U.S. Cybersecurity and Infrastructure Security Agency (CISA)
Coverage of U.S. Cybersecurity and Infrastructure Security Agency (CISA) in the Nexus archive.
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA added four critical vulnerabilities related to macOS, SharePoint, vCenter, and Microsoft IKE to its Known Exploited Vulnerabilities catalog. CISA stated that these shortcomings are being exploited in the wild. One specific vulnerability noted is CVE-2026-65400, which is an improper authentication flaw impacting Apple macOS.
- CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting a high-severity flaw. This vulnerability concerns Windows Task Host, which had previously been flagged as being exploited in April.
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
CISA added a critical-severity security flaw affecting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. This action followed reports of active exploitation in the wild, concerning the command injection vulnerability tracked as CVE-2026-8037.
- CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to patch a critical vulnerability in the LiteSpeed cPanel user-end plugin within four days, as it is currently being exploited in cyberattacks.
- Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
The Russian state-sponsored hacking group Turla has transformed its Kazuar backdoor into a modular peer-to-peer botnet for stealthy and persistent access. Turla is affiliated with Center 16 of Russia's Federal Security Service. This transformation enables Turla to maintain access to compromised hosts.
- Firestarter malware survives Cisco firewall updates, security patches
U.S. and U.K. cybersecurity agencies warn that a custom malware named Firestarter is persisting on Cisco Firepower and Secure Firewall devices using Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software despite updates and patches.