#CISA
115 stories taggedCISA · page 5 of 8.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

US and allies rewrite the software 'ingredients list' rulebook for 2026
CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

US and Australian agencies publish playbook for cutting critical systems off in a crisis
New joint guidance tells power, water and transport operators how to run in isolation when a cyberattack or geopolitical crisis forces the plug to be pulled.

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation
An updated federal advisory names the specific techniques used to break into programmable logic controllers, the computers that run factories, water plants, and power grids.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

Siemens Rushes Fix for Smart Plug Riddled With Eight Serious Flaws
The SIDIS Secured SmartPlug carried a critical 9.8-rated bug plus seven more in bundled open-source libraries. Siemens says update to V7.26.0310.

Trump Declassifies Election Fraud Claims: What Was Actually Said
President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.
Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack
Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.