#cisa

[ follow ]
#cybersecurity
fromSilicon Canals
1 week ago
Information security

Iranian hackers used Stryker's own security tools against it - and U.S. agencies say it's just the beginning - Silicon Canals

US politics
fromTheregister
2 weeks ago

Trump wants to slash $707M from CISA's budget

CISA faces a proposed $707 million budget cut, risking national cybersecurity and critical infrastructure management.
SF politics
fromNextgov.com
14 hours ago

CISA resources 'more limited than I would like' amid shutdown, top official says

CISA faces significant funding limitations impacting its ability to counter hacking threats and conduct essential activities.
Information security
fromSecurityWeek
3 days ago

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities

CISA expanded its Known Exploited Vulnerabilities catalog with seven new vulnerabilities, including critical Windows and Adobe flaws.
Information security
fromSilicon Canals
1 week ago

Iranian hackers used Stryker's own security tools against it - and U.S. agencies say it's just the beginning - Silicon Canals

Iran-backed hackers are escalating cyberattacks against U.S. critical infrastructure, targeting water utilities and energy systems to cause operational disruption.
US politics
fromTheregister
2 weeks ago

Trump wants to slash $707M from CISA's budget

CISA faces a proposed $707 million budget cut, risking national cybersecurity and critical infrastructure management.
Information security
fromTheregister
14 hours ago

CISA tells feds to patch 13-year-old Apache ActiveMQ bug

CISA warns of a critical Apache ActiveMQ vulnerability requiring federal agencies to patch within two weeks to prevent exploitation.
Information security
fromTheregister
2 days ago

Ancient Excel bug comes out of retirement for active attacks

A 17-year-old critical Excel vulnerability is actively being exploited, prompting CISA to issue a patch deadline for federal agencies.
Information security
fromTheregister
4 days ago

Ransomware scum, other crims exploit 4 old Microsoft bugs

Four Microsoft vulnerabilities are actively exploited, including one from 2012, prompting CISA to urge federal agencies to patch them within two weeks.
#budget-cuts
fromTechCrunch
1 week ago
SF politics

Trump administration plans to cut cybersecurity agency's budget by $700 million | TechCrunch

The Trump administration plans to cut CISA's budget by at least $707 million for 2027, claiming it will refocus the agency's core mission.
fromSecurityWeek
1 week ago
SF politics

White House Seeks to Slash CISA Funding by $707 Million

The Trump administration proposes a $707 million budget cut for CISA to refocus on core missions and eliminate inefficiencies.
SF politics
fromTNW | Insights
1 week ago

Trump's FY27 budget would cut $700M from CISA and kill election security

The Trump administration's FY2027 budget proposes significant cuts to CISA, eliminating its election security program and reducing its workforce by approximately 860 positions.
SF politics
fromNextgov.com
1 week ago

Trump proposes cutting CISA election security program in FY27 budget

The Trump administration plans to cut $700 million from CISA, significantly impacting election security and infrastructure protection programs.
SF politics
fromTechCrunch
1 week ago

Trump administration plans to cut cybersecurity agency's budget by $700 million | TechCrunch

The Trump administration plans to cut CISA's budget by at least $707 million for 2027, claiming it will refocus the agency's core mission.
SF politics
fromSecurityWeek
1 week ago

White House Seeks to Slash CISA Funding by $707 Million

The Trump administration proposes a $707 million budget cut for CISA to refocus on core missions and eliminate inefficiencies.
#dhs
SF politics
fromNextgov.com
2 weeks ago

DHS drops investigation into former acting CISA chief's failed polygraph exam

DHS closed an investigation into CISA staff who arranged a polygraph for the former acting director, clearing them of wrongdoing.
Information security
fromSecurityWeek
3 weeks ago

CISA Flags Critical PTC Vulnerability That Had German Police Mobilized

CISA warns of a critical vulnerability in PTC's Windchill software, with potential for exploitation despite no current evidence of attacks.
Information security
fromThe Hacker News
3 weeks ago

