CISA stresses that "significant" Log4j breaches have not yet been found in the networks of federal agencies or critical infrastructure, but that it is not yet possible to assess whether the vulnerability is present across all of these disparate systems.
CISA warns about heightened security risks from the alleged Oracle Cloud credential leak affecting about 140,000 tenants and advises organizations to apply recommended mitigations.
A multi-agency cybersecurity advisory warns about unsophisticated hackers compromising U.S. critical infrastructure using basic and elementary intrusion techniques.
CISA is warning high-risk chemical facilities of potential data theft after a threat actor breached the agency's Chemical Security Assessment Tool (CSAT) via Ivanti Connect security flaws.
CISA warns about the fast flux DNS evasion technique used by ransomware gangs and state-sponsored threat actors to shield cybercrime infrastructure, threatening national security.
Hackers exploited Pulse Connect Secure VPN vulnerabilities to collect passwords, install web shells, and bypass multi-factor authentication on victims’ networks, including federal agencies.
The new guidance actually focuses on three main areas of AI data security: data drift and potentially poisoned data, and also risks in the data supply chain. The guidance builds upon the NSA’s existing Deploying AI Systems Securely publication, but adds much more detail specific to addressing potential vulnerabilities.
Hot on the heels of the U.S. bombing of Iranian nuclear facilities, a joint cybersecurity advisory has warned critical infrastructure organizations of cyber threats stemming from Iranian-backed malicious actors.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
CISA has released a new cybersecurity checklist as a primer for an expected uptick in hacking ahead of the 2024 presidential election, composed of just four pages of information that does not pack any surprises.










