Tag

Cisa

All articles tagged with #cisa

CISA imposes 3-day patch window for critical Oracle vulnerability
security3 hours ago

CISA imposes 3-day patch window for critical Oracle vulnerability

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog, giving federal agencies a three‑day deadline to patch a critical Oracle flaw in Oracle HTTP Server and WebLogic Proxy Plug‑in on Windows VMs that can grant full data access. Oracle released patches in January 2026 for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); private-sector researchers reported active exploitation attempts, underscoring the urgency of patching.

CISA orders rapid patch for actively exploited Zimbra flaw
security1 day ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns
security14 days ago

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns

CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.

Is Iran Behind U.S. Water-Hacking? Attribution Still Unclear
technology22 days ago

Is Iran Behind U.S. Water-Hacking? Attribution Still Unclear

Minnesota reported a coordinated cyber-attack on over 30 water systems, with seven states affected and investigators probing a possible Iranian link. Iran denies involvement, but experts point to Iran-linked groups such as Handala, and attribution remains uncertain. The main concern is eroding public trust in critical services, while authorities urge immediate security upgrades, including disconnecting water systems from the internet and resetting passwords.

Coordinated cyberattack disrupts U.S. water systems across several states
technology25 days ago

Coordinated cyberattack disrupts U.S. water systems across several states

Hackers coordinated an attack on water facilities in multiple states, forcing boil-water notices and switching to manual operation as systems go offline. No drinking-water contamination has been reported, but the incident is being treated as one of the most serious cyberattacks on U.S. water infrastructure in years. Minnesota first flagged attacks on about 30 systems, with Wisconsin and others reporting related incidents; federal agencies (CISA, FBI, EPA) are scrambling to secure vulnerable PLCs and facilities. Attribution remains uncertain, though Iran is among suspected actors. Experts warn the water sector’s cybersecurity remains underfunded and under-defended against such intrusions.

Federal warning: Hackers now targeting U.S. water systems, Minnesota among those affected
technology25 days ago

Federal warning: Hackers now targeting U.S. water systems, Minnesota among those affected

U.S. federal agencies warn of a rise in cyberattacks on water systems, with more than 30 Minnesota facilities impacted. Attackers are compromising internet-facing PLCs to disrupt water production and distribution, though drinking water safety has not yet been breached; authorities urge operators to disconnect internet exposure, enforce strong passwords, and allow remote access only through a VPN or gateway. Attribution remains uncertain, though some officials point to Iranian-style patterns. Upgrading aging systems is costly, potentially driving funding needs and new cybersecurity rules from lawmakers.

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach
technology26 days ago

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach

CISA warns of a rising trend of hackers targeting U.S. water and wastewater facilities by manipulating PLCs and changing passwords to lock operators, prompting boil-water notices and manual operation. Minnesota reported a coordinated attack affecting more than 30 community water systems earlier this week, with investigators briefly weighing a possible Iran link; the overall water infrastructure remains vulnerable as probes continue.

politics27 days ago

GOP Rebuilds Support for U.S. Cyber Agency Amid AI Threats and Election Security Push

Republicans who once shunned the Cybersecurity and Infrastructure Security Agency (CISA) are rebuilding support as AI-powered cyber threats loom and election security concerns rise, with lawmakers like Reps. Garbarino and Bacon urging staffing and funding increases; DHS Secretary Mullin has signaled plans to expand CISA’s workforce by about 600, while leadership vacancies persist and budget fights over the agency’s funding continue.

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19
security1 month ago

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19

CISA added CVE-2026-58644, a critical deserialization RCE in Microsoft SharePoint Server, to the Known Exploited Vulnerabilities catalog, with FCEB agencies required to patch by July 19, 2026. Microsoft said the flaw was exploited in the wild before fixes were released (patches issued July 14, 2026). The warning comes as CISA notes ongoing exploitation of multiple on-premises SharePoint vulnerabilities and urges hardening steps: apply patches, enable AMSI, scan for intrusion artifacts, tailor logging, and avoid exposing SharePoint servers to the internet.

