#cisa

[ follow ]
US politics
fromTheregister
2 days ago

CISA misspent millions in cyber skill retention funds: audit

CISA mismanaged the Cyber Incentive program, allowing widespread ineligible payments, poor recordkeeping, and reduced capacity to protect the nation from cyber threats.
#cve
fromNextgov.com
3 days ago

CISA ready to accept any extension for key cyber info-sharing law, official says

We'll take whatever the Congress decides to authorize us, wherever they see fit within their purview, to authorize and to give us our authorities to be able to use,
Information security
fromNextgov.com
4 days ago

CISA weighs 'alternative funding sources' to preserve cyber vulnerability-tracking project

The Cybersecurity and Infrastructure Security Agency is exploring more diversified funding mechanisms to help cover the cost of a bedrock vulnerability cataloging program that's been relied upon by the cyber community for years. The Common Vulnerabilities and Exposures Program faced a near complete lapse in funding in April when MITRE, the research giant that funds much of the program's functions, warned of an imminent end to federal backing for the cornerstone cybersecurity project. The lapse was reversed within hours after outcry from the cybersecurity community.
Information security
Information security
fromDataBreaches.Net
1 week ago

CISA Delays Cyber Incident Reporting Rule for Critical Infrastructure - DataBreaches.Net

CISA plans to publish the CIRCIA Final Rule in May 2026, delaying its expected October 2025 arrival and likely postponing its effective date.
Information security
fromTheregister
1 week ago

Congress tosses lifeline to cyber intel sharing, grants

Congress must reauthorize and extend cyber information-sharing authorities like CISA to maintain private–public threat intelligence collaboration and protect critical infrastructure.
#cybersecurity
#ransomware
Information security
fromDataBreaches.Net
2 weeks ago

CISA steps in to help Nevada state government recover from cyberattack - DataBreaches.Net

CISA, the FBI, and other federal and state teams are collaborating to investigate, contain, and restore Nevada's systems after a cyberattack while securing recovery grants.
Information security
fromSecuritymagazine
3 weeks ago

CISA Issues Software Bill of Materials Draft, Encourages Public Comments

Updated minimum elements for SBOMs guide standardized, machine-readable SBOM generation and sharing to improve software supply chain transparency and risk-informed cybersecurity decisions.
fromTheregister
1 month ago

Microsoft Exchange bug can allow 'total domain compromise'

CVE-2025-53786 is an elevation of privilege bug that Outsider Security's Dirk-jan Mollema reported to Microsoft. It exists because of the way hybrid Exchange deployments, which connect on-premises Exchange servers to Exchange Online, use a shared identity to authenticate users between the two environments.
Privacy professionals
fromTheregister
1 month ago

CISA releases malware analysis for Sharepoint Server attack

CISA analysed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data.
Privacy professionals
fromThe Hacker News
1 month ago

Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups

In an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization's connected cloud environment without leaving easily detectable and auditable traces.
Privacy professionals
Privacy professionals
fromTheregister
1 month ago

Microsoft warns on-prem SharePoint users of a zero-day

Microsoft warns of an active zero-day vulnerability in SharePoint Server, allowing unauthorized access due to incomplete past updates.
US politics
fromNextgov.com
1 month ago

Trump's CISA nominee to testify before Senate panel next week

Sean Plankey is scheduled to testify before the Senate Homeland Security Committee regarding his nomination to lead the Cybersecurity and Infrastructure Security Agency.
fromBreaking Defense
2 months ago

Iran may go after US defense firms with cyber attacks, warn Pentagon, Homeland Security

Homeland Security's Cybersecurity & Infrastructure Security Agency warned US defense contractors working in Israel that they may be targeted by Iranian cyber attacks.
US politics
fromIT Pro
2 months ago

Want to build more secure software? Follow these key memory safe language tips from CISA

Achieving better memory safety demands language-level protections, library support, robust tooling, and developer training, as traditional languages can't eliminate vulnerabilities as effectively.
Software development
fromTheregister
2 months ago

AWS enforces MFA across 100% of root users: re:Inforce

For anyone who still has doubts about MFA: just ask Snowflake CISO Brad Jones, who last year saw more than 160 of his customers' accounts compromised using stolen credentials. None of these had MFA enabled, and this safeguard likely would have prevented the intruders from accessing the customers' databases.
Marketing tech
fromIT Pro
4 months ago

CISA issues warning in wake of Oracle cloud credentials leak

CISA warns of potential data breach risks from a security incident involving legacy Oracle cloud environments, urging enterprises to strengthen their security defenses.
Information security
#chris-krebs
fromArs Technica
4 months ago
Privacy professionals

Chris Krebs, who debunked 2020 election lies, vows full-time fight against Trump

CISA's Chris Krebs was terminated by Trump after debunking election fraud claims, emphasizing integrity amidst political pressure.
fromTechzine Global
4 months ago
Privacy professionals

SentinelOne exec Krebs leaves following Trump pressure

Chris Krebs resigns from SentinelOne to focus on fighting Trump's retaliatory actions against him and the company.
Privacy professionals
fromArs Technica
4 months ago

Chris Krebs, who debunked 2020 election lies, vows full-time fight against Trump

CISA's Chris Krebs was terminated by Trump after debunking election fraud claims, emphasizing integrity amidst political pressure.
fromTechzine Global
4 months ago

MITRE CVE database saved after last minute reversal

The U.S. government extended funding for the CVE database for eleven months, preventing the crucial cybersecurity resource from going offline due to funding discontinuation.
Information security
[ Load more ]