Browsing Tag
CISA
18 posts
Cybersecurity and Infrastructure Security Agency alerts, directives, guidance, and federal cyber operations.
Gunra Ransomware Puts VPN Gateways and Backups on the Same Incident List
A new FBI, CISA, NSA, Secret Service, DC3, and South Korean police advisory says Gunra ransomware affiliates are abusing exposed VPN and firewall paths, stealing cloud data, dumping credentials, and deleting backups before encryption. The useful response starts with edge-device patching, identity triage, immutable backups, and log review before recovery begins.
Water Utility Hacks Put Internet-Exposed PLCs on the Emergency List
Federal agencies say water and wastewater utilities in at least seven states reported attacks on internet-exposed PLCs, with some operations degraded. The Minnesota response shows why utilities need to remove controllers from public access, verify cellular modem exposure, and preserve manual operating capability.
Check Point SmartConsole Zero-Day Puts Firewall Management on Patch Deadline
Check Point has patched CVE-2026-16232, an actively exploited SmartConsole authentication bypass that can give attackers full administrator access to exposed Security Management servers. The urgent work is not only installing the Jumbo Hotfix, but also restricting Trusted Clients and checking management logs for signs of compromise.
Russian Router Campaign Turns SNMP Into a Critical Infrastructure Risk
NSA, CISA, the FBI, and 15 allied agencies warn that Russian FSB Center 16 actors are still compromising poorly configured routers across critical infrastructure. The practical fix starts with SNMPv3, blocked management protocols, patched firmware, and a hard look at exposed network devices.
SharePoint’s New Exploited RCE Turns Patching Into Key Rotation Triage
CISA added Microsoft SharePoint Server CVE-2026-58644 to its exploited-vulnerabilities catalog on July 16, two days after Microsoft patched it. Admins should patch, verify AMSI, hunt for machine-key theft, and reduce internet exposure before treating the farm as clean.
Signal Backup-Key Phishing Turns Account Recovery Into an Espionage Target
The FBI and CISA warn that Russian intelligence-linked actors are impersonating messaging-app support accounts to steal Signal backup recovery keys, verification codes, and account PINs. The attacks do not break encryption, but they can expose message backups and keep account-takeover paths alive until users replace compromised keys.
iDirect Satellite Terminal Flaws Put Link Management on the Patch List
CISA says ST Engineering iDirect iQ-Series satellite terminals running software 4.5.2.1 or earlier expose sensitive device identifiers and can be forced into reboots through weak API controls. Operators should treat the July 2 advisory as both a patch event and a management-plane exposure audit.
SharePoint RCE Gives Admins a July 4 Patch Deadline
CISA has added Microsoft SharePoint Server CVE-2026-45659 to its exploited-vulnerabilities catalog, giving federal agencies until July 4 to apply mitigations and run forensic triage. The flaw was patched in May, but active exploitation means on-prem SharePoint teams should verify builds, review exposure, and check for compromise now.
BlueHammer Ransomware Flag Puts Microsoft Defender Patching Back on the Clock
CISA has updated the Microsoft Defender BlueHammer flaw, CVE-2026-33825, to mark it as used in ransomware campaigns. The flaw was patched in April, but the new flag gives Windows teams a fresh reason to verify Defender updates, endpoint telemetry, and local privilege escalation controls.
Daktronics Controller Flaws Put Public Digital Signs on Patch Watch
CISA is warning that flaws in Daktronics DMP-5000, VFC-DMP-5000, and DMP-8000 controller firmware could expose public display systems to root-level compromise. Operators of billboards, highway signs, venues, hospitals, and other connected displays should patch firmware, change default credentials, and verify that controllers are not reachable from the open internet.