Tag

#CISA

99 stories taggedCISA · page 2 of 7.

Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Threat Intelligence

A Decade of Iranian Cyberattacks on America: What We Know

From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

4 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Vulnerabilities

CISA flags N-able N-central bug as actively exploited, orders federal fix

The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

3 min read
Aerial 16:9 view of a large municipal water treatment facility at dusk, concrete reservoir tanks and pipe infrastructure visible, cool blue and grey tones, over
Threat Intelligence

Iranian hackers suspected in attack on 30 US water systems

A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.

3 min read
Photoreal editorial image of a sleek modern server rack glowing with blue indicator lights, partially connected by old beige Ethernet cables and a vintage patch
Policy & Regulation

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.

A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

4 min read
Full-frame edge-to-edge photoreal image of a federal seizure notice style web page displayed on a dark monitor in a dim server room, faint blue glow from rack L
Policy & Regulation

When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath

Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a rack-mounted network security appliance in a dim data center aisle, status LEDs glowing amber and re
Threat Intelligence

CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet

The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

4 min read
Aerial view of a large industrial fuel storage facility at dusk, rows of cylindrical metal tanks reflecting low amber light, pressure gauges and pipe networks v
Vulnerabilities

NASA's Core Flight System has a flaw that can crash spacecraft software

A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

4 min read
Photoreal news-editorial image of a darkened enterprise server rack with one rack unit displaying a red status LED, others showing amber and green, shallow dept
Vulnerabilities

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack

A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

3 min read
A long polished conference table in a modern governmental chamber, empty high-backed chairs arranged formally on both sides, soft overhead lighting casting clea
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
AI analyzing network data
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
a government building with digital security overlay, emphasizing cybersecurity
Policy & Regulation

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.

A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

5 min read
An industrial control room with AI dashboards and outdated equipment
Policy & Regulation

US and Australian agencies publish playbook for cutting critical systems off in a crisis

New joint guidance tells power, water and transport operators how to run in isolation when a cyberattack or geopolitical crisis forces the plug to be pulled.

4 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, blue and amber status LEDs glowing, one server unit slightly pulled
Vulnerabilities

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.

Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

4 min read
A dimly lit modern security operations centre viewed from behind an empty analyst chair, multiple large curved monitors glowing with abstract log data and netwo
Policy & Regulation

US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation

An updated federal advisory names the specific techniques used to break into programmable logic controllers, the computers that run factories, water plants, and power grids.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild

CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

4 min read
© 2026 Threat Vectr