Tag

#CISA

115 stories taggedCISA · page 3 of 8.

A split-screen view of two different security operations centers (one dimly lit, one brightly lit), each with multiple monitors displaying network activity and
Threat Intelligence

Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other

CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.

4 min read
A security analyst's desk with multiple monitors displaying vulnerability scanning software dashboards, with one screen highlighting early-warning alerts appear
Vulnerabilities

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists

A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

4 min read
A corporate development environment showing Spring framework code with security patches being silently applied in the background, while a security team at separ
Policy & Regulation

Silent Software Patches Protect Hackers, Not Users

When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

4 min read
A Java development environment showing Spring framework code with multiple security vulnerability indicators and patch notifications stacked in the interface
Vulnerabilities

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps

One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

3 min read
A government office building exterior with alert notifications and warning symbols overlaid, representing federal agencies receiving urgent patching directives
Vulnerabilities

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused

Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

3 min read
An industrial factory floor with manufacturing equipment and control systems, cybersecurity warning banners and AI-generated script alerts visible on monitoring
Threat Intelligence

US agencies warn hackers are using AI to break into Siemens factory controllers

CISA, NSA, FBI, DOE and EPA say attackers are scanning the internet for exposed Siemens S7 PLCs and running AI-written scripts dressed up as monitoring tools.

4 min read
A map of critical infrastructure across the United States—hospitals, power plants, banks, defense facilities—with 500 location markers indicating Medusa ransomw
Ransomware

Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn

A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500, with hospitals, defence suppliers and banks all in the firing line.

4 min read
Multiple windows showing security patch notifications and system update dialogs stacked across a desktop environment, with warning badges highlighted in red and
Vulnerabilities

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

4 min read
A network traffic analyzer dashboard with cascading data streams and highlighted vulnerabilities, showing file upload processes and access control bypass attemp
Vulnerabilities

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks

The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

4 min read
A server room filled with blinking network equipment and cooling systems, with red warning lights illuminating the hardware, suggesting active threat detection
Vulnerabilities

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

3 min read
A vast digital database visualization showing cascading vulnerability reports flooding a screen, with AI algorithms processing the data stream indicated by anim
Policy & Regulation

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?

The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

4 min read
A busy security operations center with multiple analysts at stations overwhelmed with alert dashboards and priority queues stretching across multiple screens, c
Policy & Regulation

Your security team's growing backlog is not their fault

When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

4 min read
An industrial design workstation with 3D modelling software displaying a malformed CAD file causing a crash, error messages and system logs visible, security pa
Vulnerabilities

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine

A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

3 min read
An industrial control room with SCADA system displays showing pipeline and manufacturing equipment monitoring, a security alert panel highlighting a code execut
Vulnerabilities

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

4 min read
A recruiter's email inbox displayed on screen with fake job offer messages crafted with professional design, alongside Windows system dialogs showing exploitati
Threat Intelligence

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies

Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

4 min read
© 2026 Threat Vectr