#CISA
110 stories taggedCISA · page 6 of 8.

CISA and NSA Publish Playbook for Working With Outside Bug Hunters
New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure
A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.

CISA sounds alarm on SharePoint Server flaws being used to break in right now
The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

CISA Warns of Active Attacks on SharePoint Servers, Urges Immediate Patching
Three flaws are being chained to break into on-premises SharePoint, steal cryptographic keys, and plant malware. Two more just disclosed could be next.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both carrying the maximum severity score.

Microsoft says AI is finding so many Windows bugs, expect bigger Patch Tuesdays
The company is using multiple AI models to hunt vulnerabilities in Windows code, and warns customers will see more fixes each month as a result.

AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are.
A four-hour outage. A room full of people who couldn't say which human authorized the last action. A new six-stage model explains why AI agents are breaking identity security, and what it takes to fix it.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins share the same quiet flaw: the copy most people read is rarely the full story.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

Federal Cyber Agency Reportedly Turning to AI to Hunt for Weaknesses in Government Software
CISA's specialist team is said to be using Anthropic's Mythos tool to scan federal systems for security flaws, in what could become a significant shift in how the U.S. government checks its own digital defenses.