CISA is a ticker tracked in our intelligence system with 6 linked articles.
CISA adds three actively exploited flaws to KEV, including Langflow CVE-2026-9198 (CVSS 9.8) RCE; two other flaws in Tomcat and N-central flagged, signaling urgent patching and regulatory/compliance considerations for affected firms.
CISA added the exploited N-able N-central flaw CVE-2026-18577 to the KEV catalog, with CVSS 8.2, tied to incomplete patching of CVE-2026-18556 and active exploitation in the wild.
Research finds thousands of servers have exploitable BMCs with externally exposed risk (86k exposed, 54% with critical flaws; up to 75k vulnerable to CVE-2013-4786; internal scans show 29% vulnerable), plus actionable mitigations and an open-source scanner.
The piece argues Iran-use of telecom signaling attacks against U.S. troops is a known risk and lays out regulatory and procurement fixes, including tighter carrier access, mandatory audits, and a move by the DoD to secure cellular networks amid a long renewal cycle for current contracts.
A Russian state-backed group exploited a then-unknown Zimbra webmail flaw to exfiltrate 90 days of emails, the full mailbox directory, browser-stored passwords, and 2FA recovery codes; NSA/CISA and partners issued/publicized guidance.
CISA reportedly had to build its incident playbook during the incident, after a contractor employee uploaded a public GitHub repo containing exposed passwords flagged by a GitGuardian researcher (per Krebs).
Subscribe for real-time ticker updates and unlimited access to our intelligence platform.