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks

Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications targeting individuals of high intelligence value.
SF politics
fromNextgov.com
1 month ago

Mullin's appointment to lead DHS raises questions about future of CISA

Trump appointed Oklahoma Senator Markwayne Mullin as DHS Secretary after firing Kristi Noem, amid CISA's significant workforce reductions and leadership instability.
fromDataBreaches.Net
1 month ago

Hospitals at Risk of BeyondTrust Ransomware Hacks - DataBreaches.Net

U.S. federal authorities and industry officials are urging hospitals and clinics to address a critical flaw in BeyondTrust Remote Support and Privileged Remote Access software, which if exploited, could give an attacker a foothold inside a corporate network. The U.S. Department of Health and Human Services in an alert Thursday warned healthcare and public health sector organizations to review and address the vulnerability in light of rising cyberattacks targeting those entities.
Information security
Miscellaneous
fromEngadget
1 month ago

US website 'freedom.gov' will allow Europeans to view hate speech and other blocked content

The US State Department and DHS are developing freedom.gov to let people view online content banned in their countries, including a VPN to bypass restrictions.
US politics
fromNextgov.com
1 month ago

CISA threat-hunting leader to depart for private sector role

CISA's associate director for threat hunting, Jermaine Roebuck, is leaving for the private sector amid agency furloughs and ongoing workforce attrition.
US politics
fromSecurityWeek
1 month ago

CISA Navigates DHS Shutdown With Reduced Staff

CISA operations continue during the DHS shutdown at reduced capacity, requiring 888 of 2,341 staff to work without pay while projects are curtailed.
#government-shutdown
US news
fromNextgov.com
2 months ago

CISA's acting chief says 70 staff were reassigned to other DHS offices in last year

CISA reassigned roughly 70 staff out and received over 30 transfers last year, prompting congressional concern about loss of cyber expertise amid rising cyber threats.
Information security
fromTheregister
2 months ago

CISA: Remove EOL edge kit before cybercriminals strike

CISA directs federal agencies to inventory and replace end-of-support edge devices within set timelines to eliminate critical intrusion risks.
fromSecurityWeek
2 months ago

Questions Raised Over CISA's Silent Ransomware Updates in KEV Catalog

Thorpe described the KEV updates as representing a material change to an organization's risk posture. "Your prioritization calculus should shift. But there's no alert, no announcement. Just a field change in a JSON file," the expert said. "We're good at reacting to new disclosures. Decent at tracking active exploitation. But we're not great at noticing when the characterization of existing threats evolves," Thorpe noted.
Information security
Information security
fromNextgov.com
2 months ago

CISA orders agencies to patch and replace end-of-life devices, citing active exploitation

CISA ordered federal agencies to identify, remove, and replace unsupported internet-facing edge devices due to widespread exploitation by advanced threat actors.
fromTheregister
2 months ago

Critical SolarWinds Web Help Desk bug under attack

The vulnerability under attack, CVE-2025-40551, is an untrusted deserialization flaw that can lead to remote code execution, allowing a remote, unauthenticated attacker to execute OS commands on the affected system. SolarWinds fixed the security hole, along with five others, in Web Help Desk version 2026.1, released on January 28. Horizon3.ai and watchTowr researchers reported these six bugs to the software vendor, with Horizon3 warning that "these vulnerabilities are easily exploitable."
Information security
fromNextgov.com
2 months ago

AI info-sharing center is in development, CISA official says

We just want to make sure we've got the right elements of, how do we pull together people, and how do we take advantage of the leadership position that we have
Information security
Information security
fromTheregister
2 months ago

CISA quietly updated ransomware flags on 59 flaws last year

On 59 occasions in 2025 CISA changed KEV entries to indicate ransomware use without alerting defenders, creating unnoticed risk shifts and missed remediation priorities.
Information security
fromSecurityWeek
2 months ago

In Other News: Paid for Being Jailed, Google's $68M Settlement, CISA Chief's ChatGPT Leak

