#cisa — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cisa, aggregated by home.social.
-
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
US says hackers are targeting vulnerable water systems with the help of AI
Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States.
#CISA #criticalinfrastructure #cyberattack #cybersecurity #Water
-
NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs — BigGo Finance
U.S. intelligence and security authorities have issued an urgent warning about AI-powered hacking attempts against critical infrastructure. Hackers…
#Germany #DE #Europe #EU #Europa #Siemens #BusanMetropolitanPolice #CISA #fbi #Lazarus #Medusaransomware #NSA #programmablelogiccontroller #siemens #U.S.DepartmentofEnergy #U.S.EnvironmentalProtectionAgency
https://www.europesays.com/germany/76886/ -
CISA Warns of Exploited Flaws in Russian Video Conferencing Platform TrueConf
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about two critical vulnerabilities in TrueConf, a Russian video conferencing platform, that have already been exploited in real-world attacks. Federal agencies have just until September 10 to patch these flaws and protect themselves.
#ExploitedVulnerabilities #Trueconf #Russia #Cisa #Cve202672529
-
CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.
#RayFramework #CVE202562593 #ActiveExploitation #CISA
https://cyberworldops.eu/en/ray-added-to-the-kev-catalog-active-exploitation-targeting-ai
-
This was posted yesterday.
Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
The document: https://www.cisa.gov/resources-tools/resources/logging-reference-architecture #CISA #infosec
-
This was posted yesterday.
Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
The document: https://www.cisa.gov/resources-tools/resources/logging-reference-architecture #CISA #infosec
-
This was posted yesterday.
Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
The document: https://www.cisa.gov/resources-tools/resources/logging-reference-architecture #CISA #infosec
-
This was posted yesterday.
Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
The document: https://www.cisa.gov/resources-tools/resources/logging-reference-architecture #CISA #infosec
-
This was posted yesterday.
Press release: CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging
The document: https://www.cisa.gov/resources-tools/resources/logging-reference-architecture #CISA #infosec
-
CISA Mandates Patching of Exploited TrueConf Server Flaws
Don't wait until it's too late: CISA has issued a two-week deadline for U.S. federal agencies to patch two critical TrueConf Server vulnerabilities that hackers are actively exploiting to execute malicious scripts remotely. With a September 3 remediation deadline looming, prioritize patching now to safeguard your systems.
#TrueconfServer #Cve202672529 #Cisa #KnownExploitedVulnerabilities #Kev
-
Siemens Says No Spike in Attacks Despite US Warning on Hacked Industrial Controllers — BigGo Finance
Siemens said Wednesday it has not detected an increase in cyberattacks or any previously unknown vulnerabilities …
#Germany #DE #Europe #EU #Europa #Siemens #CISA #CyberAv3ngers #DepartmentofEnergy #EnvironmentalProtectionAgency #fbi #Iran #nationalsecurityagency #NickAndersen #S7Seriesprogrammablelogiccontrollers #siemens #USDepartmentofHomelandSecurity
https://www.europesays.com/germany/76362/ -
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.
-
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.
-
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.
-
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.
-
Reward: You've received a cracked Stone Gorgon Shield — cosmetic only, no defensive stats.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
Reward: You've received a cracked Stone Gorgon Shield — cosmetic only, no defensive stats.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
Reward: You've received a cracked Stone Gorgon Shield — cosmetic only, no defensive stats.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
-
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
-
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
-
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
-
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
-
#CISA : #Medusa #Ransomware Hit Over 500 Critical #Infrastructure Orgs
#security -
#CISA : #Medusa #Ransomware Hit Over 500 Critical #Infrastructure Orgs
#security -
#CISA : #Medusa #Ransomware Hit Over 500 Critical #Infrastructure Orgs
#security -
#CISA : #Medusa #Ransomware Hit Over 500 Critical #Infrastructure Orgs
#security -
#CISA : #Medusa #Ransomware Hit Over 500 Critical #Infrastructure Orgs
#security -
Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.
Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.
Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."
#CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)
-
Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.
Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.
Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."
#CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)
-
Quiet dignity. A patch it never received in time. It will be remembered by no one, mourned by your incident response team exclusively.
Patch Windows IKE Extension immediately — CISA's warning means the funeral procession is already at your perimeter.
Reward: A commemorative Fallen Control Plane Tombstone. It reads: "It could have been patched."
