CISA

CISA’s logging guidance works beyond government

CISA’s logging guidance works beyond government 2026-08-24 at 13:56 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture […]

CISA’s logging guidance works beyond government Read More »

US agencies warn of AI-powered attacks on Siemens industrial controllers

US agencies warn of AI-powered attacks on Siemens industrial controllers 2026-08-20 at 12:07 By Sinisa Markovic Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industrial computers

US agencies warn of AI-powered attacks on Siemens industrial controllers Read More »

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 2026-08-19 at 13:37 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Read More »

Medusa ransomware gang has hit over 500 organizations, CISA warns

Medusa ransomware gang has hit over 500 organizations, CISA warns 2026-08-19 at 13:18 By Sinisa Markovic Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory

Medusa ransomware gang has hit over 500 organizations, CISA warns Read More »

US fuel gauge exposure fell by more than half in three months

US fuel gauge exposure fell by more than half in three months 2026-08-07 at 08:00 By Anamarija Pogorelec Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May,

US fuel gauge exposure fell by more than half in three months Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

CISA lays out new guidance for using open-source software

CISA lays out new guidance for using open-source software 2026-08-03 at 14:53 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open

CISA lays out new guidance for using open-source software Read More »

CISA sets a new SBOM baseline

CISA sets a new SBOM baseline 2026-07-30 at 15:23 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). An SBOM is a

CISA sets a new SBOM baseline Read More »

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) 2026-07-30 at 13:44 By Zeljka Zorz A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) Read More »

Coordinated cyberattack hits more than 30 Minnesota water utilities

Coordinated cyberattack hits more than 30 Minnesota water utilities 2026-07-30 at 11:59 By Sinisa Markovic A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in

Coordinated cyberattack hits more than 30 Minnesota water utilities Read More »

200 new CVEs a day and no realistic way to patch them all

200 new CVEs a day and no realistic way to patch them all 2026-07-30 at 09:00 By Mirko Zorz Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability

200 new CVEs a day and no realistic way to patch them all Read More »

Russian hackers exploit unpatched Zimbra servers to steal emails

Russian hackers exploit unpatched Zimbra servers to steal emails 2026-07-24 at 15:09 By Sinisa Markovic Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and

Russian hackers exploit unpatched Zimbra servers to steal emails Read More »

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 2026-07-23 at 13:42 By Zeljka Zorz Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) Read More »

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance 2026-07-16 at 16:23 By Zeljka Zorz On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance Read More »

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities 2026-07-15 at 17:07 By Ionut Arghire Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Read More »

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) 2026-07-08 at 17:03 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two weeks after

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) Read More »

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws 2026-07-08 at 13:45 By Ionut Arghire Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA’s Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion,

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

JSP webshells being dropped on unpatched PTC Windchill instances

JSP webshells being dropped on unpatched PTC Windchill instances 2026-06-29 at 19:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links

JSP webshells being dropped on unpatched PTC Windchill instances Read More »

Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)

Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) 2026-06-19 at 13:50 By Zeljka Zorz CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by the vendor

Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) Read More »

Scroll to Top