The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed three new vulnerabilities are being actively exploited by attackers. Any business using the affected software should treat these as urgent.
- What it is: CISA has added three software flaws to its Known Exploited Vulnerabilities list — meaning real-world attacks are already happening, not just theoretical risks.
- Daemon Tools Lite (disc image software): Malicious code embedded in this utility can allow attackers to run harmful programs on affected computers. If your business uses Daemon Tools Lite, remove or update it immediately.
- TanStack Query (React Query library): A flaw in this web development tool is being exploited. Businesses with custom web applications built on this framework should ask their developer or IT provider to check and update dependencies.
- Nx Console (developer tool): A known flaw in this development environment tool is under active exploitation. Development teams should apply updates without delay.
- Who is affected: Any business or developer using these three tools. If you are unsure whether your systems include them, ask your IT provider.
- What to do: Remove or update the affected software. If you use managed IT support, your provider should be reviewing your environment against this list.
We recommend checking with your IT provider if any of these tools are in use in your environment. Source: CISA Known Exploited Vulnerabilities Catalog