Advertisement
CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure
A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development. This leak poses a
Securing Agentic AI: CISA and International Partners Issue Guidance
CISA and international partners release guidance on securing agentic AI services, detailing risks like autonomous execution and supply chain vulnerabilities.
CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits
CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate
White House FY2027 Budget Proposes $707 Million CISA Funding Cut
The White House proposes a $707 million reduction to CISA's budget for FY2027, refocusing the agency on federal agency and critical infrastructure protection.
FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance
CISA mandates federal agencies patch the critical FortiClient EMS SQL injection flaw, CVE-2023-48788, which allows unauthenticated remote code execution.
Langflow CVE-2026-33017: AI Workflow Hijacking Under Active Exploitation
CISA warns of active exploitation of CVE-2026-33017 in Langflow, enabling attackers to hijack AI workflows and potentially compromise AI agents.

Russian Intelligence Phishing Targets Signal and WhatsApp Accounts
FBI and CISA warn that Russian state-sponsored actors are using sophisticated phishing to compromise high-value Signal and WhatsApp accounts.
CVE-2024-38094: SharePoint RCE Exploited in the Wild — Patch Now
CISA adds CVE-2024-38094 to its KEV catalog after active exploitation of a SharePoint RCE vulnerability. Learn how to detect and remediate this threat.
Hardening Endpoint Management Systems: CISA Alert on Intune Attacks
CISA warns of active cyberattacks targeting endpoint management systems, specifically Microsoft Intune. Learn how to implement least privilege, MFA, and Multi Admin
CISA Warns of RESURGE Malware Persistence on Ivanti Devices
CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.
Critical Vulnerabilities in Gardyn Smart Gardens Enable Remote Takeover
CISA warns of critical flaws in Gardyn Smart Gardens, including CVE-2024-39682 and CVE-2024-39683, allowing remote code execution and unauthorized access.
Exploitation of Roundcube Webmail Cross-Site Scripting Vulnerabilities
CISA has added two Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation of legacy flaws in webmail infrastructure.