#CISA
99 stories taggedCISA · page 4 of 7.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

Microsoft's July 2026 Patch Tuesday Is the Biggest Ever, 622 Fixes at Once
AI tools are finding software flaws faster than companies can fix them. This month's update from Microsoft shows exactly what that looks like in practice.

CISA Warns of Active Attacks on SharePoint Servers, Urges Immediate Patching
Three flaws are being exploited to break into on-premises SharePoint, steal cryptographic keys, and plant malware. Two more just disclosed could be next.

Russia's FSB Is Quietly Hijacking Old Routers Across Critical Infrastructure, Allies Warn
A rare joint advisory from thirteen agencies details how FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, have spent over a decade pulling configs from misconfigured network gear.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both scored a perfect 10 on the severity scale.

Microsoft says AI is finding so many Windows bugs, expect bigger Patch Tuesdays
The company is using multiple AI models to hunt vulnerabilities in Windows code, and warns customers will see more fixes each month as a result.

AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are.
A four-hour outage. A room full of people who couldn't say which human authorized the last action. A new six-stage model explains why AI agents are breaking identity security, and what it takes to fix it.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

Federal Cyber Agency Reportedly Turning to AI to Hunt for Weaknesses in Government Software
CISA's specialist team is said to be using Anthropic's Mythos tool to scan federal systems for security flaws, in what could become a significant shift in how the U.S. government checks its own digital defenses.