Tag: cisa
-
CISA discloses Sisense breach, customer data compromised
CISA is investigating a breach of data analytics vendor Sisense that may have exposed customers’ credentials and secrets and could impact critical inf… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366580595/CISA-discloses-Sisence-breach-customer-data-compromised
-
#RSAC: CISA Launches Vulnrichment Program to Address NVD Challenges
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-launches-vulnrichment-program/
-
Secure by Design: CISA und FBI warnen vor Directory-Traversal-Lücken
Tags: cisaFirst seen on heise.de Jump to article: www.heise.de/news/Secure-by-Design-CISA-und-FBI-warnen-vor-Directory-Traversal-Luecken-9707177.html
-
CISA in a flap as Chirp smart door locks can be trivially unlocked remotely
Tags: cisaFirst seen on theregister.com Jump to article: www.theregister.com/2024/04/15/critical_vulnerability_chirp_lock/
-
CISA urges software devs to weed out path traversal vulnerabilities
First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-urges-software-devs-to-weed-out-path-traversal-vulnerabilities/
-
CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities
CISA and the FBI warn of threat actors abusing path traversal software vulnerabilities in attacks targeting critical infrastructure. The post the FBI… First seen on securityweek.com Jump to article: www.securityweek.com/cisa-fbi-urge-organizations-to-eliminate-path-traversal-vulnerabilities/
-
Critical GitLab account takeover flaw added to CISA’s KEV Catalog
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/critical-gitlab-account-takeover-flaw-added-to-cisas-kev-catalog
-
Accelerated patching found with CISA KEV catalog-listed flaws
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/accelerated-patching-found-with-cisa-kev-catalog-listed-flaws
-
CISA adds GitLab flaw to its Known Exploited Vulnerabilities catalog
CISA adds GitLab Community and Enterprise Editions improper access control vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybe… First seen on securityaffairs.com Jump to article: securityaffairs.com/162646/security/gitlab-known-exploited-vulnerabilities-catalog.html
-
Immediate GitLab account takeover flaw remediation crucial amid attacks
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/cisa-immediate-gitlab-account-takeover-flaw-remediation-crucial-amid-attacks
-
New CISA incident reporting draft rule deemed excessive
Tags: cisaFirst seen on scmagazine.com Jump to article: www.scmagazine.com/brief/new-cisa-incident-reporting-draft-rule-deemed-excessive
-
1,400 GitLab Servers Impacted by Exploited Vulnerability
CISA says a critical GitLab password reset flaw is being exploited in attacks and roughly 1,400 servers have not been patched. The post s a critical G… First seen on securityweek.com Jump to article: www.securityweek.com/1400-gitlab-servers-impacted-by-exploited-vulnerability/
-
CISA says GitLab account takeover bug is actively exploited in attacks
‹CISA warned today that attackers are actively exploiting a maximum-severity GitLab vulnerability that allows them to take over accounts via password … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-says-gitlab-account-takeover-bug-is-actively-exploited-in-attacks/
-
CISA guidelines to protect critical infrastructure against AI-based threats
The US government’s cybersecurity agency CISA published a series of guidelines to protect critical infrastructure against AI-based attacks. CISA colla… First seen on securityaffairs.com Jump to article: securityaffairs.com/162565/security/cisa-guidelines-infrastructure-ai-based-attacks.html
-
Defending infrastructure, securing systems key to CISA’s new AI guidelines
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/defending-infrastructure-securing-systems-key-to-cisas-new-ai-guidelines
-
GitLab Hackers Use ‘Forgot Your Password’ to Hijack Accounts
US CISA Orders Federal Agencies to Apply January Patch. The U.S. federal government’s cybersecurity agency warned that hackers are exploiting a vulner… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/gitlab-hackers-use-forgot-your-password-to-hijack-accounts-a-24991
-
CISA warnt: Microsoft Smartcreen- und Gitlab-Sicherheitslücke werden angegriffen
