability/>
20 changes: 20 additions & 0 deletions docs/advisories/20250128002-CISA-New-ICS-Advisories.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# CISA Releases New ICS Advisories - 20250128002

## Overview

CISA has released multiple advisories for Industrial Control Systems (ICS) related vendors.

## What is vulnerable?

| Vendor |
| ------- |
| mySCADA |
| Hitachi Energy |
| Schneider Electric |
| HMS Networks |

## Recommendation

The WA SOC recommends administrators review relevant advisories and apply the recommended actions to all affected devices.

- CISA: <https://www.cisa.gov/news-events/alerts/2025/01/23/cisa-releases-six-industrial-control-systems-advisories>
2 changes: 1 addition & 1 deletion docs/markdown-templates/Advisory-vulnerability.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Advisory Title - 2024MMDD001
# Advisory Title - 2025MMDD001

## Overview

Expand Down
2 changes: 1 addition & 1 deletion docs/markdown-templates/advisory-CISA-ICS-Advisories.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# CISA Releases New ICS Advisories - 2024MMDD001
# CISA Releases New ICS Advisories - 2025MMDD001

## Overview

Expand Down
2 changes: 1 addition & 1 deletion docs/markdown-templates/advisory-KnownExploited.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# (Vulnerability) added to CISA Known Exploited Catalog - 2024MMDD00\#
# (Vulnerability) added to CISA Known Exploited Catalog - 2025MMDD00\#

## Overview

Expand Down
2 changes: 1 addition & 1 deletion docs/markdown-templates/advisory-threat-detection.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# ADVISORY TITLE - 2024MMDD001
# ADVISORY TITLE - 2025MMDD001

## Overview

Expand Down

0 comments on commit 3d4feb4

Please sign in to comment.