< ciso
brief />
Tag Banner

All news with #advisory tag

380 articles

CISA flags critical Progress Kemp LoadMaster flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster. The flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched appliances via unsanitized API inputs. Progress released patches in June for affected GA and LTSF versions, and CISA has directed federal agencies to remediate within three days.
read more →

CISA warns of active exploits in three products

🚨 The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. The most severe issue, tracked as CVE-2026-9198, impacts Langflow and permits unauthenticated remote code execution via chained API endpoints. Vendors have released patches and a hotfix, but incomplete fixes and public proof-of-concept exploits have enabled ongoing attacks. CISA added all three flaws to its Known Exploited Vulnerabilities catalog and urged immediate remediation.
read more →

N‑able warns of N‑central auth bypass actively exploited

🔒 N‑able has issued a hotfix (2026.3.1.7) after detecting active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting hosted and on-premises N-central servers. The vendor disclosed the issue on August 1 and released an update the following day, urging immediate upgrade to versions 2026.3 or later. Hosted deployments were updated automatically; on-premises customers must install the patch manually. Indicators of compromise and mitigation guidance are available on the hotfix download page.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

Arista fixes critical VeloCloud Orchestrator flaw

🔒 Arista has released patches for a critical vulnerability in VeloCloud Orchestrator (VCO) that is actively being exploited in the wild. The vendor warned the flaw may allow remote attackers to access privileged internal functionality and impact VCO hosts, affecting confidentiality, integrity, and availability. Customers are urged to upgrade to fixed releases (VCO 5.2.3.14+, 6.1.3.4+, 6.4.2.4+) and to consider incident response actions such as credential rotation and device validation. Advisors stressed the severity—an unauthenticated command‑injection in an orchestration platform—and warned that on‑premises users often receive fixes more slowly than cloud deployments.
read more →

Check Point issues fixes for actively exploited flaw

🛡️ Check Point released security updates for Security Management and Multi-Domain Management products to address multiple vulnerabilities, including a critical authentication bypass (CVE-2026-16232) actively exploited in the wild. The flaw enables unauthenticated attackers to obtain a SmartConsole login token and gain full administrative privileges if Management is exposed to the internet without Trusted Client or firewall restrictions. Additional patches cover two other high-severity issues (CVE-2026-62144 and CVE-2026-62145). Customers are urged to apply the July 22 Jumbo hotfix, restrict Trusted Clients to trusted IPs, and secure Management access with firewall protections.
read more →

Eclypsium InfraTrust highlights top infrastructure fixes

🛡️ Eclypsium launched InfraTrust and a monthly InfraTrust Pulse to aggregate vendor infrastructure advisories and guide administrators on which flaws to patch first. The inaugural July 2026 Pulse tracked 61 advisories from 14 vendors, flagging six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report emphasizes prioritizing flaws by exploitability, exposure, and real-world risk rather than CVSS alone.
read more →

OpenSSL HollowByte memory-exhaustion flaw analysis

🛡️ OpenSSL received a silent June fix for a denial-of-service issue Okta branded "HollowByte," which causes servers to allocate up to 131 KB per TLS ClientHello before the body arrives. The bug lets attackers exhaust connections and, on glibc systems, fragment the heap so freed memory remains resident until process restart. Fixed releases are 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 dated June 9, but OpenSSL chose to treat the change as a "bug or hardening" without a CVE, advisory, or changelog note.
read more →

Chained Zero-Day Flaws in Siemens ROX II Switches

🛡️ This Unit 42 advisory, developed in partnership with Siemens, describes a chained exploit of three zero-day vulnerabilities in Siemens ROX II OT switches. The chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) enables arbitrary file disclosure, root privilege escalation and persistent root execution, risking full device compromise. Siemens has issued advisories and a firmware update V2.17.1; Palo Alto Networks provides virtual patching and OT device protections.
read more →

CISA urges immediate SharePoint hardening now

🔒 CISA has warned that three Microsoft SharePoint vulnerabilities are being actively exploited and urged organizations to immediately patch on-premises SharePoint deployments. Administrators should follow Microsoft’s mitigation guidance, enable AMSI integration, hunt for indicators of compromise, and rotate machine keys where appropriate. The agency added CVE-2026-33201, CVE-2026-45659, and the newly listed CVE-2026-56164 to its Known Exploited Vulnerabilities catalog and required rapid remediation for federal agencies.
read more →

Microsoft July 2026 Patch Tuesday: 570+ Vulnerabilities

🔒 July’s Patch Tuesday from Microsoft addressed an unprecedented number of vulnerabilities, with reports of 570–622 CVEs (620 if platform-level fixes are counted), plus hundreds in Chromium. The release includes many high-severity flaws — notably elevation of privilege and remote code execution bugs — with only three zero-days and 59 critical issues. Microsoft’s new summary-style advisories and its AI-powered MDASH scanning explain the surge, forcing organizations to reassess patch management and prioritization.
read more →

