Topic: federal cybersecurity
-
CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe
CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch these issues or cease using the affected systems by September 27. Two additional actively exploited flaws were identified: a high-sever...
Read More » -
CISA Concludes 10 Emergency Directives Following Federal Cyber Audits
CISA has closed ten Emergency Directives from 2019-2024 after confirming their security goals were met, signaling a strategic shift from reactive emergency measures to standardized, ongoing risk management. The retired directives' requirements are now integrated into Binding Operational Directive...
Read More » -
CISA orders agencies to patch critical Langflow flaw
CISA has ordered all federal agencies to patch a critical Langflow vulnerability (CVE-2025-XXXX) by Friday, as it is being actively exploited and poses a national security risk. The flaw allows arbitrary code execution on systems using Langflow versions before 1.1.0, and CISA has added it to its ...
Read More » -
CISA Orders US Agencies to Patch Critical Bugs in 3 Days Over AI Threats
CISA's new binding operational directive requires federal agencies to patch the most critical security vulnerabilities within three days and conduct forensic triage, responding to the accelerating threat of AI-powered vulnerability discovery and exploitation. The directive introduces a four-facto...
Read More » -
CISA gives federal agencies 3 days to patch exploited VPN flaw
A ransomware group named Qilin is actively exploiting an unpatched VPN vulnerability in Check Point Software products, prompting CISA to issue an emergency directive for all civilian federal agencies to remediate the flaw by June 11. The vulnerability impacts Check Point's remote access tools, fi...
Read More » -
CISA: Ransomware gangs exploit SonicWall SMA1000 flaws
CISA has confirmed ransomware operators are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410), both added to its Known Exploited Vulnerabilities catalog with a three-day remediation mandate for federal agencies. Threat actor UTA0533 has...
Read More » -
Urgent Samsung Patch Stops Spyware Exploit
Samsung has released a critical security update for a vulnerability (CVE-2025-21042) in its image processing library, which was actively exploited to install the LANDFALL spyware on mobile devices. The spyware uses a zero-click infection method via manipulated image files, allowing it to infect d...
Read More » -
CISA Guide Helps Agencies Adopt SASE for Zero Trust
CISA released a guide on June 24 to help federal agencies transition to Secure Access Service Edge (SASE) technology, replacing the outdated MTIPS and moving from perimeter-based TIC 2.0 to the zero trust-aligned TIC 3.0 framework. SASE combines networking (SD-WAN) and security tools like secure ...
Read More »