CISA Adds Actively Exploited KNX Protocol Flaw to KEV Catalog
A critical account lockout vulnerability in KNX Association products is now under active exploitation, requiring immediate remediation by federal agencies.
CISA has added CVE-2023-4346, an overly restrictive account lockout vulnerability within the KNX Association KNX Protocol Connection Authorization Option 1, to its Known Exploited Vulnerabilities catalog. This flaw allows an attacker to purge all devices lacking additional security configurations and set a Bus Coupling Unit (BCU) key to lock the affected hardware.
The vulnerability, classified under CWE-645, is confirmed to be under active, real-world exploitation. Federal agencies are required to apply vendor-provided mitigations by July 29, 2026, in accordance with BOD 26-04. Stakeholders must evaluate the internet exposure of their assets and ensure compliance with CISA's forensic triage and patching requirements.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.