#CyberSecurity #RCE #Windows #Vulnerability #CISA #CriticalAlert (2/2)
-
CISA, the FBI, and HHS updated their joint advisory on Medusa ransomware, reporting over 500 critical infrastructure victims and detailing its RaaS and IAB-driven operations.
#MedusaRansomware #CISA #Ransomware #CriticalInfrastructure #RaaS
-
CISA, the FBI, and HHS updated their joint advisory on Medusa ransomware, reporting over 500 critical infrastructure victims and detailing its RaaS and IAB-driven operations.
#MedusaRansomware #CISA #Ransomware #CriticalInfrastructure #RaaS
-
Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water and Energy
Five U.S. agencies issued an urgent joint advisory on August 19, 2026, confirming for the first time in…
#Germany #DE #Europe #EU #Europa #Siemens #AI #AIexploitICS #CISA #CISAAA26-231A #Criticalinfrastructure #cyberattack #siemens #SiemensS7PLC #WaterSecurity
https://www.europesays.com/germany/75813/ -
US agencies warn of AI-powered attacks on Siemens industrial controllers
Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs)…
#Germany #DE #Europe #EU #Europa #Siemens #AI #CISA #Criticalinfrastructure #fbi #NSA #siemens
https://www.europesays.com/germany/75700/ -
Microsoft patched this Windows VPN flaw in April. CISA confirms active exploitation now. CVE-2026-33824, CVSS 9.8, no auth needed. Patch or block UDP 500/4500 today.
-
Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
Reward: This achievement was proudly sponsored by Unrotated Credentials, LLC. We do not offer prizes. We offer consequences.
#Ransomware #Medusa #CyberSecurity #CISA #CriticalInfrastructure #PatchedOrPerish (3/3)
-
CISA Flags Exploited Microsoft, VMware, Apple Flaws
CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.
https://pulseofnations.lol/cisa-flags-exploited/
#AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay
-
CISA Flags Exploited Microsoft, VMware, Apple Flaws
CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.
https://pulseofnations.lol/cisa-flags-exploited/
#AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay
-
CISA Flags Exploited Microsoft, VMware, Apple Flaws
CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.
https://pulseofnations.lol/cisa-flags-exploited/
#AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay
-
CISA Flags Exploited Microsoft, VMware, Apple Flaws
CISA adds four actively exploited vulnerabilities to its KEV catalog, including flaws used in a Chinese AI-enabled autonomous hacking campaign.
https://pulseofnations.lol/cisa-flags-exploited/
#AiHacking #Apple #CISA #Kev #Microsoft #Vmware #Vulnerability #ZeroDay
-
FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches
Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are…
#Germany #DE #Europe #EU #Europa #Siemens #CISA #CyberSecurity #Iranwar #siemens
https://www.europesays.com/germany/75446/ -
CISA and the NSA warn of an active Siemens PLC cyber threat using AI-generated exploit scripts disguised as monitoring tools. Learn how to protect OT.
#SiemensPLC #ICSsecurity #OTsecurity #CISA #CriticalInfrastructure
-
CISA has added four vulnerabilities to its KEV catalog with evidence of active exploitation. Affected systems include Microsoft IKE Service Extensions, SharePoint, VMware vCenter, and Apple macOS.
#CISA #ActiveExploitation #VulnerabilityManagement #PatchManagement
https://cyberworldops.eu/en/four-critical-vulnerabilities-exploited-against-macos-sharepoint
-
Progress LoadMaster CVE-2026-8037 (CVSS 9.6): 792 exploit attempts logged, CISA KEV deadline passed. Unauthenticated root command injection. Patch to GA 7.2.63.2 now.
-
CISA added four exploited vulnerabilities to its KEV Catalog, hitting SharePoint, VMware vCenter, macOS, and Windows IKE. Patch by August 21.
-
CISA added four exploited vulnerabilities to its KEV Catalog, hitting SharePoint, VMware vCenter, macOS, and Windows IKE. Patch by August 21.
-
FIXED: Nothing. Nothing has been fixed. You are the content of this release.
Monitor CISA and FBI advisories for Medusa indicators of compromise and remediation guidance before Medusa ships version 3.
Reward: You've received a complimentary Outdated Advisory Scroll — now with 67% more victims than advertised.
#Ransomware #Medusa #CISA #CyberSecurity #CriticalInfrastructure #ThreatLevelEscalating (2/2)