home.social

#cisa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cisa, aggregated by home.social.

fetched live
  1. Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

    Listen/Read: hackread.com/attackers-exploit

  2. Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

    Listen/Read: hackread.com/attackers-exploit

    #CyberSecurity #MLflow #AI #Vulnerability #CISA

  3. Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

    Listen/Read: hackread.com/attackers-exploit

    #CyberSecurity #MLflow #AI #Vulnerability #CISA

  4. Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

    Listen/Read: hackread.com/attackers-exploit

    #CyberSecurity #MLflow #AI #Vulnerability #CISA

  5. Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

    Listen/Read: hackread.com/attackers-exploit

    #CyberSecurity #MLflow #AI #Vulnerability #CISA

  6. US says hackers are targeting vulnerable water systems with the help of AI

    Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States.

    justpaste.in/news/us-says-hack

    #CISA #criticalinfrastructure #cyberattack #cybersecurity #Water

  7. NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs — BigGo Finance

    U.S. intelligence and security authorities have issued an urgent warning about AI-powered hacking attempts against critical infrastructure. Hackers…
    #Germany #DE #Europe #EU #Europa #Siemens #BusanMetropolitanPolice #CISA #fbi #Lazarus #Medusaransomware #NSA #programmablelogiccontroller #siemens #U.S.DepartmentofEnergy #U.S.EnvironmentalProtectionAgency
    europesays.com/germany/76886/

  8. CISA Warns of Exploited Flaws in Russian Video Conferencing Platform TrueConf

    The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about two critical vulnerabilities in TrueConf, a Russian video conferencing platform, that have already been exploited in real-world attacks. Federal agencies have just until September 10 to patch these flaws and protect themselves.

    osintsights.com/cisa-warns-of-

    #ExploitedVulnerabilities #Trueconf #Russia #Cisa #Cve202672529

  9. CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.

    #RayFramework #CVE202562593 #ActiveExploitation #CISA

    cyberworldops.eu/en/ray-added-

  10. This was posted yesterday.

    Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards cisa.gov/news-events/news/cisa

    The document: cisa.gov/resources-tools/resou #CISA #infosec

  11. This was posted yesterday.

    Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards cisa.gov/news-events/news/cisa

    The document: cisa.gov/resources-tools/resou #CISA #infosec

  12. This was posted yesterday.

    Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards cisa.gov/news-events/news/cisa

    The document: cisa.gov/resources-tools/resou #CISA #infosec

  13. This was posted yesterday.

    Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards cisa.gov/news-events/news/cisa

    The document: cisa.gov/resources-tools/resou #CISA #infosec

  14. This was posted yesterday.

    Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards cisa.gov/news-events/news/cisa

    The document: cisa.gov/resources-tools/resou #CISA #infosec

  15. CISA Mandates Patching of Exploited TrueConf Server Flaws

    Don't wait until it's too late: CISA has issued a two-week deadline for U.S. federal agencies to patch two critical TrueConf Server vulnerabilities that hackers are actively exploiting to execute malicious scripts remotely. With a September 3 remediation deadline looming, prioritize patching now to safeguard your systems.

    osintsights.com/cisa-mandates-

    #TrueconfServer #Cve202672529 #Cisa #KnownExploitedVulnerabilities #Kev

  16. CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

    #CVE202633824 #Windows #CISA #IKE #Vulnerability

    meterpreter.org/cve-2026-33824

  17. CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

    #CVE202633824 #Windows #CISA #IKE #Vulnerability

    meterpreter.org/cve-2026-33824

  18. CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

    #CVE202633824 #Windows #CISA #IKE #Vulnerability

    meterpreter.org/cve-2026-33824

  19. CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

    #CVE202633824 #Windows #CISA #IKE #Vulnerability

    meterpreter.org/cve-2026-33824

  20. CISA has added two known vulnerabilities to the KEV catalogue.

    - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

    - CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

    Yesterday:

    Cisco:

    CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

  21. CISA has added two known vulnerabilities to the KEV catalogue.

    - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

    - CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

    Yesterday:

    Cisco:

    CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

  22. CISA has added two known vulnerabilities to the KEV catalogue.

    - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

    - CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

    Yesterday:

    Cisco:

    CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

  23. CISA has added two known vulnerabilities to the KEV catalogue.

    - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

    - CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

    Yesterday:

    Cisco:

    CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

  24. CISA has added two known vulnerabilities to the KEV catalogue.

    - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

    - CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

    Yesterday:

    Cisco:

    CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

  25. Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.

    Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.

    Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."

    #CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)

  26. Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.

    Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.

    Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."

    #CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)

  27. Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.

    Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.

    Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."

    #CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)

  28. Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water and Energy

    Five U.S. agencies issued an urgent joint advisory on August 19, 2026, confirming for the first time in…
    #Germany #DE #Europe #EU #Europa #Siemens #AI #AIexploitICS #CISA #CISAAA26-231A #Criticalinfrastructure #cyberattack #siemens #SiemensS7PLC #WaterSecurity
    europesays.com/germany/75813/

  29. US agencies warn of AI-powered attacks on Siemens industrial controllers

    Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs)…
    #Germany #DE #Europe #EU #Europa #Siemens #AI #CISA #Criticalinfrastructure #fbi #NSA #siemens
    europesays.com/germany/75700/

  30. Microsoft patched this Windows VPN flaw in April. CISA confirms active exploitation now. CVE-2026-33824, CVSS 9.8, no auth needed. Patch or block UDP 500/4500 today. 

    🇬🇧 zurl.co/BS5bz
    🇩🇪 zurl.co/sdMt2

    #CyberSecurity #Windows #CISA

  31. Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.

    #Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)

  32. Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.

    #Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)

  33. Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.

    #Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)

  34. CISA Flags Exploited Microsoft, VMware, Apple Flaws

    CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.

    pulseofnations.lol/cisa-flags-

    #AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay

  35. CISA Flags Exploited Microsoft, VMware, Apple Flaws

    CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.

    pulseofnations.lol/cisa-flags-

    #AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay

  36. CISA Flags Exploited Microsoft, VMware, Apple Flaws

    CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.

    pulseofnations.lol/cisa-flags-

    #AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay

  37. CISA Flags Exploited Microsoft, VMware, Apple Flaws

    CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.

    pulseofnations.lol/cisa-flags-

    #AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay

  38. FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches

    Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are…
    #Germany #DE #Europe #EU #Europa #Siemens #CISA #CyberSecurity #Iranwar #siemens
    europesays.com/germany/75446/

  39. CISA has added four vulnerabilities to its KEV catalog with evidence of active exploitation. Affected systems include Microsoft IKE Service Extensions, SharePoint, VMware vCenter, and Apple macOS.

    #CISA #ActiveExploitation #VulnerabilityManagement #PatchManagement

    cyberworldops.eu/en/four-criti

  40. Progress LoadMaster CVE-2026-8037 (CVSS 9.6): 792 exploit attempts logged, CISA KEV deadline passed. Unauthenticated root command injection. Patch to GA 7.2.63.2 now.

    🇬🇧 zurl.co/Ph6GB
    🇩🇪 zurl.co/nejNF

    #CyberSecurity #CISA #LoadBalancer

  41. FIXED: Nothing. Nothing has been fixed. You are the content of this release.

    Monitor CISA and FBI advisories for Medusa indicators of compromise and remediation guidance before Medusa ships version 3.

    Reward: You've received a complimentary Outdated Advisory Scroll — now with 67% more victims than advertised.

    #Ransomware #Medusa #CISA #CyberSecurity #CriticalInfrastructure #ThreatLevelEscalating (2/2)