Tag

#CISA

98 stories taggedCISA.

AI analyzing network data
Policy & Regulation

Your security team's growing backlog is not their fault

When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

4 min read
Full-frame close-up photograph of an industrial smart plug device mounted on a metal DIN rail inside a factory electrical cabinet, cool blue LED status light gl
Vulnerabilities

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine

A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

3 min read
Full-frame edge-to-edge 16:9 photoreal editorial image of a dimly lit enterprise server room with rack-mounted servers glowing amber, a single open maintenance
Vulnerabilities

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a small metallic cryptocurrency hardware wallet plugged into a laptop USB port on a dark wooden desk, faint
Threat Intelligence

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies

Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

4 min read
Full-frame edge-to-edge photoreal close-up of a server rack interior glowing with cool blue indicator LEDs, fiber cables in soft bokeh, a subtle red warning glo
Vulnerabilities

August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment

A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

4 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

Ransomware crews are now breaking into SharePoint servers through a May flaw

CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

4 min read
A close-up, editorial-style photograph of a illuminated server room corridor at night, shot in 16:9 framing
Ransomware

US and Korean agencies warn about Gunra, a fast-growing ransomware gang built from leaked Conti code

The FBI, CISA and Korea's National Police Agency say Gunra has hit hospitals, utilities, banks and manufacturers across five continents since April 2025.

4 min read
Aerial 16:9 view of a vast server room with long rows of illuminated blue and amber rack lights stretching to a vanishing point, emergency backup lighting casti
Threat Intelligence

Iranian Hackers Hit Water Systems in at Least 12 US States

New Jersey and Alabama are the latest to confirm attacks on water infrastructure. So far, no taps have run dry and no water has been contaminated, but the campaign is still expanding.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dark server rack in a data centre with a single amber warning light glowing on one rack unit, cool b
Vulnerabilities

Researchers Find Five Flaws in the Radio System Pilots and Air Traffic Controllers Use to Text Each Other

CISA has published five CVEs against CPDLC, the digital messaging link between cockpits and control towers. There are no fixes, but exploitation needs lab-grade conditions.

3 min read
Full-frame photoreal editorial image of a dimly lit corporate server room with rows of blue-lit racks, a soft red warning glow pulsing from one rack indicating
Vulnerabilities

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020

Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

4 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity

A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

3 min read
A dimly lit server room with rows of rack-mounted hardware, status indicator lights blinking amber and red in rhythmic patterns, cool blue ambient light casting
Vulnerabilities

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack

Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

4 min read
Aerial 16:9 editorial photograph of a multi-lane American interstate highway at dusk, large digital message signs mounted on overhead gantries displaying amber
Vulnerabilities

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List

A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

3 min read
Aerial 16:9 photograph of a large municipal water treatment facility at dusk, circular sedimentation tanks reflecting fading orange sky, surrounded by industria
Threat Intelligence

The criminals behind the Minnesota water attacks may have a better backup of your plant than you do

Hackers hit more than 30 small water utilities in two days. The most alarming detail isn't how they got in, it's that they may have walked out with the only complete copy of control logic the operators ever had.

4 min read
Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Threat Intelligence

A Decade of Iranian Cyberattacks on America: What We Know

From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

4 min read
© 2026 Threat Vectr