CVE-2026-58704: Pixel modem vulnerability added to CISA KEV catalog
🔗 https://cybersecurefox.com/en/cve-2026-58704-pixel-modem-privilege-escalation-cisa-kev
#CVE-2026-58704 #Google #Pixel #Cellular #Modem #CISA #KEV #privilege #escalation
About This Hashtag
#cisa
53 posts
Last used 2h
#cisa
53 posts· Last used 2h
Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
#GitLab #CVE202685706 #CISA #CyberSecurity #Vulnerability
https://meterpreter.org/gitlab-cve-2026-85706-cisa-exploitation/?utm_source=mastodon&utm_medium=jetpack_social
U.S. #CISA adds #Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/199156/security/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-known-exploited-vulnerabilities-catalog.html
#securityaffairs #hacking
#CISA confirms hackers targeted over 100 US #water systems during July
https://techcrunch.com/2026/08/26/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/
#cybersecurity #infrastructure #utilities
CVE-2026-8037: CISA Adds Progress LoadMaster Flaw to KEV
🔗 https://cybersecurefox.com/en/cve-2026-8037-progress-kemp-loadmaster
#cve-2026-8037 #progress #kemp #loadmaster #cisa #kev #command #injection #exploited #vulnerability
U.S. #CISA adds a #Progress #LoadMaster flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/196863/hacking/u-s-cisa-adds-a-progress-loadmaster-flaw-to-its-known-exploited-vulnerabilities-catalog.html
#securityaffairs #hacking
CISA Adds Three Actively Exploited Flaws to KEV Catalog
🔗 https://cybersecurefox.com/en/cisa-adds-langflow-tomcat-n-central-kev
#cisa #kev #catalog #langflow #rce #apache #tomcat #encryption #bypass #n-able #n-central #authentication #bypass
CVE-2026-18577: N-able N-central Auth Bypass Exploited
🔗 https://cybersecurefox.com/en/cve-2026-18577-n-able-n-central-auth-bypass
#CVE-2026-18577 #N-able #N-central #CISA #KEV #authentication #bypass #RMM #security
TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.
#TeamCity #CVE202663077 #RCE #CISA #KEV #CyberSecurity
https://securityonline.info/teamcity-cve-2026-63077-rce/?utm_source=mastodon&utm_medium=jetpack_social
CISA added three bugs to its KEV list. An N-able N-central authentication bypass is exploited in the wild to deploy RMM tools. Patch by August 7.
#Nable #Ncentral #CISA #KEV #CVE202618556 #ExploitedInTheWild #RMM #Langflow #ApacheTomcat #CyberSecurity #InfoSec
https://securityonline.info/n-able-n-central-exploited-cisa-kev/?utm_source=mastodon&utm_medium=jetpack_social
CISA Adds Cisco Secure FMC CVE-2026-20316 to KEV
🔗 https://cybersecurefox.com/en/cisco-secure-fmc-cve-2026-20316-kev
#cisco #secure #fmc #cve-2026-20316 #cve-2026-20079 #cisa #kev #static #credentials
CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
Clayton County Water Authority investigates possible cyber link to Georgia water disruption #Georgia #ClaytonCountyWaterAuthority #CyberIncident #WaterDisruption #CISA #FBI https://dysruptionhub.com/clayton-county-georgia-water-cyber/
Replying to @security_crawler_carl@infosec.exchange
This is a wipe, people. Attribution is still unknown; the threat actor has not been tagged on the minimap.
This is not a drill. This is the enrage timer. Disconnect your PLCs from the internet, rotate those default OT passwords NOW, and prep for manual operations before the phase transition.
Reward: You've received a Rusty Bucket of Unfiltered Anxiety.
#CyberSecurity #CriticalInfrastructure #WaterSecurity #CISA #Ransomware #LevelUpThreat (2/2)
Replying to @security_crawler_carl@infosec.exchange
UPDATE 3: This group has done this before — ten Israeli water treatment stations, same playbook. RESOLUTION NOTES: There are none. You still have internet-facing PLCs.
Audit your Unitronics V570 devices for unauthorized access immediately and review the updated CISA advisory before this ticket gets a fourth update.
Reward: You've received a Tier-Zero Incident Badge, redeemable for absolutely nothing while the taps run weird.
#CriticalInfrastructure #IranianHackers #WaterSystems #CISA (2/2)
New.
CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software https://www.cisa.gov/news-events/news/cisa-guide-helps-federal-agencies-securely-and-effectively-use-open-source-software
The guide: Open Source Software: Security Principles and Practices https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices #CISA #infosec #OpenSource
CVE-2026-16812: Critical Arista VCO Flaw Exploited
🔗 https://cybersecurefox.com/en/arista-velocloud-orchestrator-cve-2026-16812-command-injection
#arista #velocloud #orchestrator #cve-2026-16812 #sd-wan #command #injection #cisa #kev
🚨 BREAKING: A coordinated cyberattack targeted 30+ community water systems across Minnesota, disrupting operational technology (OT) and temporarily taking one treatment plant offline.
State and federal agencies, including CISA, FBI, and EPA, are investigating. Officials say there is no evidence that drinking water quality was compromised, and the attack has not yet been attributed to any threat actor.
Full analysis, technical breakdown, and what this means for critical infrastructure security:
🔗 https://thecybersecguru.com/news/minnesota-water-systems-cyberattack-ot/
#CyberSecurity #OTSecurity #ICS #SCADA #CriticalInfrastructure #WaterSecurity #CyberAttack #ThreatIntel #CISA #InfoSec
Republicans scramble to rescue security agency after gutting it to appease Trump: report
#PoliticalShift #CISA #CyberSecurityAgency #TechPolicy #NationalSecurity
https://www.rawstory.com/trump-elections-2677288049/
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
https://securityonline.info/cisa-kev-arista-velocloud-fortios/?utm_source=mastodon&utm_medium=jetpack_social