Tag: cisa
-
CISA’s Acting Director Defends Cuts Amid Growing Turmoil
Top Cyber Official Says CISA Wants to Eliminate Duplication and Increase Efficiency. The acting director of the Cybersecurity and Infrastructure Security Agency told a House appropriations subcommittee Thursday the nation’s cyber defense agency was continuing to improve its ability to respond to growing threats from China despite budget cuts and looming workforce reductions. First seen…
-
CISA, FBI warn of ‘unsophisticated’ hackers targeting industrial systems
Federal authorities, including the EPA and the U.S. Department of Energy, urged network defenders to secure remote access and use stronger passwords. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-fbi-warn-hackers-targeting-industrial/747491/
-
CISA warns of cyberattacks targeting the US oil and gas infrastructure
Tags: advisory, cisa, control, cyberattack, cybersecurity, flaw, infrastructure, intelligence, Internet, network, open-source, password, risk, threatStronger passwords, segmentation, and manual operations are advised: CISA cited past analysis to emphasize that targeted systems use default or easily guessable (using open-source tools) passwords. Changing default passwords for strong and unique ones is important for public-facing internet devices that have the capability to control OT systems or processes, it added in the advisory.Segmenting…
-
U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GoVision device flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: According toBinding Operational Directive…
-
U.S. CISA adds FreeType flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds FreeType flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added a FreeType flaw, tracked as CVE-2025-27363 (CVSS score of 8.1), to its Known Exploited Vulnerabilities (KEV) catalog. In mid-March, Metawarnedthat the out-of-bounds write vulnerabilityCVE-2025-27363may have been actively exploited in attacks. “An out…
-
Trump’s ‘Grand Cyber Plan’ Coming Soon, Noem Tells Lawmakers
Homeland Security Secretary Accuses Cyber Agency of Failing to Stop China Hacks. U.S. President Donald Trump will shortly reveal a grand cyber plan, Homeland Security Secretary Kristi Noem told lawmakers Tuesday, even as the administration seeks to cut the Cybersecurity and Infrastructure Security Agency budget by $500 million. CISA’s mission is to hunt and harden,…
-
Researcher Says Patched Commvault Bug Still Exploitable
CISA added CVE-2025-34028 to its catalog of known exploited vulnerabilities, citing active attacks in the wild. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/researcher-patched-commvault-bug-exploitable
-
Lawmakers grill Noem over CISA funding cuts, demand Trump cyber plan
House members pushed Homeland Security Secretary Kristi Noem for answers about a large proposed cut to CISA spending and a promised national cybersecurity plan from the White House. First seen on therecord.media Jump to article: therecord.media/noem-house-hearing-proposed-cisa-funding-cuts
-
House appropriators have reservations, or worse, about proposed CISA cuts
Tags: cisaA top Republican said lawmakers needed more information about the proposed reductions, while Democrats were more searing in their criticisms. First seen on cyberscoop.com Jump to article: cyberscoop.com/house-questions-trump-cisa-budget-cuts-2025/
-
CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation
The vulnerabilities affect SonicWall’s SMA devices for secure remote access, which have been heavily targeted by threat actors in the past. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation
-
U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added a Langflow flaw, tracked as CVE-2025-3248 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. Langflow is a popular tool used for building agentic AI workflows. CVE-2025-3248 is a…
-
RCE flaw in tool for building AI agents exploited by attackers (CVE-2025-3248)
A missing authentication vulnerability (CVE-2025-3248) in Langflow, a web application for building AI-driven agents, is being exploited by attackers in the wild, CISA has … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/05/06/langflow-cve-2025-3248-exploited/
-
CISA Issues Alert on Langflow Vulnerability Actively Exploited in Attacks
