Tag: cisa
-
How to Automate CVE and Vulnerability Advisory Response with Tines
Run by the team at workflow orchestration and AI platform Tines, the Tines library features pre-built workflows shared by security practitioners from across the community – all free to import and deploy through the platform’s Community Edition.A recent standout is a workflow that automates monitoring for security advisories from CISA and other vendors, enriches advisories…
-
U.S. CISA adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws:…
-
CISA Issues New ICS Advisories Addressing Critical Vulnerabilities and Exploits
The Cybersecurity and Infrastructure Security Agency (CISA) has issued two new advisories revealing critical vulnerabilities found in widely used Industrial Control Systems (ICS). Released on May 1, 2025, the advisories spotlight severe security risks affecting KUNBUS GmbH’s Revolution Pi devices and the MicroDicom DICOM Viewer, with some vulnerabilities scoring the highest possible rating for risk…
-
CISA Issues Alert on Actively Exploited Apache HTTP Server Escape Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a newly discovered and actively exploited vulnerability in the widely used Apache HTTP Server. The flaw, catalogued as CVE-2024-38475, affects the server’s mod_rewrite module and poses significant risks to organizations worldwide. Details of the Vulnerability CVE-2024-38475 is classified as an >>improper escaping…
-
Planned CISA Cuts Face Political Delays and Growing Backlash
CISA Staff Told to Prepare for Cuts and Crowded Work Locations Amid Growing Turmoil. Top officials at the nation’s cyber defense agency want to give President Donald Trump’s pick to lead the agency time to assess major restructuring plans – a move that is reportedly delaying the timeline for reductions in force while causing growing…
-
Breach Roundup: Surge in Edge Device Zero-Day Exploits
Also, Baltimore Public Schools Suffer Data Breach, Disney Menu Hacker Sentenced. This week, zero-day exploits surged, accused Nefilim hacker extradited, Baltimore schools breach, CISA lists Broadcom Brocade, Commvault flaws, a fake WooCommerce patch, Akira hit Hitachi Vantara, ex-Disney worker sentenced and a Darcula phishing kit upgrade. FBI published 42,000 phishing domains. First seen on govinfosecurity.com…
-
The 14 most valuable cybersecurity certifications
Tags: access, ai, application-security, attack, automation, best-practice, blockchain, blueteam, china, cisa, cisco, ciso, cloud, compliance, computer, computing, conference, control, country, credentials, cryptography, cyber, cybersecurity, data, defense, encryption, endpoint, exploit, finance, governance, government, guide, hacker, hacking, incident response, intelligence, Internet, jobs, kali, law, linux, malware, metric, microsoft, monitoring, network, penetration-testing, privacy, reverse-engineering, risk, risk-analysis, risk-management, skills, threat, training, vulnerability, windowsIndustry recognition Who’s to say one certification is more respected than another? Such criteria can be very subjective, so we turned to the most direct and unbiased source to cut through the ambiguity: job listings. In addition to education, skills, and qualifications, employers often specify certs they seek in their ideal candidate. These mentions carry…
-
Homeland Secretary Noem Vows to Put CISA ‘Back to Focusing on its Core Mission’
Homeland Security Secretary Kristi Noem vowed to refocus CISA, especially in defense of critical systems threats from China. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/04/homeland-secretary-noem-vows-to-put-cisa-back-to-focusing-on-its-core-mission/
-
Former CISA Head Slams Trump Admin Over ‘Loyalty Mandate’
Tags: cisaJen Easterly, former director of CISA, discussed the first 100 days of the second Trump administration and criticized the president’s mandate for loyalty during a panel at RSAC 2025. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/former-cisa-head-slams-trump-admin-loyalty-mandate
-
CISA restructuring plan release date unknown and likely to be slowed by Plankey nomination
Tags: cisaActing CISA Director Bridget Bean acknowledged at a meeting with employees that the process of releasing of a plan to reduce and reorganize the agency’s workforce faces “multiple hurdles.” First seen on therecord.media Jump to article: therecord.media/cisa-restructuring-slowed-plankey-nomination
-
Congressional officials wonder how CISA can carry out core mission in face of workforce cuts
Staffers on the House Committee on Homeland Security indicate that workforce challenges, both within government and the private sector, demand immediate attention. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisa-workforce-cuts-concerns-cybersecurity-panel-rsac-2025/
-
Attacks involving Qualitia, Commvault, Broadcom bugs ongoing
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-attacks-involving-qualitia-commvault-broadcom-bugs-ongoing
-
CISA Flags Actively Exploited Flaws in Broadcom, Commvault, and Qualitia Products
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-flags-actively-exploited-flaws-in-broadcom-commvault-and-qualitia-products
-
Message to Kristi Noem: Now’s the worst possible time to weaken CISA
