Skip to main content

Tag: cisa

398 articles

Hospital corridor with staff, equipment, and furniture, conveying disruption and concern.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs

The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

Analyst 207
Hospital corridor with people walking, computer workstation, and door in background.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

Analyst 207
Blurred webpage on a laptop screen on a cluttered desk in a modern office workspace.

CISA Mandates Swift Fix for Exploited Ray RCE Flaw

A critical bug in the Ray framework, scoring 9.4 under CVSS v4, can be exploited for remote code execution with a simple visit to a malicious web page or hostile ad in Firefox or Safari. This vulnerability can be triggered when an attacker crafts requests that appear browser-originated, allowing for a potentially disastrous security breach.

Analyst 207
Cluttered office workstation with laptop and monitor on desk.

Ransomware gangs exploit Windows Task Host flaw

Ransomware gangs are exploiting a high-severity flaw in Windows Task Host, a core component that could allow them to escalate privileges and wreak havoc on your system. This vulnerability, already patched by Microsoft, poses significant risks to users, especially those with basic user permissions.

Analyst 207
Laptop screen shows blurred web browser with network router in background.

CISA Warns of Actively Exploited Ray Flaw Enabling Browser-Based RCE

A critical vulnerability, CVE-2025-62593, is under active exploitation, allowing hackers to execute remote code through web browsers like Firefox and Safari by using a clever DNS rebinding attack. This high-severity flaw, with a CVSS score of 9.4, stems from a weakness in the Ray project's defenses against browser-based attacks.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit server room.

Ransomware gangs exploit Microsoft SharePoint flaw

Ransomware gangs are actively exploiting a high-severity Microsoft SharePoint flaw, known as CVE-2026-45659, that allows them to execute arbitrary code on unpatched servers, and it's crucial to patch up ASAP to avoid falling victim. Microsoft has already released security updates for affected SharePoint versions, so make sure to get those installed pronto!

Analyst 207
Modern office setting with idle computers, hinting at disruption or concern.

US, South Korea Warn of Gunra Ransomware Gang's Global Reach

US and South Korean authorities are sounding the alarm on the global threat of the Gunra Ransomware Gang, warning that this malicious group has evolved into a sophisticated ransomware-as-a-service operation. The joint advisory aims to alert network defenders to the gang's growing reach and devastating impact on organizations worldwide.

Analyst 207
Network operations center equipment rack with loadmaster device and cabling.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

Analyst 207
Server terminal on a rack with generic screen, amidst technical infrastructure.

CISA Warns of Active TeamCity Exploit

Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.

Analyst 207
Blurred industrial control system in foreground, with brightly-lit equipment rows in the background.

IBM Langflow AI Platform Under Active Exploitation

A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

Analyst 207
Modern tech facility with server racks in background and laptop in foreground.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws

A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

Analyst 207
Rack of computer equipment with monitors in a neutral industrial setting.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws

Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

Analyst 207
Rows of routers and switches in a neutral-colored room with natural light from a large window in the background.

Chinese Telecoms Persist in US Market Despite Regulatory Crackdowns

Despite efforts by US regulators to shut them down, Chinese telecoms like China Mobile International continue to find ways to operate in the US market, with recent routing data showing their networks still appearing in paths to servers linked to malicious activity, including 192 instances of connections to Salt Typhoon servers in just a few days. This persistence raises concerns about the reach and resilience of these companies in the US.

Analyst 207
Government IT operations room with equipment and terminals, daylight through a window, and a blurred cyber threat…

CISA Warns of Active N-able Flaw Exploit in Federal Agencies

Exploiting the N-able flaw can give attackers unrestricted control over your N-central console, putting your entire operation at risk. Federal agencies have just three days to patch this high-severity vulnerability, tracked as CVE-2026-18577, under CISA's Binding Operational Directive 26-04.

Analyst 207
Server room with rows of equipment, a single server highlighted, and a laptop screen showing a blank management interface.

