CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… Continuați lectura Asigură-ți Rețeaua Împotriva Vulnerabilității Mitsubishi Electric
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… Continuați lectura Protejează Rețelele de Telecomunicații de Actorii Statului Chinez Acum
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… Continuați lectura Avertizare de Vulnerabilitate Schneider Electric Modicon M340
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… Continuați lectura Revizuirea Ghidului SBOM de către CISA Solicită Feedback din Industrie
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… Continuați lectura Vulnerabilitatea Siemens Mendix SAML Necesită Patch-uri Urgente
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… Continuați lectura Vulnerabilitatea Trend Micro Apex One Pune Serverele în Pericol
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Continuați lectura Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… Continuați lectura CISA Lansează Șapte Avertizări Urgente de Securitate ICS
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… Continuați lectura Protejează Serverele SharePoint de Exploatarea ToolShell Acum
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… Continuați lectura CISA avertizează operatorii despre amenințările în creștere la adresa sistemelor industriale
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… Continuați lectura CISA Avertizează despre Defectele Critice din Tigo Energy Cloud Connect Advanced
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… Continuați lectura Alertă CISA: Defect Critic în Dispozitivele Seismice Güralp FMUS (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… Continuați lectura CISA Lansează Instrumentul de Strategii de Evacuare pentru Răspunsul la Incidente
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… Continuați lectura CISA Adaugă Vulnerabilitățile Cisco ISE, PaperCut în Catalogul KEV
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… Continuați lectura CISA Avertizează despre Defectul de Hijacking DLL în Software-ul CNC Mitsubishi (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… Continuați lectura Nicio Legătură de Securitate Cibernetică cu Scandalul Kiss-Cam al Astronomului
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… Continuați lectura CISA Avertizează despre Ocolirea Critică a Autentificării în Termostatul de Rețea X-Series
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… Continuați lectura CISA Avertizează despre Vulnerabilitățile de Mare Risc în DuraComm DP-10iN-100-MU
Sistemul Cyber Essentials reprezintă piatra de temelie a eforturilor Regatului Unit în materie de securitate cibernetică, permițând întreprinderilor să se protejeze împotriva amenințărilor cibernetice. Aflat acum în al zecelea an de existență, sistemul, dezvoltat de... Continuați lectura Sărbătorim 10 ani de Cyber Essentials: Un deceniu de consolidare a apărării cibernetice a întreprinderilor
Agenția pentru Securitate Cibernetică și Securitate a Infrastructurii a emis astăzi o alertă majoră cu privire la o campanie sofisticată de spear-phishing care lovește organizații din diverse sectoare, în special guvernamentale și IT. CISA a afirmat într-o alertă... Continuați lectura Alertă cibernetică critică: Actorul străin al amenințărilor vizează organizațiile cu atașamente RDP rău intenționate
Australian Cyber Security Centre, care este o divizie a Australian Signals Directorate, tocmai a lansat un avertisment de nivel mediu cu privire la un alt val de escrocherii avansate prin e-mail care vizează persoanele... Continuați lectura Escroci prin e-mail care se dau drept Centrul Australian de Securitate Cibernetică al ASD