#CISA
98 stories taggedCISA.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine
A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing
A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment
A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

Ransomware crews are now breaking into SharePoint servers through a May flaw
CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

US and Korean agencies warn about Gunra, a fast-growing ransomware gang built from leaked Conti code
The FBI, CISA and Korea's National Police Agency say Gunra has hit hospitals, utilities, banks and manufacturers across five continents since April 2025.

Iranian Hackers Hit Water Systems in at Least 12 US States
New Jersey and Alabama are the latest to confirm attacks on water infrastructure. So far, no taps have run dry and no water has been contaminated, but the campaign is still expanding.

Researchers Find Five Flaws in the Radio System Pilots and Air Traffic Controllers Use to Text Each Other
CISA has published five CVEs against CPDLC, the digital messaging link between cockpits and control towers. There are no fixes, but exploitation needs lab-grade conditions.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack
Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List
A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

The criminals behind the Minnesota water attacks may have a better backup of your plant than you do
Hackers hit more than 30 small water utilities in two days. The most alarming detail isn't how they got in, it's that they may have walked out with the only complete copy of control logic the operators ever had.

A Decade of Iranian Cyberattacks on America: What We Know
From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.