BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Lea

News tagged CISA

Every TorPortal story that mentions CISA. 53 stories, newest first. Category: lea.

Latest coverage of CISA

Click a headline for the full story or jump to the original.

Max severity SAP Commerce Cloud flaw now targeted in attacks
BleepingComputer · Aug 14, 2026 · 2 min read

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
Shell investigates 'potential incident' after Clop data theft claims
BleepingComputer · Aug 14, 2026 · 2 min read

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
Hackers leverage new Microsoft SharePoint exploit in attacks
BleepingComputer · Aug 12, 2026 · 1 min read

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday.
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
The Record · Aug 12, 2026 · 3 min read

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer · Aug 11, 2026 · 1 min read

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
Cisco warns of high-severity ClamAV flaws with public exploits
BleepingComputer · Aug 11, 2026 · 1 min read

Cisco warns of high-severity ClamAV flaws with public exploits

Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Record · Aug 10, 2026 · 2 min read

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
Senate Democrats introduce bill to distribute $300 million annually to shore up water system…
The Record · Aug 10, 2026 · 3 min read

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer · Aug 10, 2026 · 2 min read

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
Critical Progress LoadMaster flaw now actively exploited in attacks
BleepingComputer · Aug 10, 2026 · 1 min read

Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
18-Year-Old Linux Flaw Could Enable Root Access
DarkDotWeb · Aug 7, 2026 · 2 min read

18-Year-Old Linux Flaw Could Enable Root Access

A Linux SCTP flaw dating to 2008 could allow local privilege escalation and potentially container escapes, researchers warn.
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
BleepingComputer · Aug 5, 2026 · 1 min read

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited.
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
The Record · Aug 5, 2026 · 7 min read

Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents

Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Record · Aug 4, 2026 · 2 min read

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.
N-able warns of N-central auth bypass flaw exploited in attacks
BleepingComputer · Aug 3, 2026 · 1 min read

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Record · Jul 31, 2026 · 2 min read

CISA warns of spike in attacks on water systems as Minnesota incidents probed

The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
CISA warns of cyberattacks disrupting U.S. water utilities
BleepingComputer · Jul 31, 2026 · 1 min read

CISA warns of cyberattacks disrupting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
VMware fixes three critical flaws allowing auth bypass, VM escapes
BleepingComputer · Jul 30, 2026 · 1 min read

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a…
BleepingComputer · Jul 29, 2026 · 1 min read

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack."
CISA shares advice on isolating vital systems during cyberattacks
BleepingComputer · Jul 28, 2026 · 1 min read

CISA shares advice on isolating vital systems during cyberattacks

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
BleepingComputer · Jul 27, 2026 · 1 min read

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
Outdated VPNs should be purged from federal agencies, senator says
The Record · Jul 27, 2026 · 2 min read

Outdated VPNs should be purged from federal agencies, senator says

Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
BleepingComputer · Jul 24, 2026 · 1 min read

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer · Jul 23, 2026 · 1 min read

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a…
Check Point warns of SmartConsole zero-day exploited in attacks
BleepingComputer · Jul 23, 2026 · 1 min read

Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
The Record · Jul 22, 2026 · 2 min read

Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill

A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.
Federal agencies broaden alert on Iran-linked OT attacks
The Record · Jul 22, 2026 · 1 min read

Federal agencies broaden alert on Iran-linked OT attacks

The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
New InfraTrust report reveals infrastructure flaws admins should patch first
BleepingComputer · Jul 22, 2026 · 1 min read

New InfraTrust report reveals infrastructure flaws admins should patch first

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge…
CISA orders urgent action on actively exploited Langflow RCE flaw
BleepingComputer · Jul 22, 2026 · 1 min read

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
Closing the Identity Gaps in Critical Infrastructure Security
BleepingComputer · Jul 21, 2026 · 1 min read

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical…
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
BleepingComputer · Jul 21, 2026 · 1 min read

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
CISA urges immediate action on actively exploited Fortinet flaws
BleepingComputer · Jul 17, 2026 · 1 min read

CISA urges immediate action on actively exploited Fortinet flaws

CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.
CISA orders feds to patch actively exploited Oracle flaw by Saturday
BleepingComputer · Jul 16, 2026 · 1 min read

CISA orders feds to patch actively exploited Oracle flaw by Saturday

CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application.
Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities
The Record · Jul 15, 2026 · 2 min read

Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities

The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.
Microsoft smashes Patch Tuesday record for second successive month
The Record · Jul 15, 2026 · 4 min read

Microsoft smashes Patch Tuesday record for second successive month

Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.
CISA warns admins to patch actively exploited SharePoint flaws
BleepingComputer · Jul 15, 2026 · 1 min read

CISA warns admins to patch actively exploited SharePoint flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
BleepingComputer · Jul 14, 2026 · 1 min read

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates.
Krebs on Security · Jul 14, 2026 · 4 min read

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
SAP warns of critical flaws in NetWeaver and Commerce Cloud
BleepingComputer · Jul 14, 2026 · 1 min read

SAP warns of critical flaws in NetWeaver and Commerce Cloud

SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
CISA warns of actively exploited RCE flaws in Joomla extensions
BleepingComputer · Jul 13, 2026 · 1 min read

CISA warns of actively exploited RCE flaws in Joomla extensions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file…
Lessons Learned from CISA’s Recent GitHub Leak
Krebs on Security · Jul 13, 2026 · 4 min read

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for…
US and allies warn of Russian critical infrastructure attacks
BleepingComputer · Jul 13, 2026 · 1 min read

US and allies warn of Russian critical infrastructure attacks

Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks.
Zimbra urges customers to patch critical web client XSS flaw
BleepingComputer · Jul 10, 2026 · 1 min read

Zimbra urges customers to patch critical web client XSS flaw

The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
Microsoft expects more Windows security updates from AI-discovered flaws
BleepingComputer · Jul 9, 2026 · 1 min read

Microsoft expects more Windows security updates from AI-discovered flaws

Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase.
CISA orders feds to prioritize patching Langflow auth bypass flaw
BleepingComputer · Jul 8, 2026 · 1 min read

CISA orders feds to prioritize patching Langflow auth bypass flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents.
Ubiquiti warns of new max severity  UniFi OS vulnerability
BleepingComputer · Jul 8, 2026 · 1 min read

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks.
CISA orders feds to patch max severity ColdFusion flaw by Friday
BleepingComputer · Jul 8, 2026 · 1 min read

CISA orders feds to patch max severity ColdFusion flaw by Friday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday.
CISA: Microsoft SharePoint RCE flaw now actively exploited
BleepingComputer · Jul 2, 2026 · 1 min read

CISA: Microsoft SharePoint RCE flaw now actively exploited

CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May.
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
BleepingComputer · Jun 30, 2026 · 1 min read

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks.
CISA Warns of Exploited Joomla JCE RCE Flaw
DarkDotWeb · Jun 18, 2026 · 2 min read

CISA Warns of Exploited Joomla JCE RCE Flaw

CISA added a critical Joomla JCE vulnerability to its KEV list after attackers began exploiting the flaw to execute PHP code.
CISA Flags Cisco, Chrome, Arista Flaws Under Attack
DarkDotWeb · Jun 11, 2026 · 2 min read

CISA Flags Cisco, Chrome, Arista Flaws Under Attack

CISA added three actively exploited vulnerabilities affecting Cisco, Google Chrome and Arista products to its KEV catalog.
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Krebs on Security · May 22, 2026 · 6 min read

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a…
CISA Admin Leaked AWS GovCloud Keys on Github
Krebs on Security · May 18, 2026 · 5 min read

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of…

← All news