First seen on heise.de Jump to article: www.heise.de/news/Angreifer-umgehen-Microsoft-Smartscreen-und-brechen-in-Gitlab-ein-9705715.html
-
Over 850 Vulnerable Devices Secured Through CISA Ransomware Program
CISA’s RVWP program sent 1754 ransomware vulnerability notifications to government and critical infrastructure entities in 2023, leading to 852 device… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/vulnerable-devices-secured-cisa/
-
CISA Rolls Out New Guidelines to Mitigate AI Risks to US Critical Infrastructure
New CISA guidelines categorize AI risks into three significant types and pushes a four-part mitigation strategy. The post guidelines categorize AI ri… First seen on securityweek.com Jump to article: www.securityweek.com/cisa-rolls-out-new-guidelines-to-mitigate-ai-risks-to-us-critical-infrastructure/
-
Updated CISA exploited vulnerabilties catalog includes Windows print spooler bug
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/updated-cisa-exploited-vulnerabilties-catalog-includes-windows-print-spooler-bug
-
Roku Breach Hits 567,000 Users
Plus: Apple warns iPhone users about spyware attacks, CISA issues an emergency directive about a Microsoft breach, and a ransomware hacker tangles wit… First seen on wired.com Jump to article: www.wired.com/story/roku-breach-hits-567000-users/
-
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog
CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure… First seen on securityaffairs.com Jump to article: securityaffairs.com/162308/security/cisa-adds-cisco-asa-and-ftd-and-crushftp-vfs-flaws-to-its-known-exploited-vulnerabilities-catalog.html
-
CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructur… First seen on securityaffairs.com Jump to article: securityaffairs.com/162295/hacking/cisa-adds-microsoft-windows-print-spooler-flaw-to-its-known-exploited-vulnerabilities-catalog.html
-
CISA to deploy automated vulnerability warning program by year end
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/cisa-to-deploy-automated-vulnerability-warning-program-by-year-end
-
SQL injection vulnerability in Fortinet software under attack
Fortinet and CISA confirmed CVE-2023-48788 is being actively exploited. But the Shadowserver Foundation found that many vulnerable instances remain on… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366575417/SQL-injection-vulnerability-in-Fortinet-software-under-attack
-
CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation
CISA warns organizations of a two-year-old Windows Print Spooler vulnerability being exploited in the wild. The post ns organizations of a two-year-ol… First seen on securityweek.com Jump to article: www.securityweek.com/cisa-warns-of-windows-print-spooler-flaw-after-microsoft-sees-russian-exploitation/
-
US says Russian hackers stole federal government emails during Microsoft cyberattack
CISA said the latest theft of government email , blamed on Russian government hackers , presents a grave and unacceptable risk to U.S. federal agencie… First seen on techcrunch.com Jump to article: techcrunch.com/2024/04/11/us-cisa-russia-apt-29-government-email-theft-microsoft/
-
CISA Announces Malware Next-Gen Analysis for Public Access
Have you ever downloaded a file and wondered if it’s safe? Now, there’s a powerful new weapon in the fight against malware thanks to the Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/cisa-announces-malware-next-gen-analysis-for-public-access/
-
Response to CISA Advisory (AA24-109A): #StopRansomware: Akira Ransomware
AttackIQ has released a new attack graph in response to the recently published CISA Advisory (AA24-109A) which disseminates known Tactics, Techniques,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/response-to-cisa-advisory-aa24-109a-stopransomware-akira-ransomware/
-
CISA und Europol teilen wichtige Details im Kampf gegen Akira-Ransomware
Die Cyberkriminellen hinter Akira erpressen weltweit Millionenbeträge. In einem Beitrag verschiedener Institutionen gibt es wichtige Fakten zur Abwehr… First seen on heise.de Jump to article: www.heise.de/news/CISA-und-Europol-teilen-wichtige-Details-im-Kampf-gegen-Akira-Ransomware-9690899.html

