CISA

FBI disrupts Flax Typhoon hacking tools used in global cyberattacks

FBI disrupts Flax Typhoon hacking tools used in global cyberattacks 2026-10-09 at 12:44 By Sinisa Markovic The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad. Seizure […]

FBI disrupts Flax Typhoon hacking tools used in global cyberattacks Read More »

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) 2026-10-05 at 17:53 By Zeljka Zorz CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways. “Citrix has observed targeted attacks on unmitigated NetScaler deployments which […]

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) Read More »

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) 2026-09-28 at 12:51 By Zeljka Zorz Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped […]

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) Read More »

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks 2026-09-25 at 15:39 By Eduard Kovacs Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.  The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks Read More »

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators 2026-09-24 at 14:05 By Eduard Kovacs Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek. This article is […]

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators Read More »

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances 2026-09-23 at 13:22 By Zeljka Zorz Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code […]

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances Read More »

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot 2026-09-17 at 17:28 By Eduard Kovacs The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Read More »

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys 2026-09-17 at 15:51 By Zeljka Zorz Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and […]

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys Read More »

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses 2026-09-17 at 10:53 By Ionut Arghire Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek. This article is an excerpt from […]

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses Read More »

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA finalize playbook to stop token theft and forgery 2026-09-16 at 10:40 By Anamarija Pogorelec NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR […]

NIST and CISA finalize playbook to stop token theft and forgery Read More »

Chinese AI firms are siphoning capabilities from American models, CISA warns

Chinese AI firms are siphoning capabilities from American models, CISA warns 2026-09-09 at 12:55 By Anamarija Pogorelec China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that […]

Chinese AI firms are siphoning capabilities from American models, CISA warns Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of […]

CISA review makes the case for eliminating vulnerability classes Read More »

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks 2026-08-26 at 14:29 By Eduard Kovacs The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek. This article is an excerpt […]

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

CISA’s logging guidance works beyond government

CISA’s logging guidance works beyond government 2026-08-24 at 13:56 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture […]

CISA’s logging guidance works beyond government Read More »

US agencies warn of AI-powered attacks on Siemens industrial controllers

US agencies warn of AI-powered attacks on Siemens industrial controllers 2026-08-20 at 12:07 By Sinisa Markovic Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industrial computers […]

US agencies warn of AI-powered attacks on Siemens industrial controllers Read More »

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 2026-08-19 at 13:37 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Read More »

Medusa ransomware gang has hit over 500 organizations, CISA warns

Medusa ransomware gang has hit over 500 organizations, CISA warns 2026-08-19 at 13:18 By Sinisa Markovic Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory […]

Medusa ransomware gang has hit over 500 organizations, CISA warns Read More »

US fuel gauge exposure fell by more than half in three months

US fuel gauge exposure fell by more than half in three months 2026-08-07 at 08:00 By Anamarija Pogorelec Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, […]

US fuel gauge exposure fell by more than half in three months Read More »

Scroll to Top