FSB Centre 16 Targets Routers Using Weak SNMP

🔒 Cyber agencies from 12 countries warn that Russian FSB Centre 16 (aka Berserk Bear/Static Tundra) is scanning the internet for routers using default or weak SNMP credentials and occasionally exploiting known CVEs in Cisco devices. Sectors such as communications, defence, energy, finance, government and healthcare are urged to adopt SNMPv3, patch affected systems and disable vulnerable features like Smart Install when patching is not possible. The advisory links Centre 16’s tactics to broader disruptive campaigns and coincides with UK/EU attribution of late 2025 attacks on Poland’s energy grid to the group.
read more →

Talos: Multiple Vulnerabilities in WolfSSL, GeoVision, VTK

🔒 Cisco Talos disclosed multiple vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM, all of which have been patched by vendors in line with Cisco’s disclosure policy. The findings include three WolfSSL issues (two improper input validation and one integer underflow), 14 GeoVision advisories spanning 37 CVEs, and one heap-based buffer overflow in VTK-DICOM. Snort rules to detect exploit attempts are available from Snort.org. Discoveries were made by Ankur Tyagi, Philippe Laulheret, and Emmanuel Tacheau of Cisco Talos.
read more →

Max-severity Adobe ColdFusion flaw being actively exploited

🔧 Adobe has issued emergency updates to fix a maximum-severity ColdFusion vulnerability (CVE-2026-48282) that is now being actively exploited, the Canadian Center for Cyber Security (CCCS) warned. The flaw affects ColdFusion 2025.9, 2023.20, and earlier, enabling unauthenticated remote code execution on unpatched systems. Adobe urges administrators to install the patch immediately, and Shadowserver reports nearly 800 exposed ColdFusion instances online.
read more →

FBI warns Russian actors stealing Signal backup keys

🔐 The FBI and CISA warn that Russian-linked threat actors have shifted phishing tactics to steal Signal Backup Recovery Keys, enabling access to users' historical messages. The campaign, tracked as UNC5792 and UNC4221, targets high-value individuals including officials, journalists, and military personnel. Attackers impersonate Signal support, trick users into enabling backups and then request the recovery key to restore data to attacker-controlled devices. Authorities advise that official support never asks for codes or recovery keys and recommend reporting incidents to the FBI or CISA.
read more →

CISA urges hardening of Fortinet devices after breaches

🔒 CISA warns that malicious actors have targeted internet-accessible Fortinet devices using compromised credentials, a campaign dubbed FortiBleed affecting roughly 74,000 devices including firewalls and VPN gateways. The agency urges immediate actions such as terminating active SSL VPN and administrative sessions, resetting credentials, enforcing strong password policies, and ensuring secure credential storage using PBKDF2. Organizations should review logs for suspicious activity, enable phishing-resistant MFA for remote and administrative access, and restrict management interfaces from public internet exposure.
read more →

PavilionX Missing Authorization Vulnerability Adviso

🔒 A security issue was identified in Rockwell Automation FactoryTalk Analytics PavilionX due to improper authorization enforcement in API endpoints, allowing unauthorized actors to perform privileged operations such as user and role management. Rockwell Automation recommends updating PavilionX to version 7.01 or later. CISA advises minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods while performing impact analysis before defensive changes.
read more →

Rockwell Logix 5370/5570 CIP Denial-of-Service Fixes

🛡️ A denial-of-service vulnerability in Rockwell Automation Logix 5370 and 5570 controllers can cause a major nonrecoverable fault (MNRF) when a crafted CIP message is processed, with devices having less memory at greater risk. Rockwell advises updating to specific firmware versions: CompactLogix 5370 (34.016+), Compact GuardLogix 5370 (35.015+), ControlLogix 5570 (36.012+), and GuardLogix 5570 (37.011+). CISA recommends minimizing network exposure, isolating control networks behind firewalls, using secure remote access methods such as VPNs, and following ICS defensive best practices to reduce exploitation risk.
read more →

RSLinx Classic vulnerability advisory and mitigations

🔒 This advisory describes a stack-based buffer overflow and an out-of-bounds read in Rockwell Automation RSLinx Classic Third-Party components that can cause denial of service or enable remote code execution. Rockwell recommends upgrading to version 4.60.00 or later or applying patch BF31213 where upgrades are not possible. CISA urges minimizing network exposure, isolating control systems behind firewalls, and using secure remote access methods such as updated VPNs while performing impact analysis and risk assessments.
read more →

CISA Adds Two Vulnerabilities to KEV Catalog

🔔 CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. The agency emphasizes these flaws are common attack vectors that present substantial risk to the federal enterprise. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk CVEs in the KEV catalog and to assess potential compromise before patching. CISA urges all organizations to adopt risk-based vulnerability management and to submit suspected exploited flaws via the KEV Nomination Form.
read more →