CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Bối cảnh: Các đội an ninh cần lưu ý Mitsubishi Electric đã xác định một lỗ hổng trong một loạt các mô-đun CPU Dòng MELSEC iQ-F—CVE-2025-7405—và nó có điểm cơ bản khoảng… Tiếp tục đọc Bảo Vệ Mạng Của Bạn Trước Lỗ Hổng Mitsubishi Electric
Các đội an ninh cần biết—CISA đã đưa ra một khuyến cáo với FBI và một số đối tác quốc tế về Salt Typhoon. Họ là những tác nhân nhà nước Trung Quốc tấn công các mạng viễn thông trên toàn cầu, thậm chí cả ở Canada… Tiếp tục đọc Bảo Vệ Mạng Viễn Thông Khỏi Các Tác Nhân Nhà Nước Trung Quốc Ngay Bây Giờ
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… Tiếp tục đọc Khuyến Cáo Lỗ Hổng Schneider Electric Modicon M340
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… Tiếp tục đọc CISA Cải Tổ Hướng Dẫn SBOM Tìm Kiếm Phản Hồi Từ Ngành Công Nghiệp
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… Tiếp tục đọc Lỗ Hổng SAML Siemens Mendix Yêu Cầu Vá Khẩn Cấp
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… Tiếp tục đọc Lỗ Hổng Trend Micro Apex One Đặt Máy Chủ Vào Nguy Cơ
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… Tiếp tục đọc Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… Tiếp tục đọc CISA Phát Hành Bảy Khuyến Cáo An Ninh ICS Khẩn Cấp
CISA đã phát hành một phân tích phần mềm độc hại chi tiết về các lỗ hổng SharePoint đang bị khai thác tích cực. Lỗ hổng “ToolShell” kết hợp CVE-2025-49704 với CVE-2025-49706 để xâm nhập máy chủ SharePoint, triển khai web shell và .NET DLLs mà… Tiếp tục đọc Bảo vệ máy chủ SharePoint khỏi lỗ hổng ToolShell ngay bây giờ
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… Tiếp tục đọc CISA cảnh báo các nhà điều hành về các mối đe dọa gia tăng đối với hệ thống công nghiệp
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… Tiếp tục đọc CISA Cảnh Báo Về Các Lỗ Hổng Nghiêm Trọng Trong Tigo Energy Cloud Connect Advanced
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… Tiếp tục đọc Cảnh Báo CISA: Lỗ Hổng Nghiêm Trọng Trong Thiết Bị Địa Chấn Güralp FMUS (CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… Tiếp tục đọc CISA Phát Hành Công Cụ Chiến Lược Trục Xuất Cho Phản Ứng Sự Cố
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… Tiếp tục đọc CISA Thêm Lỗ Hổng Cisco ISE, PaperCut Vào Danh Mục KEV
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… Tiếp tục đọc CISA Cảnh Báo Về Lỗ Hổng DLL Hijacking Trong Phần Mềm CNC Mitsubishi (CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… Tiếp tục đọc Không Có Liên Kết An Ninh Mạng Đến Vụ Tai Tiếng Kiss-Cam Của Nhà Thiên Văn
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… Tiếp tục đọc CISA Cảnh Báo Về Lỗ Hổng Bỏ Qua Xác Thực Nghiêm Trọng Trong Network Thermostat X-Series
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… Tiếp tục đọc CISA Cảnh Báo Về Các Lỗ Hổng Nguy Cơ Cao Trong DuraComm DP-10iN-100-MU
Chương trình Cyber Essentials là nền tảng cho các nỗ lực an ninh mạng của Vương quốc Anh, trao quyền cho các doanh nghiệp tự bảo vệ mình khỏi các mối đe dọa trên mạng. Hiện đang kỷ niệm năm thứ mười, chương trình do… Tiếp tục đọc Kỷ niệm 10 năm Cyber Essentials: Một thập kỷ tăng cường phòng thủ mạng cho doanh nghiệp
Cơ quan An ninh mạng và Cơ sở hạ tầng hôm nay đã ban hành một cảnh báo lớn về một chiến dịch lừa đảo tinh vi nhắm vào các tổ chức trên nhiều lĩnh vực, đặc biệt là chính phủ và CNTT. CISA cho biết trong một cảnh báo… Tiếp tục đọc Cảnh báo mạng quan trọng: Tác nhân đe dọa nước ngoài nhắm vào các tổ chức có tệp đính kèm RDP độc hại
Trung tâm An ninh mạng Úc, một bộ phận của Cục Tín hiệu Úc, vừa đưa ra cảnh báo cấp trung bình về một làn sóng lừa đảo qua email tinh vi khác nhắm vào những người… Tiếp tục đọc Những kẻ lừa đảo qua email mạo danh Trung tâm an ninh mạng Úc của ASD