CISA
72 briefings written from CISA's reporting, newest first. Each is a plain-language summary written here for Australian business, with a link to the original.
- CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight
- CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
- CISA Flags Actively Exploited Google Pixel Vulnerability
- Siemens Mendix SAML Flaw Could Let Attackers Hijack Login Sessions
- New Guidance Aims to Stop Attackers Forging Login Tokens in Cloud Systems
- Critical Flaws Found in Digital Watchdog VMAX Surveillance Recorders
- Actively Exploited Cisco Secure Email Gateway Flaw Added to CISA's Watchlist
- CISA Flags Active Exploitation of JFrog Artifactory and ConnectWise ScreenConnect Flaws
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- Security Flaws Found in NextGen Healthcare's Mirth Connect Software
- CISA Warns of Active Exploitation of Two MikroTik RouterOS Vulnerabilities
- CISA Flags Four Actively Exploited Flaws in Fortinet, Citrix, Cisco and Chrome
- CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
- Actively Exploited Chrome Flaw Added to US Government's Must-Patch List
- Quantum Computing Threat: CISA Urges Businesses to Start Planning Now
- New Guidance: How Businesses Should Communicate During IT Outages
- CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
- Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
- US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
- Security Flaw Found in Mitsubishi Electric CNC Machine Controllers
- Password Security Flaw Found in Rockwell Automation's OTTO Fleet Manager
- Mitsubishi Electric Industrial Devices Vulnerable to Denial-of-Service Attacks
- Critical Vulnerabilities Found in Fuel-Boss Fuel Management Systems
- Critical Security Flaws Found in Xiiaozet LK100W Devices
- Critical Security Flaws Found in Ebyte NA111-M Industrial Device
- Critical Flaws Found in ASE2000 Industrial Test Tool Used in Energy and Water Sectors
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- CISA Flags Six More Vulnerabilities Under Active Attack
- Two Companies, Two Outcomes: What a CISA Red Team Test Reveals About Cyber Defence
- Security Flaw Found in Rently Smart Home Devices Could Expose User Data
- Security Flaw Found in PayRange Payment API Could Expose Sensitive Data
- Critical Security Flaws Found in Ebyte NE2-D11 Industrial Devices
- Critical Flaws Found in Bendix Truck Brake Control Systems
- Critical Flaw in ZoneMinder Video Surveillance Software Could Allow Full Server Takeover
- Critical Flaw in Siemens SIMATIC IoT2050 Advanced Devices Allows Full Remote Takeover
- Critical Flaw Found in FURUNO Marine AIS Transponder Could Let Attackers Change Device Settings
- CISA Flags Actively Exploited Gitea Vulnerability — Patch Now
- CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
- Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
- Security Flaw Found in Johnson Controls Simplex Incident Manager Could Expose User Credentials
- CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities
- Urgent Warning: Active Cyberattacks Targeting Industrial Control Systems, Including Siemens PLCs
- CISA Flags Actively Exploited MLflow Vulnerability — Act Now
- Siemens Simcenter Nastran Vulnerability Could Allow Remote Code Execution
- Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
- CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products
- CISA Flags Actively Exploited Flaw in Ray-Project AI Framework
- Siemens Solid Edge Software Vulnerable to Malicious File Attacks
- Siemens Parasolid Software Vulnerable to File-Based Attack, Update Urged
- Siemens LOGO! Soft Comfort Software Has Encryption Flaws — Update Now
- Siemens License Server Flaws Could Let Attackers Elevate Privileges, Access Files
- Siemens Building Controllers Vulnerable to Network-Based Disruption
- Security Flaws Found in ANDRITZ HIPASE-250 and 250 SCALA Devices Used in Energy Sector
- Security Flaw Found in Johnson Controls Metasys Building Management System
- Security Flaw Found in Flow Neuroscience Brain Stimulation Device
- Critical Flaw Found in Siemens Video Management Software—Update Now
- CISA Flags Vulnerabilities in Johnson Controls Airwall Security Devices
- Three Actively Exploited Vulnerabilities Added to CISA's Critical List — Cisco, Microsoft and Metabase Affected
- Security Flaw Found in Pulsetto Vagus Nerve Stimulator Device
- Critical Security Flaws Found in Mira Hormone Monitor Devices and App
- Critical Flaws Found in Johnson Controls Access Control Systems
- New Gunra Ransomware Threat Targets Businesses with Double-Extortion Tactics
- Aviation Alert: Legacy Air Traffic Communication System Vulnerable to Message Injection Attacks
- Actively Exploited Flaw in Progress LoadMaster Added to CISA's Must-Patch List
- Security Flaw Found in Medixant RadiAnt DICOM Medical Imaging Software
- Security Flaw Found in Johnson Controls TL280 Devices
- Multiple Security Flaws Found in ABB Ability Zenon Industrial Software
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- Security Flaw Found in Thermo Fisher Genetic Analyzer Software Could Allow DNA Data Tampering
- Hard-Coded Encryption Key Flaw Found in Vehicle Alarm Systems
- CISA Flags Three More Actively Exploited Software Flaws — Is Your Business Affected?
- Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know