Skip to content

other

CISA

U.S. federal agency under DHS that protects critical infrastructure and government networks from cyber and physical threats, issuing advisories and guidance.

Known aliases

  • CISA
  • cisagov
  • cisa.gov
  • Cybersecurity and Infrastructure Security Agency
  • U.S. CISA
  • U.S. cybersecurity agency
  • US cybersecurity agency
  • U.S. Cybersecurity and Infrastructure Security Agency
  • US Cybersecurity and Infrastructure Security Agency
  • U.S. Cybersecurity & Infrastructure Security Agency

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 66%
Investor
Investor 7%

Reality

Evidence64
Adoption70
Hype gap+8
Incentives
Insufficient
Confidence62
security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
security5 publishers

Manufacturers selling into the EU now owe ENISA a 24-hour warning on exploited flaws

The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.

Publishers:commission.europa.eucsoonline.comdev.toscworld.comwebflow.sysdig.com

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence72
security8 publishers

Star Blizzard now sends its Ukraine lures from hacked WordPress and cPanel sites

Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.

Perspective Coverage

8 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence66
Adoption35
Hype gap+18
Incentives35
Confidence70
security4 publishers

Crafted emails give attackers shells on Zimbra servers running SNMP notifications

Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.

Perspective Coverage

4 publishers
Builder
Builder 21%
Operator
Operator 68%
Investor
Investor 11%

Reality

Evidence80
Adoption40
Hype gap+5
Incentives
Insufficient
Confidence75
security6 publishers

Warlock ransomware group narrows its targets to large Spanish- and Portuguese-speaking organizations

Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 59%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence68
build1 publisher

vm2's prefix allowlist let one approved module load its unapproved siblings

vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence58
security7 publishers

Fortinet tells FortiMail admins to disable IBE while an exploited CVSS 9.8 flaw awaits fixes

Fortinet says attackers are exploiting a CVSS 9.8 unauthenticated file-write flaw in FortiMail, and no fixed release has shipped yet. Until builds arrive, its two workarounds are the only protection, including for 7.2 users told to move to a 7.4 branch that is still unpatched.

Perspective Coverage

7 publishers
Builder
Builder 15%
Operator
Operator 82%
Investor
Investor 3%

Reality

Evidence78
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence74
security4 publishers

GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 59%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence74

Earlier coverage

  1. Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

    Security · October 2, 2026 · 3 publishers

  2. Gunra enters through the same VPN appliances the advisory says should front RDP

    Build · October 2, 2026 · 1 publisher

  3. DIVD traces its breach to two chained zero-days in its own Zammad helpdesk

    Security · October 1, 2026 · 8 publishers

  4. FBI and EPA pin the water-sector PLC attacks on controllers reachable from the open internet

    Build · October 2, 2026 · 1 publisher

  5. Two known-exploited Chromium V8 bugs lead September's 36 device CVEs beyond the kernel

    Build · October 1, 2026 · 1 publisher

  6. CISA says every version of Monta's charging platform lets attackers pose as EV chargers

    Security · October 1, 2026 · 1 publisher

  7. Crafted links could run script in users' sessions on CISA Malcolm before v26.06.0

    Security · October 1, 2026 · 1 publisher

  8. Armatura One's access-control software leaves a 2023 ActiveMQ flaw open to unauthenticated code execution

    Security · October 1, 2026 · 1 publisher

  9. ABB's PCM600 Scheduler Service gives standard users a route to LocalSystem control

    Security · October 1, 2026 · 1 publisher

  10. Johnson Controls EasyIO Neo controllers send building-system logins over plain HTTP

    Security · October 1, 2026 · 1 publisher

  11. CISA gives federal agencies until October 2 to patch Apple's exploited CoreGraphics flaw

    Security · September 30, 2026 · 9 publishers

  12. NetScaler compromise response has to unwind the controls the gateway concentrated

    Build · October 1, 2026 · 1 publisher

  13. How Gunra actors got into a network through a default SSL VPN admin password

    Build · October 1, 2026 · 1 publisher

  14. Triage and tuning decided which SOC caught CISA's red team

    Leadership · October 1, 2026 · 1 publisher

  15. Google traces most of 2026's exploitation growth to fast n-day weaponization

    Security · September 30, 2026 · 4 publishers

  16. OpenSSL patches a DTLS flaw that sends heap memory to unauthenticated peers

    Security · September 30, 2026 · 4 publishers

  17. NetScaler attackers tunnel into internal networks with a new Python proxy

    Security · September 30, 2026 · 21 publishers

  18. Attackers chain three JFrog Artifactory flaws to mint their own admin tokens

    Build · September 30, 2026 · 2 publishers

  19. A low-privilege LiteLLM key could run system commands through its MCP test endpoints

    Build · September 30, 2026 · 1 publisher

  20. WaterISAC speeds threat sharing for water utilities still running exposed, pre-cyber PLCs

    Security · September 30, 2026 · 1 publisher

  21. CISA gives federal agencies until October 2 to patch Apple's CoreGraphics flaw

    Build · September 29, 2026 · 1 publisher

  22. Two exploited Windows privilege escalations should go first in September's record Patch Tuesday

    Build · September 29, 2026 · 1 publisher

  23. Viidure dashcam platform exposes live footage and firmware through a publicly readable bucket

    Security · September 29, 2026 · 1 publisher

  24. Lantronix cellular gateway turns tampered update metadata into root code, CISA says

    Security · September 29, 2026 · 1 publisher

  25. CVE-2026-22755 opens 37 VIVOTEK camera models to remote command execution

    Security · September 29, 2026 · 1 publisher

  26. CISA publishes nine Anjvision YSSD-RTMP-H5 flaws with no fix planned

    Security · September 29, 2026 · 1 publisher

  27. Toptech TMS7 and TopHAT 7.6.3 let unauthenticated attackers export any database table

    Security · September 29, 2026 · 1 publisher

  28. Two NetScaler zero-days under active attack justify an outage outside the patch cycle

    Leadership · September 29, 2026 · 2 publishers

  29. Nvidia's Huang defends AI distillation as competition despite Treasury's July sanctions threat

    Invest · September 28, 2026 · 2 publishers

  30. Build number and SAML settings decide exposure to exploited NetScaler flaw CVE-2026-19490

    Security · September 28, 2026 · 1 publisher

  31. CISA wants NetScaler owners to check for intruders before installing Citrix's zero-day fixes

    Product · September 28, 2026 · 2 publishers

  32. Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

    Build · September 28, 2026 · 3 publishers

  33. Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection

    Security · September 25, 2026 · 4 publishers

  34. Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

    Security · September 27, 2026 · 3 publishers

  35. Meta ads steer Android users to fake Google Play pages carrying the RemControl banking trojan

    Security · September 25, 2026 · 4 publishers

  36. SharePoint flaw CVE-2026-65660 came under attack within days of Viettel's technical write-up

    Security · September 27, 2026 · 5 publishers

  37. Kiteworks asks customers to power down for nine hours to guard against zero-day attacks

    Invest · September 27, 2026 · 3 publishers

  38. Cisco email gateway flaw runs attacker SQL as root the moment it parses a message

    Build · September 27, 2026 · 1 publisher

  39. Putting KEV and EPSS ahead of CVSS lifts a 6.5 finding above a 9.1

    Build · September 26, 2026 · 1 publisher

  40. CISA's exploitation listing moves kernel flaw CVE-2026-53266 ahead of the monthly patch cycle

    Build · September 26, 2026 · 1 publisher