CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… Continue reading Secure Your Network Against Mitsubishi Electric Vulnerability
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… Continue reading Protect Telecom Networks from Chinese State Actors Now
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… Continue reading Schneider Electric Modicon M340 Vulnerability Advisory
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… Continue reading CISA SBOM Guidance Overhaul Seeks Industry Feedback
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… Continue reading Siemens Mendix SAML Vulnerability Requires Urgent Patching
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… Continue reading Trend Micro Apex One Vulnerability Puts Servers at Risk
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Continue reading Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… Continue reading CISA Releases Seven Urgent ICS Security Advisories
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… Continue reading Protect SharePoint Servers from ToolShell Exploit Now
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… Continue reading CISA warns operators about rising threats to industrial systems
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… Continue reading CISA Warns of Critical Tigo Energy Cloud Connect Advanced Flaws
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… Continue reading CISA Alert: Critical Flaw in Güralp FMUS Seismic Devices (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… Continue reading CISA Releases Eviction Strategies Tool for Incident Response
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… Continue reading CISA Adds Cisco ISE, PaperCut Vulnerabilities to KEV Catalog
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… Continue reading CISA Warns of DLL Hijacking Flaw in Mitsubishi CNC Software (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… Continue reading No Cybersecurity Link to Astronomer Kiss-Cam Scandal
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… Continue reading CISA Warns of Critical Auth Bypass in Network Thermostat X-Series
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… Continue reading CISA Warns of High-Risk Vulnerabilities in DuraComm DP-10iN-100-MU
The Cyber Essentials scheme is a cornerstone of the UK’s cybersecurity efforts, empowering businesses to protect themselves from cyber threats. Now celebrating its tenth year, the scheme, developed by the… Continue reading Celebrating 10 Years of Cyber Essentials: A Decade of Strengthening Business Cyber Defenses
The Cybersecurity and Infrastructure Security Agency today issued a major alert about a sophisticated spear-phishing campaign hitting organizations across various sectors, especially government and IT. CISA said in an alert… Continue reading Critical Cyber Alert: Foreign Threat Actor Targets Organizations with Malicious RDP Attachments
The Australian Cyber Security Centre, which is a division of the Australian Signals Directorate, has just released a medium-level warning regarding another wave of advanced email scams that target people… Continue reading Email Scammers Impersonating the ASD’s Australian Cyber Security Centre