CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… متابعة القراءة أمّن شبكتك ضد ثغرة Mitsubishi Electric
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… متابعة القراءة احمِ شبكات الاتصالات من الجهات الصينية الحكومية الآن
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… متابعة القراءة استشارة حول ثغرة Schneider Electric Modicon M340
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… متابعة القراءة تسعى CISA إلى مراجعة إرشادات SBOM للحصول على ملاحظات الصناعة
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… متابعة القراءة تتطلب ثغرة Siemens Mendix SAML تصحيحًا عاجلاً
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… متابعة القراءة ثغرة Trend Micro Apex One تعرض الخوادم للخطر
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… متابعة القراءة Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… متابعة القراءة تصدر CISA سبعة استشارات أمنية عاجلة لـ ICS
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… متابعة القراءة احمِ خوادم SharePoint من استغلال ToolShell الآن
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… متابعة القراءة تحذر CISA المشغلين من التهديدات المتزايدة على الأنظمة الصناعية
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… متابعة القراءة تحذر CISA من ثغرات خطيرة في Tigo Energy Cloud Connect Advanced
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… متابعة القراءة تنبيه CISA: ثغرة خطيرة في أجهزة Güralp FMUS الزلزالية (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… متابعة القراءة تصدر CISA أداة استراتيجيات الإخلاء للاستجابة للحوادث
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… متابعة القراءة تضيف CISA ثغرات Cisco ISE وPaperCut إلى كتالوج KEV
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… متابعة القراءة تحذر CISA من ثغرة اختطاف DLL في برنامج Mitsubishi CNC (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… متابعة القراءة لا يوجد رابط للأمن السيبراني في فضيحة عالم الفلك Kiss-Cam
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… متابعة القراءة تحذر CISA من تجاوز المصادقة الخطير في Network Thermostat X-Series
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… متابعة القراءة تحذر CISA من ثغرات عالية الخطورة في DuraComm DP-10iN-100-MU
يعد مخطط Cyber Essentials حجر الزاوية في جهود الأمن السيبراني في المملكة المتحدة، حيث يعمل على تمكين الشركات من حماية نفسها من التهديدات السيبرانية. يحتفل المخطط الآن بعامه العاشر، وقد طورته… متابعة القراءة الاحتفال بمرور 10 أعوام على إطلاق Cyber Essentials: عقد من تعزيز الدفاعات السيبرانية للشركات
أصدرت وكالة الأمن السيبراني وأمن البنية التحتية اليوم تحذيرًا كبيرًا بشأن حملة تصيد احتيالي متطورة تستهدف المنظمات عبر قطاعات مختلفة، وخاصة الحكومة وتكنولوجيا المعلومات. قالت CISA في تحذير... متابعة القراءة تنبيه سيبراني بالغ الأهمية: جهة تهديد أجنبية تستهدف المؤسسات بمرفقات RDP ضارة
أصدر مركز الأمن السيبراني الأسترالي، وهو قسم من مديرية الإشارات الأسترالية، تحذيرًا متوسط المستوى بشأن موجة أخرى من عمليات الاحتيال عبر البريد الإلكتروني المتقدمة التي تستهدف الأشخاص... متابعة القراءة محتالو البريد الإلكتروني ينتحلون صفة مركز الأمن السيبراني الأسترالي التابع لـ ASD