Bottom line: Security leaders must ensure their voting systems are patched and audited to prevent similar exploitation.
What's happening: Researchers from the University of Michigan used AI-powered tools to exploit the vulnerability in Dominion Voting Systems' scanners, which were used in 21 US states, including Georgia, between 2017 and 2019. The vulnerability, identified as CVE-2021-20149, has a CVSS score of 7.8. The researchers also found that the vulnerability was not patched in time, with the fix being deployed in January 2022, four years after the original vulnerability was disclosed.
What to do: Security leaders should review their patch management processes and ensure that all affected systems are updated with the latest patches, and conduct regular audits to detect any potential exploitation.