CISA
77 stories on CISA, newest first, from 81 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- US Cyber Agency Warns of Active Attacks on Critical Citrix NetScaler Flaws
- Citrix NetScaler Under Attack Again: Critical Flaws Being Exploited Right Now
- Urgent: Citrix NetScaler Devices Under Active Attack, Patch Immediately
-
CISA Flags Actively Exploited Flaws in Microsoft SharePoint and MikroTik Routers
Also covered by CISA
- CISA Releases Election Security Plan Ahead of 2026 US Midterms
- CISA Warns of Actively Exploited WordPress Vulnerability
- Lawmakers Push to Classify Biotech as Critical Infrastructure After Cyberattacks
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento
- CISA Unveils Plan to Improve Quality of Global Vulnerability Database
- Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules
- F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns
- New Bill Would Give Critical Infrastructure Operators Free Access to AI Cyber Defence Tools
- CISA Shows Small Businesses How to Turn the Tables on Hackers
- Democrats Push for Review of CISA's Workforce After Major Staff Losses
- Zyxel Network Switch Flaw Added to US Government's Actively Exploited Vulnerability List
- Foreign Hackers Manipulate Equipment in Colorado Water Utilities
- CISA Flags Two Actively Exploited Linux Kernel Flaws
- CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT
-
CISA Shifts Away from Weekly Vulnerability Bulletins in Favor of Risk-Based Alerts
Also covered by The Register
- CISA Tells Critical Infrastructure to Set Traps for Hackers Already Inside the Network
- CISA's New Advice: Fight Hackers by Feeding Them Fake Data
- Google Pixel Phones Hit by Zero-Click Attack: Update Now
- New US Guidance Targets Weak Links in Cloud Login Tokens
- CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight
- CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
- CISA Flags Actively Exploited Google Pixel Vulnerability
- CISA Aims to Speed Up Its Cybersecurity Support Program for Federal Agencies
- Cisco Email Gateways Under Active Attack: Patch Now
- Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
- Actively Exploited Cisco Secure Email Gateway Flaw Added to CISA's Watchlist
- CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS
- CISA Pushes for Clearer Breach Reporting as Cyber Outages Rise
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- CISA Refreshes Insider Threat Guide with New Advice on Remote Work and AI Risks
- CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
- Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline
- CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
- Actively Exploited Chrome Flaw Added to US Government's Must-Patch List
- Quantum Computing Threat: CISA Urges Businesses to Start Planning Now
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- New Guidance: How Businesses Should Communicate During IT Outages
- CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
- Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
- Critical ownCloud Flaw Exploited in Attack on Philippine Nuclear Research Agency
- US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
- CISA Red Team Breaches Two Critical Infrastructure Firms — One Never Noticed
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- CISA Flags Six More Vulnerabilities Under Active Attack
- CISA Warns: Over 100 Water Systems Hit in Cyberattacks Linked to Iran
- Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- Two Companies, Two Outcomes: What a CISA Red Team Test Reveals About Cyber Defence
- Critical Security Flaws Found in Ebyte NE2-D11 Industrial Devices
-
CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability
Also covered by The Hacker News
- Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
- CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
- Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
- CISA Flags Actively Exploited MLflow Vulnerability — Act Now
- Urgent: Patch Now — Microsoft, VMware and Apple Flaws Under Active Attack
- Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
- CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products
- US Cybersecurity Agency Warns of Actively Exploited Flaw in AI Framework 'Ray'
- CISA Flags Actively Exploited Flaw in Ray-Project AI Framework
- CISA Flags Vulnerabilities in Johnson Controls Airwall Security Devices
- Microsoft SharePoint Flaw Under Active Attack After Exploit Code Goes Public
- Three Actively Exploited Vulnerabilities Added to CISA's Critical List — Cisco, Microsoft and Metabase Affected
- Security Flaw Found in Pulsetto Vagus Nerve Stimulator Device
-
Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software
Also covered by CISA
- Security Flaw Found in Medixant RadiAnt DICOM Medical Imaging Software
- US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- US Cyber Agency Warns: Attackers Actively Exploiting Flaws in Popular Business Software
- US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software
- CISA Flags Three More Actively Exploited Software Flaws — Is Your Business Affected?
- CISA Warns: N-able N-central Flaw Actively Exploited, Patch Now
- Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know