CISA

Entity category: organization

Cybersecurity

Urgent Samsung Patch Stops Spyware Exploit

Samsung has released a critical security update for a vulnerability (CVE-2025-21042) in its image processing library, which was actively exploited…

Read More »
Cybersecurity

CISA Urges Immediate Patch for Samsung Spyware Zero-Day

A critical vulnerability (CVE-2025-21042) in Samsung smartphones allows attackers to install LandFall spyware via manipulated DNG images sent through WhatsApp,…

Read More »
Artificial Intelligence

Critical RCE Flaw Found in Popular expr-eval JavaScript Library

A critical remote code execution vulnerability (CVE-2025-12735) has been found in the widely used expr-eval JavaScript library, affecting over 800,000…

Read More »
Cybersecurity

Urgent: Critical Web Panel Flaw Actively Exploited (CVE-2025-48703)

A critical security vulnerability (CVE-2025-48703) in Control Web Panel (CWP) is being actively exploited, posing a severe threat to web…

Read More »
Business

Government Shutdown: A Cybersecurity Crisis in the Making

A cybersecurity breach at the Congressional Budget Office, suspected to involve a foreign actor, highlights increased vulnerabilities during the government…

Read More »
Business

Urgent CISA Alert: Active Attacks Exploit Critical CentOS Bug

A critical security flaw (CVE-2025-48703) in CentOS Web Panel allows unauthenticated attackers to execute arbitrary commands, prompting CISA to issue…

Read More »
Business

Secure Your Exchange Server: CISA & NSA Best Practices

A new cybersecurity framework from CISA and the NSA provides detailed steps to protect Microsoft Exchange Server installations from sophisticated…

Read More »
Business

CISA Alerts: 2 New Dassault Flaws Under Active Attack

CISA warns that two new security flaws in Dassault Systèmes' DELMIA Apriso platform are being actively exploited, posing risks to…

Read More »
BigTech Companies

CISA Urges Immediate VMware Patch for Chinese Hacker Exploit

CISA has issued an urgent directive for U.S. government agencies to patch a critical VMware vulnerability (CVE-2025-41244) that allows privilege…

Read More »
Business

Ransomware Gangs Now Exploiting Critical Linux Flaw

A critical Linux kernel vulnerability (CVE-2024-1086) is now being actively exploited by ransomware gangs, allowing attackers to gain complete control…

Read More »
BigTech Companies

CISA, Partners Act on Critical Microsoft Exchange Vulnerabilities

CISA, NSA, and international partners have issued critical guidance for securing on-premises Microsoft Exchange Servers, as Microsoft ends perpetual security…

Read More »
BigTech Companies

Secure Your Microsoft Exchange Servers: CISA & NSA Guidance

A joint advisory from cybersecurity agencies recommends a proactive, multi-layered security strategy for Microsoft Exchange servers, including decommissioning outdated on-premises…

Read More »
BigTech Companies

Urgent: Actively Exploited WSUS Bug Now on CISA KEV List

A critical security flaw (CVE-2025-59287) in Windows Server Update Services (WSUS) allows unauthenticated attackers to execute remote code with system…

Read More »
BigTech Companies

CISA Urges Immediate Patch for Critical Windows Server Flaw

A critical remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS) allows attackers to gain full SYSTEM-level control…

Read More »
Business

Zero-Day Attack Exploits Lanscope Endpoint Manager Flaw

A critical zero-day vulnerability (CVE-2025-61932) in Lanscope Endpoint Manager is being actively exploited, primarily targeting Japanese customers since April 2025.…

Read More »
BigTech Companies

Microsoft Issues Critical Windows Update Amid Active Attacks

Microsoft has issued an urgent security update for Windows Server to patch a critical vulnerability (CVE-2025-59287) that is actively being…

Read More »
BigTech Companies

Urgent: Patch Windows SMB Flaw Being Actively Exploited

A critical Windows SMB Client vulnerability (CVE-2025-33073) is being actively exploited, allowing attackers to gain SYSTEM-level privileges through a malicious…

Read More »
Business

Hackers Exploit Critical Oracle Flaw, CISA Confirms

CISA has added the critical Oracle E-Business Suite vulnerability CVE-2025-61884 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and…

Read More »
BigTech Companies

Urgent Windows Update: 2-Week Security Deadline

Microsoft has released urgent security updates addressing two actively exploited zero-day vulnerabilities, with federal agencies mandated to patch within two…

Read More »
BigTech Companies

Urgent Windows SMB Flaw Actively Exploited, CISA Warns

A critical Windows SMB vulnerability (CVE-2025-33073) is being actively exploited, allowing attackers to gain full SYSTEM-level control over unpatched systems.…

Read More »