< ciso
brief />
Tag Banner

All news with #critical infrastructure tag

470 articles

OT Coalition Urges CISA to Mandate Federal OT Security

🔐 The Operational Technology Cybersecurity Coalition (OTCC) urged CISA to issue a binding operational directive requiring mandatory OT security across federal civilian agencies, citing lack of minimum practices and limited visibility into risks. The report highlights OT in over 8,000 GSA-managed facilities and follows a GAO finding that most agencies missed OMB inventory requirements. The proposed directive would set baselines for asset inventory, segmentation, remote access, configuration, incident preparedness and recovery.
read more →

Warlock ransomware exploits SharePoint to hit critical services

🔒 A China-linked group known as Warlock exploited Microsoft SharePoint vulnerabilities to compromise a water utility, a telecom operator, a regional government, and a university across Portuguese- and Spanish-speaking regions. The actor used web shells, staged the ransomware in SYSVOL to propagate via Group Policy, and disabled protection on dozens of hosts before deploying the ransomware. Symantec and Carbon Black link the activity to Longlegs and provide IoCs and technical details.
read more →

Critical Dell CSM Flaws Allow Full Administrative Access

🔒 Dell released updates to fix multiple critical flaws in Container Storage Modules (CSM) that allow unauthenticated attackers to gain administrative control, escalate privileges, or forge tokens. Affected versions are all prior to 1.17.0, and the fixes are included in 1.18.0. Dell urges immediate updating and rotation of JWT signing secrets, as no effective mitigations exist aside from upgrading.
read more →

GitLab warns of critical RCE in AI Gateway

🔔 GitLab warned customers to immediately patch a critical AI Gateway vulnerability that could allow attackers to execute arbitrary commands on vulnerable instances. The flaw, tracked as CVE-2026-90970, affects self-hosted AI Gateway deployments and stems from improper neutralization allowing sandbox escape by authenticated users with Duo Agent Platform access. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue and said hosted AI Gateway users are already protected.
read more →

Unidentified Flock Cameras Found in Florida County

📷 St. Lucie County, Florida found a dozen unpermitted Flock surveillance cameras whose ownership is unknown. The situation echoes past incidents like StingRay cell-site simulators in Washington, DC, where operators were never identified. The author suggests local government actors are likelier culprits than foreign parties, and warns that normalizing surveillance infrastructure invites widespread use.
read more →

CISA warns of critical pre-auth RCE in RouterOS

🔒 CISA has issued an alert about a critical pre-authentication vulnerability (CVE-2026-84411) in MikroTik RouterOS that can lead to remote code execution or denial of service. The flaw is an integer underflow in the web-management HTTP request handling and can be triggered by a single crafted request to achieve root-level code execution. Affected RouterOS releases are reported to be below 7.24, and MikroTik recommends updating to 7.23 or later; the vendor has not yet published its own advisory.
read more →

Pentagon personnel data breach affects millions

🛡️ The US Department of Defense confirmed a breach at the Defense Manpower Data Center (DMDC) exposing just over three million records, including Social Security numbers, names, birth dates, contact details, and some job information. Unauthorized access occurred between October 2025 and July 16, 2026, remaining undetected for nine months until a file‑sharing vulnerability was patched. The Pentagon says it has seen no evidence of misuse and is offering 12 months of identity protection and credit monitoring to those affected. The incident raises concerns about espionage, targeted spear‑phishing, and the risks posed when personnel records include job details.
read more →

Critical Citrix NetScaler DTLS Overflow Under Active Exploitation

🔒 Researchers disclosed details of a critical memory overflow in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 9.5). The flaw stems from improper DTLS fragment parsing in the NetScaler Packet Processing Engine, allowing crafted records to overflow a scratch buffer and enable remote code execution or denial-of-service. Vendor and researchers show how reassembly of many small fragments can produce a large NSB chain, enabling shellcode execution by bypassing NX protections with mprotect().
read more →

Kiteworks fixes critical vulnerability after shutdown

🛡️ Kiteworks worked with federal intelligence authorities during a scheduled precautionary shutdown to identify and fix a critical vulnerability affecting fewer than 1% of customers. The company developed and deployed a patch and added an extra protective layer across all environments, and said there is no evidence the flaw was exploited. Customers were advised to bring systems back online after the threat window passed and no anomalies were observed.
read more →

Tokyo railway operators disclose separate cyber incidents

🚆 Tokyo Metro and Keio Corporation have disclosed separate cyber incidents affecting customer data and corporate systems, respectively. Tokyo Metro confirmed unauthorized access to the email addresses of 59,000 Metpo loyalty members and has taken steps to prevent recurrence, warning of potential phishing attempts. Keio reported a ransomware attack that disrupted sales systems and prompted police investigation while ensuring train operations remain unaffected. A related breach at Times Car may have exposed personal data for up to 6.6 million individuals, raising broader transport-sector concerns.
read more →

