CISA

Entity category: organization

Business

Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

A critical five-year-old Fortinet firewall flaw (CVE-2020-12812) allows attackers to bypass two-factor authentication by altering a username's case, and over…

Read More »
BigTech Companies

IBM API Connect flaw exposes critical authentication bypass risk

A critical vulnerability (CVE-2025-13915) in IBM API Connect allows attackers to bypass authentication and gain unauthorized remote access, posing a…

Read More »
Business

US Federal Cybersecurity Stagnation Sparks Growing Alarm

Significant staffing cuts at CISA, the national cybersecurity agency, have created a severe operational crisis with a 40% vacancy rate…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited MongoBleed Flaw

A critical vulnerability in MongoDB, tracked as CVE-2025-14847 and dubbed MongoBleed, is being actively exploited to remotely steal sensitive data…

Read More »
Business

Romanian Water Authority Hit by Major Ransomware Attack

A ransomware attack disrupted administrative systems at Romania's national water authority, but crucial operational technology controlling physical water infrastructure like…

Read More »
Cybersecurity

Thousands of FortiCloud SSO Devices Vulnerable to Remote Hacks

Tens of thousands of internet-facing Fortinet devices remain vulnerable to critical authentication bypass flaws (CVE-2025-59718/9), creating a massive attack surface…

Read More »
BigTech Companies

Urgent Apple Update Fixes Critical Security Exploits

Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine,…

Read More »
Business

MITRE Reveals 2025’s 25 Most Dangerous Software Weaknesses

MITRE and CISA have released the 2025 CWE Top 25, a critical ranking of the most dangerous software weaknesses based…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited Geoserver Flaw

CISA has mandated federal agencies to patch a critical, actively exploited vulnerability (CVE-2025-58360) in GeoServer that allows attackers to steal…

Read More »
Business

Multiple Threat Groups Exploit Active WinRAR Vulnerability

A critical path traversal vulnerability (CVE-2025-6218) in WinRAR for Windows is being actively exploited, allowing attackers to execute arbitrary code…

Read More »
Business

US Critical Infrastructure Hit by Pro-Russia Cyberattacks

Pro-Russia hacktivist groups are exploiting weak security to breach U.S. critical infrastructure, causing real disruptions in sectors like water and…

Read More »
Business

CISA Alerts: Chinese “BrickStorm” Malware Targets VMware Servers

A sophisticated Chinese-linked malware campaign called "Brickstorm" is targeting VMware vSphere servers, using hidden virtual machines to steal credentials and…

Read More »
Artificial Intelligence

US & Australia Release AI Security Guidelines for Infrastructure

U.S. and Australian cybersecurity agencies have released joint guidelines to help critical infrastructure operators securely integrate AI tools, like machine…

Read More »
Business

Pall Mall Process: Defining Responsible Cyber Intrusion

The Pall Mall Process, a joint UK-France initiative with 27 governments and major tech firms, aims to establish international standards…

Read More »
Cybersecurity

CISA Warns of Active Android Attacks – Update Now

CISA has issued an urgent directive for federal employees to apply critical Android security updates by December 23 or stop…

Read More »
BigTech Companies

Google Patches Actively Exploited Zero-Day Vulnerabilities

Google has released a critical Android security update patching over 100 vulnerabilities, including three severe flaws that are under active,…

Read More »
Business

Patch Now: CISA Warns of Active Oracle Identity Manager Attack

A critical vulnerability (CVE-2025-61757) in Oracle Identity Manager is being actively exploited, allowing unauthenticated attackers to execute arbitrary code via…

Read More »
Business

Urgent CISA Alert: Active Oracle Identity Manager RCE Exploits

A critical security vulnerability (CVE-2025-61757) in Oracle Identity Manager allows attackers to execute remote code without authentication by exploiting weaknesses…

Read More »
BigTech Companies

Google Issues Emergency Chrome Update for 2 Billion Users

Google has issued an emergency security patch for Chrome to address a high-severity vulnerability (CVE-2025-13223) that is already being actively…

Read More »
Cybersecurity

D-Link DIR-878 routers have critical RCE flaws

D-Link has issued a critical alert for its unsupported DIR-878 router, revealing three severe vulnerabilities that allow unauthenticated remote command…

Read More »