#CISA
98 stories taggedCISA · page 3 of 7.

SonicWall Security Devices Were Hacked for Weeks Before a Fix Existed
Criminals planted hidden malware inside SonicWall remote-access appliances at least three weeks before the manufacturer knew the attack routes existed. Two fresh vulnerabilities, now patched, gave intruders near-total control of the devices.

Trump Declassifies Election Fraud Claims: What Was Actually Said
President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.
Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack
Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint
Two Fortinet FortiSandbox flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

Siemens Patches Four Flaws in SICAM 8 Grid Kit, Including a Firmware Signing Bypass
The German industrial giant is pushing V26.20 firmware for gear that sits inside power stations. One bug lets an insider install their own firmware.

A malformed packet can knock Rockwell's Flex 5000 Adapter offline until someone power-cycles it
Rockwell Automation has patched a denial-of-service flaw in a widely deployed factory-floor module. The fix ships as firmware 6.012.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

CISA and NSA Publish Playbook for Working With Outside Bug Hunters
New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure
A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.

CISA sounds alarm on SharePoint Server flaws being used to break in right now
The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.