CISA publishes election security plan ahead of 2026

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) released an Election Infrastructure Security Plan on September 24, 2026, to guide federal, state, and local bodies in mitigating cyber and physical threats ahead of the November 3 midterm elections. The plan outlines risks to physical assets and ICT systems—including voter registration databases and voting machines—and recommends measures such as harmonized patch management, paper ballots, MFA, continuous monitoring, and insider-risk mitigations. CISA also detailed no-cost services like tabletop exercises, penetration testing, vulnerability scanning, and regional coordination to help election stakeholders strengthen defenses.
read more →

Chinese actors exploit multiple flaws to steal data

🛡️ GreyNoise reports a Chinese-speaking threat actor exploited vulnerabilities across ZyXEL GS1900 switches and WordPress to compromise 996 devices and exfiltrate over 18,500 backend records. The campaign, tied to a group related to Red Heron, leveraged public wp2shell exploits and multiple other CVEs to target governments, small businesses, and infrastructure. Observed activity began in June 2026, with extensive post-exploitation reconnaissance and credential harvesting noted in at least one Western government breach.
read more →

Critical Check Point flaw allows root code execution

🔒 Check Point Software released updates for a critical stack-based buffer overflow (CVE-2026-91843) in Security Management Server and Log Server login flows that can enable remote root code execution without user interaction. The vendor offered temporary mitigations, including system hardening and restricting trusted client IPs in SmartConsole, and advised teams to watch for "Administrator failed to log in: Username too long" alerts. The issue is part of a series of recent critical patches affecting Check Point firewalls and management systems.
read more →

US agencies investigate cyber intrusion on supertanker

🚢 The US Coast Guard and FBI boarded the Liberian-flagged VL Prosperity after indications its network may have been compromised during a voyage from Egypt to Galveston. The alleged intrusion reportedly affected fuel systems, engine speed and communications for about 30 hours before a specialised team spent four days eradicating the threat. Authorities report no injuries or environmental impact while urging stronger cyber hygiene and network segmentation.
read more →

CISA Guidance Urges Honeytokens for Intrusion Detection

🛡️ CISA has published guidance recommending that critical infrastructure operators deploy decoys such as fake files, accounts and credentials inside their networks to detect intruders who bypass perimeter defenses. The guidance emphasizes honeytokens—low-complexity data tripwires with no legitimate use—over internet-facing honeypots, and frames decoys as complementary to Zero Trust. It outlines three actions: deploy high-fidelity tripwires in high-value areas, map coverage using MITRE ATT&CK and MITRE Engage, and continuously refine through threat emulation.
read more →

MeshCentral backdoor used in 3BB broadband intrusion

🔎 Hunt.io discovered an active intrusion in Thailand ISP 3BB where an attacker installed MeshCentral as a hidden backdoor to maintain remote root access. The exposed server captured on June 3, 2026, contained tools, device lists, and scripts targeting RADIUS databases, FortiGate SSL‑VPN appliances, and internal portals. Cleanup scripts removed logs but deliberately left the agent to preserve persistence.
read more →

Defense cyber spending set to double by 2031

🔒 A MarketsandMarkets report published on September 14 forecasts the cyber warfare market to grow from $14.99bn in 2026 to $28.75bn by 2031. The firm cites rising attacks on military networks, increased reliance on connected and cloud platforms, and a focus on offensive cyber capabilities as key drivers. Europe is expected to become the largest regional market, while cloud-based security will see the fastest growth.
read more →

Post-Quantum Cryptography and National Security Risks

🔒 Quantum computing advancements are turning theoretical cryptographic vulnerabilities into imminent threats, prompting an urgent shift to post-quantum cryptography (PQC). The technology will likely remain concentrated within nation-states and large corporations, creating adoption gaps among smaller organizations and critical infrastructure. This disparity could be exploited for intelligence collection, economic espionage, or prepositioning for conflict.
read more →

Microsoft issues record Windows security patch batch

🔒 Microsoft released updates addressing at least 974 security vulnerabilities across Windows and other products, its largest single patch bundle ever. Two zero-day vulnerabilities are being actively exploited, and 113 bugs were rated critical. Vendors attribute rising patch volumes to AI-assisted discovery, while security teams warn of the burden of testing and deploying so many fixes. Administrators are urged to prioritize and test patches carefully to avoid disruption.
read more →

US Military Disables Ad Tracking on Government Phones

🔒 Branches of the US military have disabled advertising IDs on government-issued phones and computers after concerns that commercially available location data was being used to target American forces. Senator Ron Wyden and Representative Pat Harrigan pushed the Pentagon for action and sought an inspector general investigation into how location data risks were handled. The move follows warnings about adversary exploitation of commercial location data and broader guidance urging personnel to limit personal device sharing and clean up social media.
read more →