#cisa

[ follow ]
#cybersecurity
fromNextgov.com
1 week ago
Information security

'High-severity' Microsoft Exchange vulnerability disclosed on heels of Black Hat talk

fromNextgov.com
1 week ago
Information security

'High-severity' Microsoft Exchange vulnerability disclosed on heels of Black Hat talk

fromTheregister
6 days ago

Microsoft Exchange bug can allow 'total domain compromise'

CVE-2025-53786 is an elevation of privilege bug that Outsider Security's Dirk-jan Mollema reported to Microsoft. It exists because of the way hybrid Exchange deployments, which connect on-premises Exchange servers to Exchange Online, use a shared identity to authenticate users between the two environments.
Privacy professionals
fromTheregister
6 days ago

CISA releases malware analysis for Sharepoint Server attack

CISA analysed six files including two Dynamic Link-Library (.DLL), one cryptographic key stealer, and three web shells. Cyber threat actors could leverage this malware to steal cryptographic keys and execute a Base64-encoded PowerShell command to fingerprint host system and exfiltrate data.
Privacy professionals
fromThe Hacker News
6 days ago

Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups

In an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization's connected cloud environment without leaving easily detectable and auditable traces.
Privacy professionals
#ransomware
fromComputerWeekly.com
3 weeks ago

Patch ToolShell SharePoint zero-day immediately, says Microsoft | Computer Weekly

Organisations using on-premise SharePoint instances must urgently update due to serious vulnerabilities being exploited.
Privacy professionals
fromTheregister
3 weeks ago

Microsoft warns on-prem SharePoint users of a zero-day

Microsoft warns of an active zero-day vulnerability in SharePoint Server, allowing unauthorized access due to incomplete past updates.
fromNextgov.com
3 weeks ago

Trump's CISA nominee to testify before Senate panel next week

Sean Plankey is scheduled to testify before the Senate Homeland Security Committee regarding his nomination to lead the Cybersecurity and Infrastructure Security Agency.
fromBreaking Defense
1 month ago

Iran may go after US defense firms with cyber attacks, warn Pentagon, Homeland Security

Homeland Security's Cybersecurity & Infrastructure Security Agency warned US defense contractors working in Israel that they may be targeted by Iranian cyber attacks.
US politics
fromIT Pro
1 month ago

Want to build more secure software? Follow these key memory safe language tips from CISA

Achieving better memory safety demands language-level protections, library support, robust tooling, and developer training, as traditional languages can't eliminate vulnerabilities as effectively.
Software development
fromTheregister
1 month ago

AWS enforces MFA across 100% of root users: re:Inforce

For anyone who still has doubts about MFA: just ask Snowflake CISO Brad Jones, who last year saw more than 160 of his customers' accounts compromised using stolen credentials. None of these had MFA enabled, and this safeguard likely would have prevented the intruders from accessing the customers' databases.
Marketing tech
fromTheregister
2 months ago

CISA loses senior exec Bridget Bean, pre-budget cuts

Bridget Bean has officially retired from CISA, leaving the agency without a Senate-confirmed director.
fromTheregister
3 months ago

NSA, CISA top brass absent from RSA Conference

The NSA's 'State of the Hack' panel was canceled at this year's RSA Conference, reflecting a shift in their public engagement approach.
fromIT Pro
3 months ago

CISA issues warning in wake of Oracle cloud credentials leak

CISA warns of potential data breach risks from a security incident involving legacy Oracle cloud environments, urging enterprises to strengthen their security defenses.
Information security
#chris-krebs
fromArs Technica
3 months ago
Privacy professionals

Chris Krebs, who debunked 2020 election lies, vows full-time fight against Trump

CISA's Chris Krebs was terminated by Trump after debunking election fraud claims, emphasizing integrity amidst political pressure.
fromTechzine Global
3 months ago
Privacy professionals

SentinelOne exec Krebs leaves following Trump pressure

Chris Krebs resigns from SentinelOne to focus on fighting Trump's retaliatory actions against him and the company.
Privacy professionals
fromArs Technica
3 months ago

Chris Krebs, who debunked 2020 election lies, vows full-time fight against Trump

CISA's Chris Krebs was terminated by Trump after debunking election fraud claims, emphasizing integrity amidst political pressure.
fromTechzine Global
3 months ago

MITRE CVE database saved after last minute reversal

The U.S. government extended funding for the CVE database for eleven months, preventing the crucial cybersecurity resource from going offline due to funding discontinuation.
Information security
fromArs Technica
3 months ago

Crucial CVE flaw-tracking database narrowly avoids closure to DHS cuts

CVE's funding was at risk, but CISA has extended the contract to ensure continued operations.
[ Load more ]