Mitsubishi Electric acquired Nozomi Networks; LastPass disrupted phishing infrastructure but attackers sent a new wave; CISA withdrew from RSA Conference.
US politics
fromTheregister
2 months ago

CISA insider-threat warning comes with an ironic twist

Insider threats are among the most serious security risks and require multidisciplinary teams and decisive action to detect, mitigate, and prevent damage.
#chatgpt
fromTechCrunch
2 months ago
US politics

Trump's acting cybersecurity chief uploaded sensitive government docs to ChatGPT | TechCrunch

fromTechCrunch
2 months ago
US politics

Trump's acting cybersecurity chief uploaded sensitive government docs to ChatGPT | TechCrunch

US politics
fromEsquire
2 months ago

Is Kristi Noem Building a Shady Security Empire?

Senior DHS officials pushed CISA to install a secure intelligence-sharing facility at Dakota State University despite unclear national security need, funding concerns, and political favoritism.
Information security
fromTheregister
2 months ago

CISA won't attend infosec industry's biggest conference

CISA will not participate in the RSA Conference, citing a return to statutory mission, stakeholder review, and stewardship of taxpayer dollars amid political controversy.
fromNextgov.com
2 months ago

CISA to cease participation at RSAC conference after Biden-era cyber leader named CEO

CISA has reviewed and determined that we will not participate in the RSA Conference since we regularly review all stakeholder engagements, to ensure maximum impact and good stewardship of taxpayer dollars.
US politics
#workforce-reductions
US politics
fromNextgov.com
2 months ago

CISA budget bill would require agency to maintain 'sufficient' staffing levels

CISA must retain staffing and at least 10 regional offices with one Cyber Security Advisor per state; receives $2.6B total and $39.6M for election security.
fromNextgov.com
3 months ago

Trump officials consider skipping premier cyber conference after Biden-era cyber leader named CEO

Top Trump administration cyber officials are in discussions to cancel their attendance at the RSAC Conference taking place in San Francisco in March after a top Biden-era cyber leader was named CEO of the event, according to multiple former officials and other people with knowledge of the matter.
Information security
US politics
fromNextgov.com
3 months ago

Trump renominates Plankey to lead CISA

Sean Plankey was re-nominated to lead CISA but faces Senate delays and political holds amid leadership vacancy, staffing losses, and scrutiny over agency security oversight.
Information security
fromThe Hacker News
3 months ago

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024

CISA retired ten emergency directives issued 2019–2024 after federal remediation and enforcement via BOD 22-01 to strengthen federal cybersecurity and reduce exploited vulnerabilities.
Information security
fromThe Hacker News
3 months ago

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

CISA added two actively exploited vulnerabilities—CVE-2009-0556 in Microsoft PowerPoint and CVE-2025-37164 in HPE OneView—to its KEV catalog; agencies must apply patches.
fromDataBreaches.Net
3 months ago

US, Australia say 'MongoBleed' bug being exploited - DataBreaches.Net

U.S. and Australian cyber agencies confirmed that hackers are exploiting a vulnerability that emerged over the Christmas holiday and is impacting data storage systems from the company MongoDB. The issue drew concern on December 25 when a prominent researcher published exploit code for CVE-2025-14847 - a vulnerability MongoDB announced on December 15 and patched on December 19.
Information security
#ransomware
#sean-plankey
fromNextgov.com
3 months ago

CISA opens 100 applications for CyberCorps students

The Cybersecurity and Infrastructure Security Agency said it will make 100 internship opportunities available to students participating in a government scholarship program that's been hampered by federal hiring freezes enacted by the Trump administration. The move announced Wednesday would allow undergraduate and graduate students to enter the cyber defense agency under the CyberCorps: Scholarship for Service Program, a longstanding workforce pipeline used to place top student talent into U.S. cybersecurity positions.
Information security
Information security
fromZDNET
4 months ago

Your Android phone may be in critical danger - update it ASAP

Google released the December 2025 Android security update fixing 107 vulnerabilities, including critical kernel and framework flaws, with two vulnerabilities possibly already exploited.
fromNextgov.com
4 months ago

