#CISA
110 stories taggedCISA · page 4 of 8.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy and water plants bundles an old database carrying flaws that can leak memory and sidestep access controls.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams has a severe security hole that attackers are already using. The US government is giving federal agencies three days to fix it.

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack
Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List
A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

The criminals behind the Minnesota water attacks may have a better backup of your plant than you do
Hackers hit more than 30 small water utilities in two days. The most alarming detail isn't how they got in: they may have walked out with the only complete copy of control logic the operators ever had.

A Decade of Iranian Cyberattacks on America: What We Know
From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

CISA flags N-able N-central bug as actively exploited, orders federal fix
The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

Iranian hackers suspected in attack on 30 US water systems
A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.

When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath
Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet
The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

US and allies rewrite the software 'ingredients list' rulebook for 2026
CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.