CISA Flags N-able N-central Flaw as Exploited Vulnerability

A critical flaw in N-able N-central has been flagged by CISA as an exploited vulnerability, allowing attackers to bypass authentication and take over accounts. This weakness, known as CVE-2026-18577, lets hackers gain admin access to vulnerable servers and deploy malicious persistence mechanisms.

Analyst 207
Water treatment plant control room with industrial systems and equipment.

CISA Warns of Targeted Cyberattacks on US Water Utilities

CISA is sounding the alarm: if your water utility's programmable logic controllers are exposed to the internet, you're a prime target for cyberattacks - so take action now and remove them from public exposure to safeguard your operations.

Analyst 207
Government agency office with a person working on a laptop at a conference table.

CISA Issues Guidance on Open-Source Software Security Risks

The Cybersecurity and Infrastructure Security Agency is stepping up to help manage open-source software security risks with a new guidebook titled "Open Source Software: Security Principles and Practices". This move aims to enhance the nation's cybersecurity by providing federal agencies with essential security recommendations.

Analyst 207
Control room with industrial controllers, sensors, and machinery in a neutral-colored environment.

US, Australia Urge Critical Infrastructure to Isolate Vital Systems During Cyberattacks

Stay ahead of cyber threats: the US and Australia are urging critical infrastructure operators to isolate vital systems during cyberattacks to minimize damage and protect essential services. A new advisory provides practical guidance on how to plan for and execute a safe disconnection from vulnerable networks.

Analyst 207
Outdated VPN server equipment sits in a government office with ambient daylight.

Wyden Urges Feds to Phase Out Insecure Public-Facing VPNs

Senator Ron Wyden is calling on federal agencies to ditch outdated, vulnerable VPNs and upgrade to modern, secure remote-access technology to protect against devastating cyberattacks. In a letter to top officials, he urged a coordinated effort to safeguard government employees' remote access and prevent further breaches.

Analyst 207
Brightly-lit industrial control system terminal on a factory floor.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

Analyst 207
Formal meeting setting with attendees seated around a podium or conference table, surrounded by natural daylight from large…

CISA Faces Industry Pushback on Cyber Incident Reporting Rule

Industry leaders are pushing back on a proposed cyber incident reporting rule, arguing it casts too wide a net, with one critic saying it would ensnare far too many companies. The rule, aimed at bolstering national security, has sparked concerns about its broad scope and reporting requirements.

Analyst 207
Government agency conference room with long table, chairs, and blank circular plaque on wall, flooded with natural daylight.

CISA Overhauls Cybersecurity Collaboration with ANCHOR-CI Framework

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a game-changing collaboration framework, ANCHOR-CI, to revolutionize how the federal government and private partners work together to protect critical infrastructure. This fresh approach replaces the two-decade-old CIPAC model, promising a more effective and resilient cybersecurity partnership.

Analyst 207
Government officials gather in a secure briefing room with a computer screen visible in the background.

Russian Hackers Exploit Zimbra Flaw for Widespread Email Theft

Russian hackers have exploited a Zimbra flaw, CVE-2025-66376, to steal emails from targeted organizations, allowing them to automatically collect a victim's last 90 days of email without requiring any interaction. This alarming vulnerability was weaponized by the Russian state-sponsored group Laundry Bear using a combination of phishing and specially crafted HTML emails.

Analyst 207
Brightly-lit industrial control room with various control systems and equipment in the background, hinting at network…

Iranian Hackers Expand Target Scope in US Industrial Control Systems

US cybersecurity authorities have issued a critical warning: Iranian hackers are now targeting a wider range of industrial control systems, including those from Schneider Electric and Siemens, beyond their previously known focus on Rockwell Automation/Allen-Bradley devices. This expanded threat alert urges companies to bolster their defenses against increasingly aggressive and opportunistic cyber attacks.

Analyst 207