#CISA
115 stories taggedCISA · page 3 of 8.

Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other
CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists
A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

Silent Software Patches Protect Hackers, Not Users
When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps
One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused
Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

US agencies warn hackers are using AI to break into Siemens factory controllers
CISA, NSA, FBI, DOE and EPA say attackers are scanning the internet for exposed Siemens S7 PLCs and running AI-written scripts dressed up as monitoring tools.

Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn
A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500, with hospitals, defence suppliers and banks all in the firing line.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List
The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine
A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing
A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.