Tags: attack, cisa, cyber, cybersecurity, exploit, flaw, framework, infrastructure, malicious, open-source, risk, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding an actively exploited vulnerability in Langflow, a popular open-source framework for building language model applications. Tracked as CVE-2025-3248, the flaw allows unauthenticated attackers to execute malicious code remotely, posing significant risks to organizations using the platform. Vulnerability Details The critical flaw resides in Langflow’sapi/v1/validate/codeendpoint,…
-
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
Tags: cisa, cve, cvss, cybersecurity, exploit, flaw, infrastructure, kev, open-source, vulnerabilityA recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation.The vulnerability, tracked as CVE-2025-3248, carries a CVSS score of 9.8 out of a maximum of 10.0.”Langflow contains a missing First…
-
CISA slammed for role in ‘censorship industrial complex’ as budget faces possible $500M cut
Because who needs cybersecurity when there’s culture wars to win First seen on theregister.com Jump to article: www.theregister.com/2025/05/06/cisa_budget_cuts/
-
Almost $500M cut in CISA funding proposed by Trump admin
Tags: cisaFirst seen on scworld.com Jump to article: www.scworld.com/brief/almost-500m-cut-in-cisa-funding-proposed-by-trump-admin
-
CISA Faces Deep Cuts in Proposed 2026 Budget
Tags: cisaFirst seen on scworld.com Jump to article: www.scworld.com/brief/cisa-faces-deep-cuts-in-proposed-2026-budget
-
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog, a little over a week after it was publicly disclosed.The vulnerability in question is CVE-2025-34028 (CVSS score: 10.0), a path traversal bug that affects 11.38 Innovation Release, from versions First…
-
U.S. CISA adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws:…
-
White House Cyber Chief Urges Offensive Response to Threats
National Security Council’s Bulazel to Reset Cyber Norms With Offensive Strategy. National Security Council’s Alexei Bulazel told RSA attendees that offensive cyber tools must play a bigger role in U.S. defense. He called for a streamlined regulatory approach, more robust interagency coordination and a narrower role for CISA focused on critical infrastructure and civilian agencies.…
-
DHS Head Noem Puts Focus on CISA as Trump Targets Krebs Again
Tags: cisaFirst seen on scworld.com Jump to article: www.scworld.com/news/dhs-head-noem-puts-focus-on-cisa-as-trump-targets-krebs-again
-
RSAC 2025: Ex-CISA head Krebs defiantly urges infosec community to keep up the good fight
First seen on scworld.com Jump to article: www.scworld.com/news/rsac-2025-ex-cisa-head-krebs-defiantly-urges-infosec-community-to-keep-up-the-good-fight
-
Uncertainties surround finalization of CISA restructuring plan
Tags: cisaFirst seen on scworld.com Jump to article: www.scworld.com/brief/uncertainties-surround-finalization-of-cisa-restructuring-plan
-
Trump proposes major cut to CISA’s budget, citing false ‘censorship’ claims
The president’s budget proposal repeated a debunked claim about the nation’s cyber agency engaging in censorship. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/trump-cisa-budget-cuts-disinformation/747047/
-
Trump administration proposes cutting $491M from CISA budget
Tags: cisaA budget summary doesn’t give specific details on which programs it would cut, instead providing a broad outline. First seen on cyberscoop.com Jump to article: cyberscoop.com/trump-administration-proposed-cisa-budget-cuts/
-
White House Proposes $500 Million Cut to CISA
Administration’s Budget Proposals Would Slash Cyber Defense Agency Spending by 16%. President Donald Trump proposed a series of budget cuts Friday that would in part reduce the Cybersecurity and Infrastructure Security Agency’s spending for fiscal year 2026 by nearly $500 million – a 16% reduction the administration said was aimed at realigning the agency with…
-
Cut CISA and Everyone Pays for It
Tags: cisaGutting CISA won’t just lose us a partner. It will lose us momentum. And in this game, that’s when things break. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cut-cisa-everyone-pays
-
CISA Adds Two New Exploited Vulnerabilities to Its Catalog: CVE-2024-38475 and CVE-2023-44221
The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding two vulnerabilities, CVE-2024-38475 and CVE-2023-44221, that are currently being actively exploited. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-adds-cve-2024-38475-and-cve-2023-44221/
-
CISA Confirms Exploitation of SonicWall Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency has added two flaws affecting SonicWall products to its catalog of Known Exploited Vulnerabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-exploitation-sonicwall/

