Tag

#CISA

115 stories taggedCISA · page 5 of 8.

A spacecraft control center with multiple monitors displaying NASA flight software interfaces, one screen showing a command input field and system crash notific
Vulnerabilities

NASA's Core Flight System has a flaw that can crash spacecraft software

A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

4 min read
An industrial factory floor with networked Mitsubishi Electric machinery and control devices, with one device showing offline status and communication protocol
Vulnerabilities

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack

A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

3 min read
A government office workspace with multiple screens displaying open source code repositories and security vetting checklists, with the C4 trust framework diagra
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
Government and international security agency emblems arranged around a software blueprint document with detailed ingredient lists and components clearly labeled
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
A government office desk with federal compliance documents and updated patch management timelines, an AI-generated threat assessment report beside them, represe
Policy & Regulation

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.

A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

5 min read
A power station control room with operators standing before a wall of monitors, some screens going dark as critical systems are deliberately isolated, paper doc
Policy & Regulation

US and Australian agencies publish playbook for cutting critical systems off in a crisis

New joint guidance tells power, water and transport operators how to run in isolation when a cyberattack or geopolitical crisis forces the plug to be pulled.

4 min read
A busy IT operations center with security team members reviewing patch notes and discussing timelines on whiteboards and dashboards, with tension visible as cal
Vulnerabilities

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.

Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

4 min read
An industrial control room showing programmable logic controller interfaces, gauges, and critical infrastructure monitoring systems, with digital threat indicat
Policy & Regulation

US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation

An updated federal advisory names the specific techniques used to break into programmable logic controllers, the computers that run factories, water plants, and power grids.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild

CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

3 min read
Full-frame close-up photograph of an industrial smart plug device mounted on a metal DIN rail inside a factory electrical cabinet, cool blue LED status light gl
Vulnerabilities

Siemens Rushes Fix for Smart Plug Riddled With Eight Serious Flaws

The SIDIS Secured SmartPlug carried a critical 9.8-rated bug plus seven more in bundled open-source libraries. Siemens says update to V7.26.0310.

3 min read
The White House podium or official government setting with documents and declassified materials visible, a large display screen behind showing charts and electi
Policy & Regulation

Trump Declassifies Election Fraud Claims: What Was Actually Said

President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.

2 min read
A network security dashboard displayed across multiple monitors showing warning alerts and breach notifications, with a keyboard and mouse in the foreground sug
Vulnerabilities

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed

A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

3 min read
An office worker's computer screen showing multiple cloud application windows open simultaneously with sensitive customer data visible in each, filing cabinets
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
A government IT department frantically updating systems at night, multiple technicians at workstations with security patches being deployed across networks, urg
Vulnerabilities

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago

CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dark server rack in a data centre with a single amber warning light glowing on one rack unit, cool b
Vulnerabilities

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack

Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

3 min read
© 2026 Threat Vectr