Tag

#CISA

110 stories taggedCISA · page 4 of 8.

Industrial control system screens for energy and water infrastructure running on displays, with a MongoDB database version number from 2020 visible in the syste
Vulnerabilities

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020

Industrial software used in energy and water plants bundles an old database carrying flaws that can leak memory and sidestep access controls.

3 min read
A close-up of a developer's desk with multiple monitors displaying code and warning alerts, with a red notification banner visible on the central screen, urgent
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity

A software tool used by thousands of development teams has a severe security hole that attackers are already using. The US government is giving federal agencies three days to fix it.

3 min read
A federal government IT operations center with multiple screens displaying three different vulnerability alerts simultaneously—Langflow, N-central, and Tomcat p
Vulnerabilities

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack

Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

4 min read
A CISA alert notification displayed on a government cybersecurity operations center screen, with actively exploited vulnerabilities being added to the official
Vulnerabilities

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List

A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

3 min read
A water utility control room with SCADA screens displaying system operations, while on an adjacent monitor a digital backup shows attackers may possess more com
Threat Intelligence

The criminals behind the Minnesota water attacks may have a better backup of your plant than you do

Hackers hit more than 30 small water utilities in two days. The most alarming detail isn't how they got in: they may have walked out with the only complete copy of control logic the operators ever had.

5 min read
Composite scene showing a casino floor and children's hospital interior simultaneously split-screen style, representing decade of varied Iranian cyberattack tar
Threat Intelligence

A Decade of Iranian Cyberattacks on America: What We Know

From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

5 min read
IT service provider office with technicians managing remote monitoring dashboards, security alerts and vulnerability notifications visible on screens, urgent re
Vulnerabilities

CISA flags N-able N-central bug as actively exploited, orders federal fix

The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

3 min read
A water system control center displaying distribution maps of Minnesota and surrounding states with system outages marked, attribution analysis showing Iranian-
Threat Intelligence

Iranian hackers suspected in attack on 30 US water systems

A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.

3 min read
A certificate authority headquarters building facade at day, digital certificate chains and trust hierarchies visualized as glowing networks overlaid on the str
Policy & Regulation

When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath

Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

4 min read
An industrial water treatment control room with rows of SCADA monitors and pump system gauges, one screen showing a lockout notification and operator unable to
Threat Intelligence

CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet

The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

4 min read
A spacecraft control center with multiple monitors displaying NASA flight software interfaces, one screen showing a command input field and system crash notific
Vulnerabilities

NASA's Core Flight System has a flaw that can crash spacecraft software

A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

4 min read
An industrial factory floor with networked Mitsubishi Electric machinery and control devices, with one device showing offline status and communication protocol
Vulnerabilities

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack

A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

3 min read
A government office workspace with multiple screens displaying open source code repositories and security vetting checklists, with the C4 trust framework diagra
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
Government and international security agency emblems arranged around a software blueprint document with detailed ingredient lists and components clearly labeled
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
A government office desk with federal compliance documents and updated patch management timelines, an AI-generated threat assessment report beside them, represe
Policy & Regulation

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.

A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

5 min read
© 2026 Threat Vectr