CISA tells staff to not speak with reporters, internal email shows

"In today's culture of information saturation, it is imperative that we ensure all official information communicated on behalf of CISA is current, accurate, unbiased, and authoritative. This includes any official information communicated to the media," reads part of the note issued by agency acting Director Madhu Gottumukkala. CISA is "committed to a culture of transparency" but also has a "responsibility to ensure we meet the imperative laid out above and to that end, the Office of the Chief External Affairs Office (OCEAO/ /EA) is the only office authorized to facilitate official communication with the media," it adds.
Information security
fromTheregister
4 months ago

CISA orders feds to patch Oracle Identity Manager zero-day

Searchlight Cyber researchers Adam Kues and Shubham Shah, who discovered the flaw, have published their own technical teardown of the vulnerability that doesn't mince words about the ease with which criminals can weaponize it. The researchers call exploitation "trivial," describing a single HTTP request that bypasses OIM's normal authentication flow and ultimately gives an attacker remote system-level control. Oracle disclosed the bug in October, but didn't indicate that it was under active exploitation.
Information security
#fortiweb
#telecommunications-security
#cisco-asa
fromTechCrunch
5 months ago
Information security

CISA warns federal agencies to patch flawed Cisco firewalls amid 'active exploitation' across the US government | TechCrunch

fromTechCrunch
5 months ago
Information security

CISA warns federal agencies to patch flawed Cisco firewalls amid 'active exploitation' across the US government | TechCrunch

US politics
fromNextgov.com
5 months ago

DHS says shutdown layoffs at CISA will proceed despite court injunction

CISA is proceeding with planned layoffs of 54 Stakeholder Engagement Division employees, arguing the notices predate a court injunction and do not cover union-represented groups.
fromAxios
5 months ago

Election security cutbacks force local officials to go it alone

Local election offices are left with fewer resources, less threat intelligence, and diminished federal guidance. "It's kind of heartbreaking to know that they worked [on] creating these relationships and partnerships over the last decade, and they'renowjust disintegrating," Brianna Lennon, the county clerk in Missouri's Boone County, tells Axios. Bloomberg reported yesterday thattheCybersecurity and Infrastructure Security Agency's election monitoring room, which has been stood up during every election cycle to field and share information about active threats to elections, isn't operating this year.
Information security
fromIT Pro
5 months ago

CISA just published crucial new guidance on keeping Microsoft Exchange servers secure

"With the threat to Exchange servers remaining persistent, enforcing a prevention posture and adhering to these best practices is crucial for safeguarding our critical communication systems," Andersen said. "This guidance empowers organizations to proactively mitigate threats, protect enterprise assets, and ensure the resilience of their operations." Anderson added that CISA recommends organizations also "evaluate the use of cloud-based email services" rather than "managing the complexities" of hosting their own.
Information security
US news
fromNextgov.com
5 months ago

Top CISA official exits for TSA role amid recent cyber office reductions

Ryan Donaghy is transitioning from the Cybersecurity and Infrastructure Security Agency to the Transportation Security Administration.
Information security
fromNextgov.com
5 months ago

US cyber policy goals have regressed during Trump 2.0 in 'unprecedented setback,' landmark report says

Federal cyber policy has regressed about 13%, with workforce cuts, funding reductions, and rollback of initiatives undermining CISA, State cyber diplomacy, and counter-disinformation efforts.
fromNextgov.com
6 months ago

Multiple CISA divisions targeted in shutdown layoffs, people familiar say

Staff within the Stakeholder Engagement Division, as well as the cyber-defense agency's Infrastructure Security Division, were targeted with reduction-in-force notices, or RIFs, said the people. OMB Director Russ Vought announced the actions on Friday in line with Trump administration promises to enact layoffs during the ongoing government shutdown. The Integrated Operations Division is also believed to have been impacted, one of the people said.
US politics
fromTheregister
6 months ago

