CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… 미쓰비시 전기 취약점으로부터 네트워크 보호 계속 읽기
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… 중국 국가 행위자로부터 통신 네트워크 보호 계속 읽기
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… 슈나이더 일렉트릭 Modicon M340 취약점 권고 계속 읽기
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… CISA SBOM 지침 개정안, 산업계 피드백 요청 계속 읽기
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… 지멘스 Mendix SAML 취약점, 긴급 패치 필요 계속 읽기
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… 트렌드 마이크로 Apex One 취약점, 서버 위험 초래 계속 읽기
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Optimize OT Asset Management with CISA’s New Guidance 계속 읽기
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… CISA, 7개의 긴급 ICS 보안 권고 발표 계속 읽기
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… ToolShell 익스플로잇으로부터 SharePoint 서버 보호 계속 읽기
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… CISA, 산업 시스템에 대한 증가하는 위협 경고 계속 읽기
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… CISA, Tigo Energy Cloud Connect Advanced의 치명적 결함 경고 계속 읽기
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… CISA 경고: Güralp FMUS 지진 장치의 치명적 결함 (CVE-2025-8286) 계속 읽기
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… CISA, 사건 대응을 위한 퇴거 전략 도구 발표 계속 읽기
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… CISA, Cisco ISE, PaperCut 취약점을 KEV 카탈로그에 추가 계속 읽기
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… CISA, 미쓰비시 CNC 소프트웨어의 DLL 하이재킹 결함 경고 (CVE-2016-2542) 계속 읽기
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… 천문학자 키스캠 스캔들과 사이버 보안 연관성 없음 계속 읽기
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… CISA, 네트워크 서모스탯 X-Series의 치명적 인증 우회 경고 계속 읽기
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… CISA, DuraComm DP-10iN-100-MU의 고위험 취약점 경고 계속 읽기
사이버 에센셜 제도는 영국의 사이버 보안 노력의 초석으로, 기업이 사이버 위협으로부터 스스로를 보호할 수 있도록 지원합니다. 올해로 10주년을 맞이하는 이 제도는 다음과 같이 개발되었습니다. 사이버 에센셜의 10주년을 기념합니다: 비즈니스 사이버 방어 강화의 10년 계속 읽기
The Cybersecurity and Infrastructure Security Agency today issued a major alert about a sophisticated spear-phishing campaign hitting organizations across various sectors, especially government and IT. CISA said in an alert… 중요 사이버 경보: 해외 위협 행위자가 악성 RDP 첨부 파일로 조직을 공격합니다. 계속 읽기
호주 신호국의 한 부서인 호주 사이버 보안 센터는 사람들을 대상으로 하는 또 다른 지능형 이메일 사기에 대한 중간 수준의 경고를 발표했습니다.... 호주 사이버 보안 센터를 사칭하는 이메일 사기범들 계속 읽기