CISA

Entity category: organization

AI & Tech

CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe

CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal…

Read More »
Cybersecurity

CISA Unveils Election Security Plan for 2026 Midterms

CISA released a comprehensive security plan on September 24, 2026, to protect the November midterm elections from cyber and physical…

Read More »
AI & Tech

Kiteworks Warns of Imminent Cyberattack, Urges Server Shutdown

Kiteworks has urgently instructed users to shut down their systems immediately due to credible threat intelligence indicating hackers may target…

Read More »
AI & Tech

EU Auditors: Info Gaps Hinder Cyber Incident Response

The EU Court of Auditors identifies insufficient information exchange and structural barriers as the primary weaknesses undermining the effectiveness of…

Read More »
AI & Tech

CISA Orders Federal Agencies to Patch Zyxel Data Theft Flaw

CISA has issued an urgent mandate requiring federal agencies to patch CVE-2026-7273, a critical vulnerability in Zyxel GS1900 switches that…

Read More »
AI & Tech

CISA Automates Vulnerability Reporting Platform

As of September 17, 2026, CISA officially transitioned from the legacy VINCE system to VINCE-NT, a modernized platform managed directly…

Read More »
AI & Tech

ScreenConnect Zero-Day Now Under Active Attack

CISA confirmed that threat actors are actively exploiting CVE-2026-84869, a critical zero-day vulnerability in ConnectWise’s ScreenConnect software that allows unauthorized…

Read More »
AI & Tech

NIST, CISA Finalize Playbook to Stop Token Theft

NIST and CISA have released finalized guidelines to help federal agencies and cloud providers defend against the forgery, theft, and…

Read More »
AI & Tech

Fraudulent Hires Get Credentials Before Detection

Fraudulent hires often gain unmonitored access to corporate networks for an average of 5.73 days before detection, creating significant security…

Read More »
AI & Tech

Z.ai Raises $5bn in Hong Kong With $3bn Zero-Interest Bonds

Z.ai secured approximately $5 billion through a hybrid financing strategy combining a $2 billion equity placement and $3 billion in…

Read More »
AI & Tech

Amazon Appoints Mandiant Founder Kevin Mandia to Board

Kevin Mandia, founder of cybersecurity firm Mandiant, has officially joined Amazon’s board of directors to serve on the Audit and…

Read More »
AI & Tech

China Dismisses US Distillation Advisory as Unfounded Smears

China’s foreign ministry dismissed a US intelligence advisory alleging that Chinese firms use distillation to extract capabilities from American AI…

Read More »
AI & Tech

N-able Fixes Critical N-Central Flaw Amid Active Attacks

N-able has released an emergency hotfix, N-central 2026.3 HF4, to address critical remote code execution vulnerability CVE-2026-86218 that allows unauthenticated…

Read More »
AI & Tech

Claude Accounts Compromised by Infostealer; Patch Tuesday Forecast

Anthropic forced a logout for Claude users to secure accounts hijacked by infostealer malware, highlighting the growing threat of credential…

Read More »
AI & Tech

Citrix NetScaler Auth Bypass Now Used in Active Attacks

Threat actors are actively exploiting the critical CVE-2026-19490 vulnerability in Citrix NetScaler devices to bypass authentication, following the public release…

Read More »
AI & Tech

Zimbra Servers Compromised; Patched Citrix NetScaler Flaw Exploited

Security researchers report a surge in attacks on unpatched enterprise infrastructure, with active exploitation of critical vulnerabilities in Zimbra, Citrix…

Read More »
BigTech Companies

CISA orders federal patch for exploited TrueConf Server bugs

CISA has added two actively exploited TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) to its KEV catalog, mandating that U.S. federal…

Read More »
AI & Tech

Patch Citrix NetScaler now: New critical flaws confirmed

Citrix disclosed two new NetScaler vulnerabilities: CVE-2026-19490, an unauthenticated authentication bypass (critical, when configured as AAA or Gateway with SAML…

Read More »
Artificial Intelligence

US warns of AI-driven attacks targeting Siemens PLCs

U.S. federal agencies issued a joint advisory about an active hacking campaign targeting Siemens S7 Series PLCs, with the threat…

Read More »
Business

CISA warns Medusa ransomware hit 500+ organizations

Medusa ransomware has compromised over 500 organizations since June 2021, targeting critical infrastructure sectors including healthcare, defense, manufacturing, and government…

Read More »