CISA law may be rescued amid shutdown if Senate bill clears

The CISA law was due for renewal along with the federal government's continuing funding resolution, but given the Senate's inability to pass it and the government shutdown that followed, Peters and Rounds want it extended without having to wait for the government to reopen in order to do so. The CISA law, for those unfamiliar, establishes a framework and legal protections for companies to share threat indicators with the government and each other.
US politics
fromTechCrunch
6 months ago

Homeland Security reassigns 'hundreds' of CISA cyber staffers to support Trump's deportation crackdown | TechCrunch

Bloomberg reported Wednesday that the department moved staffers from the U.S. cybersecurity agency CISA, many of whom focus on issuing cyber guidance to help U.S. government agencies and critical infrastructure defend from cyber threats, to other agencies within the federal department, including Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). Both Bloomberg and Nextgov reported that many of the affected CISA staffers are in the agency's Capacity Building unit, which helps to improve the cybersecurity posture of federal agencies,
US politics
Information security
fromFast Company
6 months ago

U.S. cybersecurity was bad during the first Trump administration. Somehow, it's getting worse.

CISA faces severe degradation: leadership vacancy, mass staff departures, mission cuts, and furloughs amid escalating foreign cyberattacks and risky domestic data collection.
Information security
fromSecurityWeek
6 months ago

Organizations Warned of Exploited Sudo Vulnerability

A critical Sudo local privilege escalation (CVE-2025-32463) allows any user to gain root privileges and has been exploited, requiring urgent patching.
Information security
fromTheregister
6 months ago

CISA kills agreement with nonprofit that runs MS-ISAC

CISA will end its cooperative agreement and funding for the Center for Internet Security on September 30, 2025, shifting to a new SLTT support model.
fromTheregister
6 months ago

SonicWall releases rootkit-busting firmware update

The update comes about two months after Google warned that some unknown criminals have been exploiting fully patched, end-of-life SonicWall SMA 100 appliances to deploy a previously unknown backdoor and rootkit dubbed OVERSTEP. The malware modifies the appliance's boot process to maintain persistent access, enabling the criminals to steal sensitive credentials and conceal their own components. The Chocolate Factory's intel analysts in July attributed the ongoing campaign to UNC6148 - UNC in Google's threat-group naming taxonomy stands for "Uncategorized."
Information security
#cve-program
fromNextgov.com
7 months ago
Information security

CISA weighs 'alternative funding sources' to preserve cyber vulnerability-tracking project

fromNextgov.com
7 months ago
Information security

CISA weighs 'alternative funding sources' to preserve cyber vulnerability-tracking project

US politics
fromTheregister
7 months ago

CISA misspent millions in cyber skill retention funds: audit

CISA mismanaged the Cyber Incentive program, allowing widespread ineligible payments, poor recordkeeping, and reduced capacity to protect the nation from cyber threats.
Information security
fromTheregister
7 months ago

CISA attempts to assert control over CVE in vision outline

CISA aims to assert governmental control over the CVE program, transitioning it from a growth era to a government-led "quality era" beginning in 2025.
fromNextgov.com
7 months ago

CISA ready to accept any extension for key cyber info-sharing law, official says

We'll take whatever the Congress decides to authorize us, wherever they see fit within their purview, to authorize and to give us our authorities to be able to use,
Information security
Information security
fromDataBreaches.Net
7 months ago

CISA Delays Cyber Incident Reporting Rule for Critical Infrastructure - DataBreaches.Net

CISA plans to publish the CIRCIA Final Rule in May 2026, delaying its expected October 2025 arrival and likely postponing its effective date.
Information security
fromTheregister
7 months ago

Congress tosses lifeline to cyber intel sharing, grants

Congress must reauthorize and extend cyber information-sharing authorities like CISA to maintain private–public threat intelligence collaboration and protect critical infrastructure.
Information security
fromDataBreaches.Net
7 months ago

CISA steps in to help Nevada state government recover from cyberattack - DataBreaches.Net

CISA, the FBI, and other federal and state teams are collaborating to investigate, contain, and restore Nevada's systems after a cyberattack while securing recovery grants.
[ Load more ]