Tag CISA

Local Man Unintentionally Hacks 6,700 Camera-Equipped Robot Vacuums

Congressional Investigation Reveals $20.9 Billion in Losses from Data Breaches This week, Congressional Democrats on the Joint Economic Committee published a report revealing an alarming $20.9 billion in consumer losses attributed to identity theft linked to four significant data breaches involving data broker companies. The investigation, initiated by U.S. Senator…

Read MoreLocal Man Unintentionally Hacks 6,700 Camera-Equipped Robot Vacuums

Iranian Hackers Breach U.S. Federal Agency Network via Log4Shell Exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported a security breach involving a federal agency, attributed to threat actors affiliated with the Iranian government. The attackers exploited the Log4Shell vulnerability found in an unpatched VMware Horizon server, demonstrating a sophisticated exploitation technique. The breach, which occurred between mid-June…

Read MoreIranian Hackers Breach U.S. Federal Agency Network via Log4Shell Exploit

CISA Alerts on Ongoing Attacks Targeting Vulnerabilities in Fortra MFT, TerraMaster NAS, and Intel Drivers

On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) catalog, identifying three flaws currently being actively exploited. This addition underscores the persistent threat landscape faced by organizations, especially those in critical sectors. Among the newly acknowledged vulnerabilities is CVE-2022-24990, which affects TerraMaster network-attached…

Read MoreCISA Alerts on Ongoing Attacks Targeting Vulnerabilities in Fortra MFT, TerraMaster NAS, and Intel Drivers

CISA Expands KEV Catalog with Three New Vulnerabilities

On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the inclusion of three significant vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog. This decision follows emerging evidence of active exploitation affecting specific target systems. The identified vulnerabilities include: CVE-2022-47986, a code execution flaw in IBM Aspera Faspex (CVSS…

Read MoreCISA Expands KEV Catalog with Three New Vulnerabilities

Microsoft Releases Patches for 80 Vulnerabilities, Including Two Currently Under Attack

In its March 2023 Patch Tuesday update, Microsoft disclosed fixes for 80 security vulnerabilities, two of which have been actively exploited in the wild. These vulnerabilities target critical components within the Microsoft ecosystem, with eight categorized as Critical, 71 as Important, and one as Moderate in severity. This update continues…

Read MoreMicrosoft Releases Patches for 80 Vulnerabilities, Including Two Currently Under Attack

DHS Funding Gap Could Ground Federal Cybersecurity Personnel

Government, Industry Specific Acting Chief Informs Lawmakers of Potential Furloughs Amid Funding Uncertainty Chris Riotta (@chrisriotta) • February 11, 2026 In a critical address to Congress, CISA’s acting director, Madhu Gottumukkala, highlighted the severe implications of a funding lapse for the Cybersecurity and Infrastructure Security Agency. If Congress fails to…

Read MoreDHS Funding Gap Could Ground Federal Cybersecurity Personnel

CISA Updates KEV Catalog with 3 Actively Exploited Vulnerabilities, Featuring Critical PaperCut Flaw

On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three security flaws, highlighting the urgent need for businesses to address vulnerabilities currently being exploited in the wild. The newly identified vulnerabilities include CVE-2023-28432, a significant information disclosure issue affecting MinIO,…

Read MoreCISA Updates KEV Catalog with 3 Actively Exploited Vulnerabilities, Featuring Critical PaperCut Flaw

Warning: Ongoing Exploitation of Vulnerabilities in TP-Link, Apache, and Oracle Identified

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified and added three security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting concerns over active exploitation. These vulnerabilities pose significant risks to various systems and require immediate attention from cybersecurity professionals. The first vulnerability, CVE-2023-1389, carries a CVSS score…

Read MoreWarning: Ongoing Exploitation of Vulnerabilities in TP-Link, Apache, and Oracle Identified

CISA Releases Advisory on Critical Remote Code Execution Vulnerability Impacting ME RTU Remote Terminal Units

On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a critical advisory highlighting a serious vulnerability impacting ME RTU remote terminal units. This flaw, identified as CVE-2023-2131, has been assigned a maximum severity score of 10.0 on the Common Vulnerability Scoring System (CVSS), underscoring its potential for exploitation…

Read MoreCISA Releases Advisory on Critical Remote Code Execution Vulnerability Impacting ME RTU Remote Terminal Units