CISA

Entity category: organization

BigTech Companies

TikTok Deal Finalized After Months of Negotiations

A new joint venture has been established to protect U.S. TikTok user data and the platform's core algorithm, housing them…

Read More »
Business

New Global Rules to Protect Industrial Networks Unveiled

A new international framework led by US, UK, and global agencies establishes security principles to protect operational technology (OT) environments,…

Read More »
Artificial Intelligence

Ex-CISA Chief Jen Easterly to Lead RSA Conference

Jen Easterly, former head of CISA, is appointed CEO of RSA Conference, signaling a major leadership shift for the global…

Read More »
Cybersecurity

Unpatched Gogs Bug Actively Exploited, CISA Warns

A critical vulnerability (CVE-2025-8110) in the Gogs platform is being actively exploited, allowing authenticated users to achieve remote code execution…

Read More »
Business

CISA Mandates Urgent Patch for Actively Exploited Gogs Flaw

A critical remote code execution flaw (CVE-2025-8110) in Gogs is being actively exploited, allowing attackers to run arbitrary commands by…

Read More »
Business

CISA Concludes 10 Emergency Directives Following Federal Cyber Audits

CISA has closed ten Emergency Directives from 2019-2024 after confirming their security goals were met, signaling a strategic shift from…

Read More »
Artificial Intelligence

Patch Tuesday Forecast & Critical Trend Micro RCE PoC Released

A critical unauthenticated remote code execution flaw (CVE-2025-69258) in Trend Micro Apex Central requires immediate patching, and CISA warns of…

Read More »
Business

CISA Retires 10 Emergency Cyber Directives in Bulk Move

CISA has retired ten Emergency Directives, as their required security measures are now fully implemented or superseded by the broader…

Read More »
Business

Exploit Alert: Actively Targeted HPE OneView Flaw (CVE-2025-37164)

A critical, actively exploited vulnerability (CVE-2025-37164) in HPE OneView allows unauthenticated remote code execution, prompting urgent patching. The flaw is…

Read More »
Business

Sedgwick Subsidiary Breach Exposes Government Contractor Data

A data breach at Sedgwick Government Solutions exposed sensitive information from over twenty federal agency clients, including CISA, DHS, and…

Read More »
Business

Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

A critical five-year-old Fortinet firewall flaw (CVE-2020-12812) allows attackers to bypass two-factor authentication by altering a username's case, and over…

Read More »
BigTech Companies

IBM API Connect flaw exposes critical authentication bypass risk

A critical vulnerability (CVE-2025-13915) in IBM API Connect allows attackers to bypass authentication and gain unauthorized remote access, posing a…

Read More »
Business

US Federal Cybersecurity Stagnation Sparks Growing Alarm

Significant staffing cuts at CISA, the national cybersecurity agency, have created a severe operational crisis with a 40% vacancy rate…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited MongoBleed Flaw

A critical vulnerability in MongoDB, tracked as CVE-2025-14847 and dubbed MongoBleed, is being actively exploited to remotely steal sensitive data…

Read More »
Business

Romanian Water Authority Hit by Major Ransomware Attack

A ransomware attack disrupted administrative systems at Romania's national water authority, but crucial operational technology controlling physical water infrastructure like…

Read More »
Cybersecurity

Thousands of FortiCloud SSO Devices Vulnerable to Remote Hacks

Tens of thousands of internet-facing Fortinet devices remain vulnerable to critical authentication bypass flaws (CVE-2025-59718/9), creating a massive attack surface…

Read More »
BigTech Companies

Urgent Apple Update Fixes Critical Security Exploits

Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine,…

Read More »
Business

MITRE Reveals 2025’s 25 Most Dangerous Software Weaknesses

MITRE and CISA have released the 2025 CWE Top 25, a critical ranking of the most dangerous software weaknesses based…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited Geoserver Flaw

CISA has mandated federal agencies to patch a critical, actively exploited vulnerability (CVE-2025-58360) in GeoServer that allows attackers to steal…

Read More »
Business

Multiple Threat Groups Exploit Active WinRAR Vulnerability

A critical path traversal vulnerability (CVE-2025-6218) in WinRAR for Windows is being actively exploited, allowing attackers to execute arbitrary code…

Read More »