CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… Continue reading Proteggi la Tua Rete dalla Vulnerabilità di Mitsubishi Electric
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… Continue reading Proteggi le Reti di Telecomunicazioni dagli Attori Statali Cinesi Ora
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… Continue reading Avviso di Vulnerabilità Schneider Electric Modicon M340
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… Continue reading Revisione della Guida SBOM di CISA Cerca il Feedback dell'Industria
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… Continue reading La Vulnerabilità SAML di Siemens Mendix Richiede una Correzione Urgente
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… Continue reading La Vulnerabilità di Trend Micro Apex One Mette a Rischio i Server
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Continue reading Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… Continue reading CISA Rilascia Sette Avvisi Urgenti di Sicurezza ICS
CISA ha rilasciato un'analisi dettagliata del malware sulle vulnerabilità di SharePoint attivamente sfruttate. L'exploit “ToolShell” concatena CVE-2025-49704 con CVE-2025-49706 per compromettere i server SharePoint, distribuendo web shell e DLL .NET che… Continue reading Proteggi i server SharePoint dall'exploit ToolShell ora
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… Continue reading CISA avverte gli operatori delle crescenti minacce ai sistemi industriali
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… Continue reading CISA Avverte delle Gravi Vulnerabilità in Tigo Energy Cloud Connect Advanced
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… Continue reading Avviso CISA: Vulnerabilità Critica nei Dispositivi Sismici Güralp FMUS (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… Continue reading CISA Rilascia lo Strumento di Strategie di Evacuazione per la Risposta agli Incidenti
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… Continue reading CISA Aggiunge le Vulnerabilità di Cisco ISE e PaperCut al Catalogo KEV
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… Continue reading CISA Avverte della Vulnerabilità di DLL Hijacking nel Software CNC di Mitsubishi (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… Continue reading Nessun Collegamento alla Sicurezza Informatica nello Scandalo dell'Astronomo Kiss-Cam
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… Continue reading CISA Avverte di un Bypass di Autenticazione Critico in Network Thermostat X-Series
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… Continue reading CISA Avverte delle Vulnerabilità ad Alto Rischio in DuraComm DP-10iN-100-MU
Il programma Cyber Essentials è una pietra miliare degli sforzi del Regno Unito in materia di sicurezza informatica, che consente alle aziende di proteggersi dalle minacce informatiche. Il programma, sviluppato dall'Agenzia per la sicurezza informatica, festeggia il suo decimo anno... Continue reading Celebrazione dei 10 anni di Cyber Essentials: Un decennio di rafforzamento delle difese informatiche aziendali
La Cybersecurity and Infrastructure Security Agency ha lanciato oggi un importante allarme su una sofisticata campagna di spear-phishing che sta colpendo organizzazioni di vari settori, in particolare quello governativo e informatico. La CISA ha dichiarato in un avviso... Continue reading Allarme informatico critico: un attore di minaccia straniero prende di mira le organizzazioni con allegati RDP dannosi
L'Australian Cyber Security Centre, una divisione dell'Australian Signals Directorate, ha appena pubblicato un avviso di medio livello riguardante un'altra ondata di truffe avanzate via e-mail che... Continue reading Truffatori via e-mail si spacciano per il Centro australiano per la sicurezza informatica dell'ASD