Tag

Cisa

All articles tagged with #cisa

GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
security6 days ago

GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab has released patches for CVE-2026-90970, a critical vulnerability in its AI Gateway service that allows authenticated users to execute arbitrary commands. The flaw, rated 9.9 on the CVSS scale, affects only self-hosted instances; GitLab-managed services are already secured. Users must update to versions 19.2.4, 19.3.2, or 19.4.1 immediately.

Apple Patches Critical Zero-Day Flaw in CoreGraphics After Targeted Attacks
technology8 days ago

Apple Patches Critical Zero-Day Flaw in CoreGraphics After Targeted Attacks

Apple released emergency updates for iOS and macOS to fix CVE-2026-86950, a critical out-of-bounds write vulnerability in the CoreGraphics framework. The flaw, which allows arbitrary code execution, is being actively exploited in 'extremely sophisticated' attacks against specific individuals. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch the issue by October 2. While Apple credited Meta with discovering the flaw, security researchers have published a proof-of-concept that suggests a malicious PDF could trigger the bug, potentially via WhatsApp.

politics16 days ago

CISA Launches 'Securing the Next 250' Plan to Aid State Election Security Before Midterms

The Cybersecurity and Infrastructure Security Agency (CISA) released a 13-page plan titled 'Securing the Next 250' on September 24, 2026, offering free cybersecurity resources to state and local election officials ahead of the midterm elections. This marks the first public election security initiative from CISA since the Trump administration scaled back such efforts in 2025. The plan provides penetration testing, vulnerability scanning, and tabletop exercises for election infrastructure stakeholders, including polling places and ballot storage facilities. Homeland Security Secretary Markwayne Mullin called the plan crucial for ensuring free and fair elections, while CISA Acting Director Nick Andersen emphasized a holistic approach to securing critical networks. The announcement comes weeks before the midterms, which will determine congressional control and offer insights into security challenges for the 2028 presidential race.

CISA Mandates Urgent Patching for Three Actively Exploited Linux Kernel Flaws
cybersecurity17 days ago

CISA Mandates Urgent Patching for Three Actively Exploited Linux Kernel Flaws

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch them by September 23, 2026. The flaws, ranging from medium to critical severity, are being actively exploited in the wild. While CISA has not disclosed details about the threat actors, Red Hat and other vendors have confirmed public exploits exist for two of the issues. The most critical flaw, CVE-2025-39964, has existed in the kernel for 14 years and allows for privilege escalation and container escape.

CISA Maps 17 Attack Techniques Targeting Active Directory
cybersecurity23 days ago

CISA Maps 17 Attack Techniques Targeting Active Directory

CISA released a guide detailing 17 techniques commonly used by attackers to compromise Active Directory, highlighting AD as a critical attack surface and outlining defender-focused mitigations such as least-privilege access, MFA, credential hygiene, disabling legacy protocols, and continuous monitoring of authentication and privilege activity.

CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706
security26 days ago

CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706

CISA warns that attackers are probing for and could exploit CVE-2026-85706, a maximum-severity GitLab path-traversal flaw that allows unauthenticated access to credentials via the repository commits API. GitLab fixed the issue in CE/EE versions 19.3.2, 19.2.6, and 19.1, and organizations are urged to patch immediately as in-the-wild probes have been observed and the flaw was added to the actively exploited catalog.

Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes
security1 month ago

Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes

Two parallel CISA red-team assessments against two critical infrastructure orgs produced opposite results: Org A was fully compromised at the domain level with access to sensitive business systems and cloud resources, while Org B detected the phishing quickly and cut off command-and-control, then reproduced access via an assume-breach test. The common weaknesses—cleartext credentials, misconfigured AD CS, default machine account quota, static cloud keys, and over-permissioned Entra ID—are attributed more to people and processes than to tools.

Water-Utility Cyberattacks Surge Beyond Early Reports, 100+ Targets Confirmed
technology1 month ago

Water-Utility Cyberattacks Surge Beyond Early Reports, 100+ Targets Confirmed

A month after a cyberattack on U.S. water facilities began, federal authorities say the scope was far larger than first reported: more than 100 water providers across 12 states were targeted, many via PLCs connected to cellular modems. Experts say underfunded, smaller utilities struggle to detect incidents, and investigators attribute the operations to Iranian-state actors. The assault affected systems coast-to-coast, including Wisconsin, Michigan and Minnesota, with Illinois not listed in the official tally.

CISA imposes 3-day patch window for critical Oracle vulnerability
security1 month ago

CISA imposes 3-day patch window for critical Oracle vulnerability

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog, giving federal agencies a three‑day deadline to patch a critical Oracle flaw in Oracle HTTP Server and WebLogic Proxy Plug‑in on Windows VMs that can grant full data access. Oracle released patches in January 2026 for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); private-sector researchers reported active exploitation attempts, underscoring the urgency of patching.

CISA orders rapid patch for actively exploited Zimbra flaw
security1 month ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns
security2 months ago

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns

CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.

Is Iran Behind U.S. Water-Hacking? Attribution Still Unclear
technology2 months ago

Is Iran Behind U.S. Water-Hacking? Attribution Still Unclear

Minnesota reported a coordinated cyber-attack on over 30 water systems, with seven states affected and investigators probing a possible Iranian link. Iran denies involvement, but experts point to Iran-linked groups such as Handala, and attribution remains uncertain. The main concern is eroding public trust in critical services, while authorities urge immediate security upgrades, including disconnecting water systems from the internet and resetting passwords.

Coordinated cyberattack disrupts U.S. water systems across several states
technology2 months ago

Coordinated cyberattack disrupts U.S. water systems across several states

Hackers coordinated an attack on water facilities in multiple states, forcing boil-water notices and switching to manual operation as systems go offline. No drinking-water contamination has been reported, but the incident is being treated as one of the most serious cyberattacks on U.S. water infrastructure in years. Minnesota first flagged attacks on about 30 systems, with Wisconsin and others reporting related incidents; federal agencies (CISA, FBI, EPA) are scrambling to secure vulnerable PLCs and facilities. Attribution remains uncertain, though Iran is among suspected actors. Experts warn the water sector’s cybersecurity remains underfunded and under-defended against such intrusions.

Federal warning: Hackers now targeting U.S. water systems, Minnesota among those affected
technology2 months ago

Federal warning: Hackers now targeting U.S. water systems, Minnesota among those affected

U.S. federal agencies warn of a rise in cyberattacks on water systems, with more than 30 Minnesota facilities impacted. Attackers are compromising internet-facing PLCs to disrupt water production and distribution, though drinking water safety has not yet been breached; authorities urge operators to disconnect internet exposure, enforce strong passwords, and allow remote access only through a VPN or gateway. Attribution remains uncertain, though some officials point to Iranian-style patterns. Upgrading aging systems is costly, potentially driving funding needs and new cybersecurity rules from lawmakers.

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach
technology2 months ago

CISA warns of surge in cyberattacks on U.S. water systems after Minnesota breach

CISA warns of a rising trend of hackers targeting U.S. water and wastewater facilities by manipulating PLCs and changing passwords to lock operators, prompting boil-water notices and manual operation. Minnesota reported a coordinated attack affecting more than 30 community water systems earlier this week, with investigators briefly weighing a possible Iran link; the overall water infrastructure remains vulnerable as probes continue.