
CISA issues directive to secure and disconnect risky network devices.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a binding operational directive to scan federal agency networks for web-connected "networked management interfaces" that have become a key vulnerability in recent cyber exploits. CISA will notify agencies of any findings regarding web-connected interfaces and agencies have 14 days to remove the interface from the internet or deploy capabilities as part of a zero trust architecture. The directive does not apply to web applications and interfaces used for managing Cloud Service Provider offerings.