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert
technology1 month ago

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert

CISA warns that three on‑premises SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are being actively exploited to bypass authentication and run remote code, with attackers targeting unpatched systems. Microsoft also patched CVE-2026-55040 and CVE-2026-58644. Shadowserver reports thousands of exposed SharePoint servers, prompting urgent patching, hardened logging, AMSI/Defender integration, and limiting internet exposure. Federal agencies have a July 17 deadline under BOD 26-04 to patch CVE-2026-56164. Since 2021, CISA has flagged 11 exploited Microsoft SharePoint vulnerabilities (7 linked to ransomware).

security1 month ago

CISA Warns of Active SharePoint Exploits, Urges Immediate Hardening

CISA warns of active exploitation of three on-premises SharePoint vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) that enable remote code execution and post-exploitation activity such as stealing IIS machine keys; two additional CVEs (CVE-2026-55040 and CVE-2026-58644) are also identified as potential risks if not patched. To mitigate, organizations should apply the latest Microsoft patches, verify installation completion, and shorten patching cycles where possible; ensure AMSI integration is enabled for all SharePoint web apps and follow Microsoft guidance for AMSI configuration. Use the provided AMSI and MDAV detections as part of incident response and hardening: hunt for intrusion artifacts before rotating IIS keys, implement enhanced logging and telemetry to detect anomalies, and limit internet exposure by placing SharePoint behind a Layer 7 proxy and restricting Central Administration access. Review Microsoft’s security guidance and report incidents to CISA as needed. These CVEs have been added to the Known Exploited Vulnerabilities (KEV) catalog.

Russia-backed hackers weaponize home routers, US issues router-security advisory
technology1 month ago

Russia-backed hackers weaponize home routers, US issues router-security advisory

The US government warns that Russia-state hackers are compromising home and small-office routers to conceal attacks on critical infrastructure, exploiting weak SNMP configurations and default credentials to turn devices into exit nodes; the advisory urges disabling SNMP versions 1 and 2 (or SNMP entirely), using SNMPv3 if needed, disabling Cisco Smart Install, and maintaining strong passwords along with regular firmware updates to reduce risk.

CISA Tightens Patch Timelines for Federal Agencies, Pushing Critical Flaws to Three‑Day Fixes
technology2 months ago

CISA Tightens Patch Timelines for Federal Agencies, Pushing Critical Flaws to Three‑Day Fixes

The Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 26-04, requiring U.S. Federal Civilian Executive Branch agencies to remediate high‑risk vulnerabilities with accelerated timelines—down to three days for publicly exposed, known‑exploited flaws and up to two weeks for less urgent cases. The directive supersedes older BODs and mandates updates to vulnerability management policies, asset inventories, and automated KEV/CVE reporting, with full adherence within 180 days and policy changes within 60 days. It covers on‑premises, third‑party hosted, and cloud environments while excluding certain military, intelligence, and contractor systems, signaling a broader industry patch‑priority shift.

technology2 months ago

Risk-Based Patch Strategy Drives Federal Cyber Hygiene Under BOD 26-04

CISA's Binding Operational Directive 26-04 requires federal civilian agencies to prioritize vulnerability remediation based on risk, using the Known Exploited Vulnerabilities (KEV) Catalog and SSVC data while considering asset exposure, exploit automation, and technical impact. It establishes a three-phase rollout—immediate policy updates and automation (Phase I), process updates within 60 days (Phase II), and vulnerability remediation within 180 days (Phase III)—with automated reporting via the Continuous Diagnostics and Monitoring program and ongoing Cyber Hygiene practices. The directive supersedes BOD 19-02 and 22-01, aligns with OMB Circular A-130 and FISMA, and aims to harden federal networks against sophisticated cyber threats by focusing on high-risk vulnerabilities and maintaining asset tagging and exposure data.

CISA sidelined as White House coordinates AI-era cyber response
technology3 months ago

CISA sidelined as White House coordinates AI-era cyber response

CISA is shrinking and largely sidelined as the White House forges a multi-agency AI cyber response, raising concerns about protection of critical infrastructure amid fears that AI-enabled attackers could exploit gaps. The agency has faced staffing and budget cuts, leaving leadership and bench strength diminished, even as plans surface for a staffing surge and a coordinated vulnerability-management role in the broader effort.