CISA added single-factor authentication to bad cybersecurity practices, adding that it was extremely risky for remote and administrative access to critical infrastructure.
The FBI, CISA, and NSA issued a joint cybersecurity advisory about multiple APT groups that comprised a defense organization and exfiltrated sensitive data over a significant period.
A joint advisory detailing LockBit ransomware’s tactics and mitigations disclosed that the cybercrime gang extorted $91 million from US companies since 2020 after 1,700 attacks.
Threat actors exploited Log4Shell vulnerability on unpatched VMware servers to gain access, move laterally, deploy malware, and exfiltrate sensitive information.
Microsoft says state-sponsored Chinese hackers exploited four Microsoft Exchange mail server zero-day vulnerabilities. CISA warned of potential widespread exploitation.
Recent guidance establishes best practices for development of coordinated vulnerability disclosure (CVD) programs. This comes as both public and private organizations are grappling with the prospect of near-term "machine speed" discovery of vulnerabilities by attackers wielding AI tools, and looking at potential major overhauls to their remediation and reporting processes.
CISA released its customized Log4Shell scanning solution and a list of other third-party scanners. However, all the Log4j scanners tested by Rezilion failed to detect all file formats.
CISA and the "Five Eyes" national intelligence agencies have issued their annual advisory on the top exploited vulnerabilities for the prior year, and its findings bolster some other recent reports that a successful attack is becoming increasingly likely to be the result of a zero-day.
CISA published an insight document for critical infrastructure organizations to prepare for the transition to new post-quantum cryptography standards that NIST will announce soon.
Ransomware attacks and cloud security are two of the most persistent cyber defense issues today. CISA is taking a major step in expanding public-private partnerships with a new initiative.









