Tag: cisa
-
Sophos Touts Plans to Fulfill CISA’s Secure by Design Pledge
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/sophos-touts-plans-to-fulfill-cisas-secure-by-design-pledge
-
CISA offers tools to promote secure use of open-source software
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/cisa-offers-tools-to-promote-secure-use-of-open-source-software
-
CISA Advises Against Paying Ransom, But Rules Out a Ban
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/say-no-to-paying-ransom-cisa-director
-
Secure by design: How organizations are fulfilling the CISA pledge
Tags: cisaFirst seen on scmagazine.com Jump to article: www.scmagazine.com/resource/secure-by-design-how-organizations-are-fulfilling-the-cisa-pledge
-
CISA urges devs to weed out OS command injection vulnerabilities
‹CISA and the FBI urged software companies on Wednesday to review their products and eliminate path OS command injection vulnerabilities before shippi… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-urges-devs-to-weed-out-os-command-injection-vulnerabilities/
-
U.S. CISA adds Microsoft Windows and Rejetto HTTP File Server bugs to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows and Rejetto HTTP File Server bugs to its Known Exploited Vulnerabi… First seen on securityaffairs.com Jump to article: securityaffairs.com/165513/security/cisa-adds-windows-rejetto-http-file-server-bugs-known-exploited-vulnerabilities-catalog.html
-
CISA warns about directory traversal vulnerabilities
On May 02, 2024, CISA and the FBI released a Security by Design alert to all software manufacturers and customers regarding an ongoing security vulner… First seen on securityintelligence.com Jump to article: securityintelligence.com/news/cisa-warns-directory-traversal-vulnerabilities/
-
ICS Patch Tuesday: Siemens, Schneider Electric, CISA Issue Advisories
Several ICS vendors released advisories on Tuesday to inform customers about vulnerabilities found in industrial and OT products. The post ICS Patch T… First seen on securityweek.com Jump to article: www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-cisa-issue-advisories/
-
CISA Adds Critical Zero-Day Vulnerabilities from July 2024 Patch Tuesday to Exploited List
CISA has added two zero-day vulnerabilities from the cluster of vulnerabilities fixed in this month’s patch Tuesday. In its latest patch Tuesday relea… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/known-exploited-vulnerabilities-catalog/
-
Chinese APT40 hackers hijack SOHO routers to launch attacks
An advisory by CISA and multiple international cybersecurity agencies highlights the tactics, techniques, and procedures (TTPs) of APT40 (aka Kryptoni… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-apt40-hackers-hijack-soho-routers-to-launch-attacks/
-
CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalog. Th… First seen on securityaffairs.com Jump to article: securityaffairs.com/165415/security/cisa-adds-cisco-nx-os-command-injection-bug-known-exploited-vulnerabilities-catalog.html
-
CISA Advances Open-Source Software Security with Strategic Initiatives and Community Collaboration
The Cybersecurity and Infrastructure Security Agency (CISA) has announced its next phase to enhance the security of open-source software (OSS) through… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-announces-open-source-software-security/
-
How CISA Plans to Measure Trust in Open-Source Software
Agency Is in 2nd Phase of Its Open-Source Software Security Road Map. The U.S. Cybersecurity and Infrastructure Security Agency provided details on Mo… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-cisa-plans-to-measure-trust-in-open-source-software-a-25723
-
CISA Report Finds Most Open-Source Projects Contain Memory-Unsafe Code
First seen on techrepublic.com Jump to article: www.techrepublic.com/article/open-source-projects-memory-unsafe-code-cisa/
-
Grassley wants more details on breach of CISA system
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/grassley-grills-cisa-on-incident-response
-
CISA Flags Memory-Unsafe Code in Major Open Source Projects
Despite more than 50% of all open source code being written in memory-unsafe languages like C++, we are unlikely to see a massive overhaul to codebase… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cisa-memory-unsafe-code-open-source-projects
-
CISA Releases Guidance on Network Access, VPNs
First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-releases-guidance-on-network-access-vpns
-
Majority of Critical Open Source Projects Contain Memory Unsafe Code
A CISA analysis in collaboration with international partners concluded most critical open source projects potentially contain memory safety vulnerabil… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-source-projects-memory-unsafe/
-
Threat Actor May Have Accessed Sensitive Info on CISA Chemical App
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/threat-actor-may-have-accessed-sensitive-info-on-cisa-chemical-app
-
CISA warnt: Angriffe auf kritische Lücke in Progress Telerik Report Server
First seen on heise.de Jump to article: www.heise.de/news/CISA-warnt-vor-Angriffen-auf-Progress-Telerik-Report-Server-9766190.html
-
CISA and Fauquier County Partner to Enhance K-12 School Safety with Active Shooter Exercise
CISA, in collaboration with the Fauquier County Sheriff’s Office, the Fauquier County Fire Rescue System, and Fauquier County Public Schools, recently… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/k-12-active-shooter-exercise/
-
CISA executive director discusses CIRCIA, incident reporting
Tags: cisaCISA Executive Director Brandon Wales speaks with TechTarget Editorial to discuss CIRCIA and the importance of incident reporting to the larger cybers… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366586239/CISA-executive-director-discusses-CIRCIA-incident-reporting
-
CISA’s Flags Memory-Unsafe Code in Major Open Source Projects
Despite more than 50% of all open source code being written in memory-unsafe languages like C++, we are unlikely to see a massive overhaul to code bas… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cisa-memory-unsafe-code-open-source-projects
-
CISA adds GeoSolutionsGroup JAI-EXT, Linux Kernel, and Roundcube Webmail bugs to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GeoSolutionsGroup JAI-EXT, Linux Kernel, and Roundcube Webmail bugs to its Known Exp… First seen on securityaffairs.com Jump to article: securityaffairs.com/164982/security/cisa-geosolutionsgroup-jai-ext-linux-kernel-roundcube-webmail-known-exploited-vulnerabilities-catalog.html
-
CISA warnt: Kritischer PHP-Bug wird von Ransomware ausgenutzt
First seen on heise.de Jump to article: www.heise.de/news/CISA-warnt-Kritischer-PHP-Bug-wird-von-Ransomware-ausgenutzt-9762259.html
-
Chemical Facilities Warned of Possible Data Exfiltration Following CISA Breach
CISA has informed chemical facilities that its Chemical Security Assessment Tool (CSAT) was infiltrated by a malicious actor, and potentially exfiltra… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chemical-exfiltration-cisa-breach/
-
Most critical open source projects not using memory safe code
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-most-critical-open-source-projects-not-using-memory-safe-code/
-
CISA confirmed that its CSAT environment was breached in January.
CISA warned chemical facilities that its Chemical Security Assessment Tool (CSAT) environment was compromised in January. CISA warns chemical faciliti… First seen on securityaffairs.com Jump to article: securityaffairs.com/164905/data-breach/cisa-confirmed-csat-breach.html
-
Examining the US Government’s DDoS Protection Guidance Update
March 2024, CISA, MS-ISAC, and the FBI released updated DDoS response guidance. The document outlines key strategies and 15 steps for mitigating DDoS … First seen on hackread.com Jump to article: hackread.com/examining-us-govt-ddos-protection-guidance-update/
-
LockBit Ransomware Claims 33 TB of US Federal Reserve Data for Ransom
kBit ransomware claims to hold 33 TB of data from the US Federal Reserve for ransom. Hackread.com investigates, reaching out to CISA for comments on t… First seen on hackread.com Jump to article: hackread.com/lockbit-ransomware-us-federal-reserve-data-ransom/