Tags: cisaFirst seen on scworld.com Jump to article: www.scworld.com/perspective/message-to-kristi-noem-nows-the-worst-possible-time-to-weaken-cisa
-
At RSAC, Kristi Noem calls to rein in CISA and reset DHS cyber strategy
First seen on scworld.com Jump to article: www.scworld.com/news/at-rsac-kristi-noem-calls-to-rein-in-cisa-and-reset-dhs-cyber-strategy
-
DHS secretary vows to refocus CISA, saying it strayed from mission
Tags: cisaKristi Noem said the agency should be focused on securing critical infrastructure. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/dhs-secretary-vows-to-refocus-cisa-saying-it-strayed-from-mission/746739/
-
Noem calls for reauthorization of cyberthreat information sharing law during RSA keynote
Noem also defended reducing the size of CISA, postponing the creation of a new headquarters for the agency and making other funding cuts or program changes at the organization. First seen on therecord.media Jump to article: therecord.media/kristi-noem-rsa-keynote-info-sharing-law
-
DHS Secretary Noem: CISA needs to get back to ‘core mission’
In an appearance at the 2025 RSAC Conference, the Homeland Security secretary said the cyber agency was too focused on being the “Ministry of Truth” under the previous administration. First seen on cyberscoop.com Jump to article: cyberscoop.com/kristi-noem-rsac-2025-cisa-mission/
-
U.S. CISA adds SAP NetWeaver flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SAP NetWeaver flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added SAP NetWeaver flaw, tracked as CVE-2025-31324, to its Known Exploited Vulnerabilities (KEV) catalog. Last week, researchers warned that a zero-day vulnerability, tracked asCVE-2025-31324(CVSS score of 10/10), in SAP NetWeaver is…
-
RSAC 2025 Sets A Dangerous Precedent for Cybersecurity Leadership
(I posted this on LI, but I like to own my content, so am also posting here.) The cybersecurity community deserves better than what we’re witnessing at RSAC 2025, today. While Kristi Noem delivers today’s keynote, the absence of traditional cybersecurity leaders from agencies like NSA and CISA speaks volumes about shifting priorities in our……
-
CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of Broadcom Brocade Fabric OS, Commvault web servers, and Qualitia Active! Mail clients vulnerabilities that are actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/
-
Brocade Fabric OS flaw could allow code injection attacks
Same KEV update included a Commvault flaw: CISA also added a high severity bugCVSS 8.7/10 affecting Commvault Web Server to its KEV Catalog, recommending patching under the same BOD directive.The flaw, tracked as CVE-2025-3928, is an unspecified vulnerability that can be exploited by a remote, authenticated attacker to execute webshells. All versions before 11.36.46, 11.32.89,…
-
Broadcom-backed SAN devices face code injection attacks via a critical Fabric OS bug
Same KEV update included a Commvault flaw: CISA also added a high severity bugCVSS 8.7/10 affecting Commvault Web Server to its KEV Catalog, recommending patching under the same BOD directive.The flaw, tracked as CVE-2025-3928, is an unspecified vulnerability that can be exploited by a remote, authenticated attacker to execute webshells. All versions before 11.36.46, 11.32.89,…
-
CISA warns about actively exploited Broadcom, Commvault vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new flaws to its Known Exploited Vulnerabilities catalog on Monday, affecting Commvault … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/04/29/cisa-warns-about-actively-exploited-broadcom-commvault-vulnerabilities-cve-2025-1976-cve-2025-3928/
-
U.S. CISA adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are…
-
CISA Adds Broadcom Brocade Fabric OS Flaw to Known Exploited Vulnerabilities List
Tags: advisory, cisa, cyber, cybersecurity, exploit, flaw, government, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent security advisory after adding a critical Broadcom Brocade Fabric OS vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw, tracked as CVE-2025-1976, affects Broadcom’s widely deployed Brocade Fabric OS and has drawn increased concern from government and enterprise security teams due to its…
-
CISA Adds Actively Exploited Broadcom and Commvault Flaws to KEV Database
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two high-severity security flaws impacting Broadcom Brocade Fabric OS and Commvault Web Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.The vulnerabilities in question are listed below -CVE-2025-1976 (CVSS score: 8.6) – A code injection flaw First…
-
Krebs: People should be ‘outraged’ at efforts to shrink federal cyber efforts
At the RSA Conference, former CISA chief Chris Krebs said recent efforts by China-linked hacking groups makes it more important than ever to grow the federal cyber workforce. First seen on therecord.media Jump to article: therecord.media/krebs-outrage-efforts-to-shrink-federal-cyber-workforce
-
Trump moves threaten US cyber defenses, says former CISA director Easterly
First seen on scworld.com Jump to article: www.scworld.com/brief/trump-moves-threaten-us-cyber-defenses-says-former-cisa-director-easterly

