#CISA
115 stories taggedCISA.

ShinyHunters Claims FBI Hack Exploiting Oracle Flaw
The cybercrime group says it breached FBI systems using a critical Oracle software vulnerability. The FBI is investigating the claim.

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators
A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

Botslab G980H Dashcams Ship With 13 Unpatched Flaws and the Vendor Has Gone Quiet
CISA lists authentication and session bugs in a popular Chinese dashcam line. The company hasn't responded.

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints
A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

CISA Wants You to Leave a Trap Out for Hackers
America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

CISA Is Scrapping Its Weekly Vulnerability Bulletin
The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws
The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

Mars Security Launches Tool That Turns Threat Advisories Into Live Detection Rules in Minutes
A new platform feature promises to close the gap between a published hacking report and an actual working defence, automatically tested against a company's own historical data before anyone clicks deploy.

Securing Siemens PLCs Without Shutting Down the Factory
US agencies are warning that industrial controllers running critical infrastructure are being actively targeted. The advice is sound. Applying it carelessly could cause the very outages attackers are hoping for.

US Agencies Say Chinese AI Firms Are Stealing From American Models at Industrial Scale
A joint NSA, CISA and FBI advisory names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as running organised campaigns to copy the inner workings of Claude, GPT, Gemini and Grok.

Hackers Are Exploiting a Fortinet Flaw to Plant Remote-Control Malware on Network Devices
A security bug in Fortinet's firewall and switch software is being used to silently take over devices and steal data. More than 178 machines are already infected, attacks have been running since at least July 2026, and the US government is telling federal agencies they have three days to patch.

CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

CISA flags five actively exploited flaws in Artifactory, ScreenConnect and MikroTik gear
The U.S. cyber agency says criminals are already breaking into systems through bugs in three widely used products, and federal agencies must patch fast.

NIST and CISA tell agencies how to stop attackers walking in on stolen login tokens
The joint report tells federal agencies and cloud providers how to lock down the digital passes that keep users signed in across cloud services.