Security News

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List
2025-01-24 05:39

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited...

CISA: Hackers still exploiting older Ivanti bugs to breach networks
2025-01-23 16:51

CISA and the FBI warned today that attackers are still exploiting Ivanti Cloud Service Appliances (CSA) security flaws patched since September to breach vulnerable networks. [...]

CISA shares guidance for Microsoft expanded logging capabilities
2025-01-15 20:39

​CISA shared guidance for government agencies and enterprises on using expanded cloud logs in their Microsoft 365 tenants as part of their forensic and compliance investigations. [...]

China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says
2025-01-15 20:30

We are only seeing 'the tip of the iceberg,' Easterly warns Beijing's Salt Typhoon cyberspies had been seen in US government networks before telcos discovered the same foreign intruders in their...

CISA Adds Second BeyondTrust Flaw to KEV Catalog Amid Active Attacks
2025-01-14 03:21

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a second security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the...

CISA orders agencies to patch BeyondTrust bug exploited in attacks
2025-01-13 20:58

​CISA tagged a vulnerability in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) as actively exploited in attacks, ordering agencies to secure their systems within three weeks. [...]

CISA Flags Critical Flaws in Mitel and Oracle Systems Amid Active Exploitation
2025-01-08 04:21

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three flaws impacting Mitel MiCollab and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV)...

CISA warns of critical Oracle, Mitel flaws exploited in attacks
2025-01-07 18:45

CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks. [...]

CISA says Treasury was the only US agency breached via BeyondTrust
2025-01-07 12:14

The US Cybersecurity and Infrastructure Security Agency (CISA) has shared on Monday that the Treasury Department was the only US federal agency affected by the recent cybersecurity incident...

CISA: No Wider Federal Impact from Treasury Cyber Attack, Investigation Ongoing
2025-01-07 08:43

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday said there are no indications that the cyber attack targeting the Treasury Department impacted other federal agencies....