CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… Folytassa az olvasást Védje hálózatát a Mitsubishi Electric sebezhetőséggel szemben
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… Folytassa az olvasást Védje a távközlési hálózatokat a kínai állami szereplőktől most
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… Folytassa az olvasást Schneider Electric Modicon M340 sebezhetőségi tanácsadás
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… Folytassa az olvasást CISA SBOM útmutató átdolgozása iparági visszajelzést keres
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… Folytassa az olvasást Siemens Mendix SAML sebezhetőség sürgős javítást igényel
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… Folytassa az olvasást Trend Micro Apex One sebezhetőség veszélyezteti a szervereket
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Folytassa az olvasást Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… Folytassa az olvasást CISA hét sürgős ICS biztonsági tanácsot ad ki
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… Folytassa az olvasást Védje a SharePoint szervereket a ToolShell kihasználással szemben most
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… Folytassa az olvasást CISA figyelmezteti az üzemeltetőket az ipari rendszerek növekvő fenyegetéseire
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… Folytassa az olvasást CISA figyelmeztet a kritikus Tigo Energy Cloud Connect Advanced hibákra
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… Folytassa az olvasást CISA figyelmeztetés: Kritikus hiba a Güralp FMUS szeizmikus eszközökben (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… Folytassa az olvasást CISA kiadja a kilakoltatási stratégiák eszközt az incidensekre való reagáláshoz
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… Folytassa az olvasást CISA hozzáadja a Cisco ISE, PaperCut sebezhetőségeket a KEV katalógushoz
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… Folytassa az olvasást CISA figyelmeztet a DLL eltérítési hibára a Mitsubishi CNC szoftverben (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… Folytassa az olvasást Nincs kiberbiztonsági kapcsolat a csillagász csók-kamera botránnyal
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… Folytassa az olvasást CISA figyelmeztet a kritikus hitelesítési megkerülésre a Network Thermostat X-Series-ben
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… Folytassa az olvasást CISA figyelmeztet a magas kockázatú sebezhetőségekre a DuraComm DP-10iN-100-MU-ban
A Cyber Essentials program az Egyesült Királyság kiberbiztonsági erőfeszítéseinek sarokköve, amely lehetővé teszi a vállalkozások számára, hogy megvédjék magukat a kiberfenyegetésektől. Most ünnepli tizedik évét, a programot a… Folytassa az olvasást A Cyber Essentials 10 éves évfordulójának ünneplése: Egy évtized az üzleti kiberbiztonság megerősítésében
A Kiberbiztonsági és Infrastruktúra Biztonsági Ügynökség ma jelentős figyelmeztetést adott ki egy kifinomult célzott adathalász kampányról, amely különböző ágazatok, különösen a kormányzati és IT szervezeteket érinti. A CISA egy figyelmeztetésben közölte… Folytassa az olvasást Kritikus Kibertámadás Értesítés: Külföldi Fenyegető Szereplő Célozza a Szervezeteket Rosszindulatú RDP Mellékletekkel
The Australian Cyber Security Centre, which is a division of the Australian Signals Directorate, has just released a medium-level warning regarding another wave of advanced email scams that target people… Folytassa az olvasást Email Scammers Impersonating the ASD’s Australian Cyber Security Centre