Cybersecurity and Infrastructure Security Agency

Entity category: organization

AI & Tech

CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe

CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal…

Read More »
AI & Tech

Citrix NetScaler Auth Bypass Now Used in Active Attacks

Threat actors are actively exploiting the critical CVE-2026-19490 vulnerability in Citrix NetScaler devices to bypass authentication, following the public release…

Read More »
Business

Philips, GE probe Clop ransomware data theft claims

GE and Philips confirmed investigating Clop ransomware breach claims, with Philips admitting a contained breach of an internal server that…

Read More »
AI & Tech

CISA orders 3-day patch for Ray AI flaw under active attack

CISA added critical Ray vulnerability CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, confirming active exploitation via remote…

Read More »
Business

Shell probes cyber incident after Clop data theft claims

Shell is investigating a potential security breach after the Clop ransomware group claimed to have stolen 89GB of data, including…

Read More »
Business

Gunra Ransomware Targets Critical Infrastructure via Fortinet Flaws

Gunra ransomware operators are exploiting two legacy Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to breach government and critical infrastructure networks, using…

Read More »
BigTech Companies

New Microsoft SharePoint exploit used in active hacker attacks

CVE-2026-55040, a critical JWT authentication bypass in Microsoft SharePoint, is being actively exploited in the wild within a day of…

Read More »
BigTech Companies

Check Point SmartConsole zero-day actively exploited in attacks

Check Point has released a patch for CVE-2026-16232, a critical authentication bypass zero-day vulnerability in its SmartConsole GUI that is…

Read More »
BigTech Companies

Critical SharePoint RCE under attack: Patch and rotate keys now (CVE-2026-50522)

Attackers are actively exploiting the critical SharePoint remote code execution flaw CVE-2026-50522 to steal IIS machine keys from on-premise servers,…

Read More »
Business

Qilin ransomware exploits critical Palo Alto VPN bug

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN…

Read More »
AI & Tech

US Launches Gold Eagle for AI-Driven Vulnerability Management

The U.S. federal government launched "Gold Eagle," a program using AI to accelerate cyber threat detection and remediation, uniting CISA,…

Read More »
BigTech Companies

US warns Russian state hackers are targeting your router

The US government urges home and small office router users to secure their devices as Russian state-sponsored hackers continue to…

Read More »
Business

Inside a Secret War Game: If China Hacks US Water Supply

A simulated cyberattack on American water systems escalates from a strategic game to a tense crisis, as hackers disable 5,000…

Read More »
Business

900+ Oracle E-Business instances under active attack

A critical unauthenticated vulnerability (CVE-2026-46817, CVSS 9.8) in Oracle E-Business Suite's Payments component is being actively exploited, with threat intelligence…

Read More »
AI & Tech

Adobe fixes 7 critical ColdFusion and Campaign flaws

Adobe released critical security patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic, which are rated priority 1 due…

Read More »
AI & Tech

Veeam backup servers at risk from new RCE vulnerability

Veeam released a critical security patch for its Backup & Replication software (CVE-2026-44963) that fixes a remote code execution vulnerability…

Read More »
Business

Ivanti Sentry max severity flaw actively exploited

Attackers are actively exploiting a maximum-severity OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry, allowing remote code execution with root…

Read More »
Business

900+ US gas station tank gauges exposed to cyberattacks

Over 900 automatic tank gauge (ATG) systems in the U.S. remain exposed online, posing a major cybersecurity risk as attackers…

Read More »
BigTech Companies

CISA Opens KEV Nomination Form to Vendors and Researchers

CISA has launched a new online nomination form for security researchers and vendors to directly report known exploited vulnerabilities for…

Read More »
AI & Tech

NCSC Warns of AI-Driven Patch Vulnerability Wave

The UK's National Cyber Security Centre (NCSC) warns that organizations must prepare for a wave of critical software patches driven…

Read More »