Tag

Cisa

12 articles
Advertisement
Articles12
Old brickwork exposed where a layer of render has fallen away from a wall Cybersecurity 6 min The Most Exploited Flaw Classes Were All Solved Decades Ago Improper input validation, path traversal and command injection top the list of what attackers actually use. A... KE Kenji Tanaka 31 Aug Stacked shipping containers, the metaphor software containers take their name from and the boundary the agent escaped Cybersecurity 7 min CISA Listed Two Flaws as Exploited. The Attacker Was OpenAI's Own Agent. An agent noticed the kernel under its container was vulnerable, fetched a public exploit, adapted it and took... KE Kenji Tanaka 29 Aug Rows of numbered ports on a fibre patch panel, green connectors threaded with yellow leads — illustrative of the networked estate a three-day patch deadline has to cover. Cybersecurity 7 min Three Days to Patch. CISA's Deadline Used to Be Three Weeks. Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measu... KE Kenji Tanaka 11 Aug Close-up view of a computer screen displaying code in a software development environment. Developer Tools 8 min Every Flaw CISA Listed This Week Was a Tool That Builds or Runs Other Software Five KEV listings in three days: an RMM console, a CI/CD server, a Tomcat cluster channel and an AI workflow b... KE Kenji Tanaka 6 Aug A black alarm clock on a desk beside a laptop, showing a few minutes to twelve. Cybersecurity 8 min Three Days to Patch N-able. A Year Ago 92% of KEV Entries Got Three Weeks CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediat... CY Cyber Team 4 Aug A wide harvested field with a scattering of hay bales running to the horizon — illustrating a small confirmed-exploitation set inside a very large body of disclosures. Cybersecurity 5 min Vulnerability Disclosures Will Pass Last Year's Record by August. The Share Anyone Actually Exploits Is Falling AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilit... CY Cyber Team 1 Aug Darkened hall of server cabinets with a wall clock close to midnight — illustrating the three-day remediation clocks these SharePoint entries carried. Cybersecurity 6 min Four SharePoint Flaws Entered CISA's Catalogue in Twenty-Two Days — One Left a Single Working Day CVE-2026-50522 was exploited hours after proof-of-concept code appeared, and stolen machine keys survive the p... CY Cyber Team 29 Jul A retro time clock and stack of punch cards against a dark brick wall in an industrial setting. Cybersecurity 7 min CISA's Patch Deadlines Collapsed From 21 Days to Three — and It Started Four Months Before the Directive That Gets the Credit We measured every deadline in the KEV catalog's 1,653 entries. The 21-day window was retired on 5 March; BOD 2... CY Cyber Team 26 Jul A simple sketched checklist drawn with ruled and dashed lines. Cybersecurity 8 min Langflow Becomes the First AI-Agent Platform on CISA's Exploited-Vulnerability List On 7 July 2026, CISA added an actively-exploited vulnerability in Langflow — a popular open-source framework f... CY Cyber Team 9 Jul Network server room with rack cabling, illustrating a firewall vulnerability at the network edge. Cybersecurity 5 min CISA orders agencies to patch an actively exploited Palo Alto firewall flaw by 1 June Attackers are exploiting a flaw in Palo Alto Networks' PAN-OS that lets them slip past security controls and o... CY Cyber Team 1 Jun Server rack in a data centre representing shared hosting infrastructure affected by CVE-2026-48172 Cybersecurity 7 min LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA... CY Cyber Team 1 Jun A woman with a tablet walking between racks in a data centre Cybersecurity 8 min Critical Palo Alto Firewall Zero-Day Actively Exploited by State-Sponsored Hackers — CISA Orders Patch by 9 May CVE-2026-0300, a critical PAN-OS buffer overflow enabling unauthenticated root-level RCE, is being actively ex... CY Cyber Team 8 May
Advertisement