#CISA
114 stories taggedCISA · page 2 of 8.

CISA Tells Defenders to Plant Fake Systems and Wait
New federal guidance walks security teams through using decoys, tripwires and fake credentials to spot attackers who look like legitimate users.

New US Government Token Security Guide Leaves AI Agents in a Grey Zone
NIST and CISA have published fresh guidance on protecting the digital passes that systems use to grant access. It is solid work, but it sidesteps the hardest problem: nobody yet agrees how much to trust an AI agent holding a perfectly valid pass.

Google Patches Fifth Chrome Zero-Day of 2022 as Attacks Continue
A flaw in how Chrome handles Android deep links is being actively exploited. It's the fifth Chrome vulnerability criminals have used in the wild this year, and the patch window is tight.

OPC Foundation patches installer flaw that let a bystander hijack setup on industrial servers
A medium-severity bug in the OPC UA Local Discovery Server installer briefly exposes a high-privilege console anyone at the keyboard could grab.

CISA and G7 Sound the Alarm on Quantum Computing's Threat to Encryption
A joint call to action urges governments and businesses to start swapping out today's cryptography before quantum computers make it useless.

CISA flags seven actively exploited flaws, including two in SonicWall SMA1000 boxes
The US cyber agency's Known Exploited Vulnerabilities catalog picks up bugs in Sangoma, JFrog, LiteLLM, Kestra, Starlette and a pair in SonicWall's remote access appliances.

CISA Tells Critical Infrastructure Operators to Plan How They'll Talk When the Systems Go Dark
New joint guidance from CISA, the FBI and international partners spells out what utilities and hospitals should say to the public during a major IT or industrial outage, and how to say it before rumours fill the gap.

CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight
The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw
The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers
A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

CISA: Most Breaches Still Start With Old, Unpatched Bugs
A new review from the US cyber agency finds attackers rarely need clever tricks. They scan for known, exposed flaws that companies never got around to fixing.

More Than 100 Water Systems Were Hit by Hackers in July. Here's What CISA Found.
U.S. cybersecurity officials have put a number on the recent wave of attacks on drinking water and wastewater facilities: over 100 internet-connected systems targeted in a single month, most of them left exposed by a simple modem.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

The Industrial Timing Protocol That Could Let Hackers Stop a Robotic Arm Mid-Grip
Researchers found that a family of protocols keeping factory machines in sync has a fundamental weakness. Exploiting it, they could start and stop robots, mess with factory clocks, and touch every device on the network.

Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other
CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.