Tag: CISA

CISA orders feds to patch Zimbra XSS flaw exploited in attacks
News

CISA orders feds to patch Zimbra XSS flaw exploited in attacks

U.S. government organizations are required by CISA to protect their servers from a Zimbra Collaboration Suite (ZCS) vulnerability that is being actively exploited. Hundreds of millions of people worldwide, including thousands of organizations and hundreds of government bodies, use the widely used email and collaboration software suite Zimbra. This high-severity security vulnerability, known as CVE-2025-66376 and fixed in early November, is caused by a stored cross-site scripting (XSS) vulnerability in the Classic UI that remote unauthenticated attackers might exploit by leveraging Cascading Style Sheets (CSS) @import directives in email HTML. The impact of a successful CVE-2025-66376 attack can probably be exploited to execute arbitrary JavaScript via malicious HTML-based emails,...
CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
News

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

Over the next 12 to 18 months, Federal Civilian Executive Branch (FCEB) agencies have been directed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to improve asset lifecycle management for edge network devices and eliminate those that are no longer receiving security updates from original equipment manufacturers (OEMs). Since state-sponsored threat actors use these devices as a preferred entry method to breach target networks, the agency stated that the action is intended to reduce technological debt and reduce the chance of compromise. Load balancers, firewalls, routers, switches, wireless access points, network security appliances, Internet of Things (IoT) edge devices, software-defined networks, and other real or virtual networking components that route netwo...
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
News

CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks

Following indications of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity security weakness affecting VMware Aria Operations and Broadcom VMware Tools to its Known Exploited Vulnerabilities (KEV) list on Thursday. CVE-2025-41244 (CVSS score: 7.8) is the vulnerability in question, which an attacker might use to get root level privileges on a vulnerable system. According to a CISA alert, there is a privilege defined with dangerous actions vulnerability in Broadcom VMware Aria Operations and VMware Tools. This vulnerability allows a malevolent local actor with non-administrative credentials to get root access to a virtual machine (VM) that has VMware Tools installed and is managed by Aria Operations with SDMP enable...
CISA warns of Lanscope Endpoint Manager flaw exploited in attacks
News

CISA warns of Lanscope Endpoint Manager flaw exploited in attacks

Hackers are taking advantage of a serious flaw in the Motex Landscope Endpoint Manager, according to a warning from the Cybersecurity & Infrastructure Security Agency (CISA). The vulnerability has a critical severity level of 9.3 and is listed as CVE-2025-61932. It results from incorrectly confirming the source of incoming requests, and an unauthenticated attacker might use it to send specially constructed packets that would cause the system to run arbitrary code. Lanscope Endpoint Manager is an endpoint management and security solution that offers unified control across desktop and mobile devices. It was created by the Japanese company Motex, a division of Kyocera Communication Systems. AWS (Amazon Web Services) offers the product as an asset/endpoint management alternative,...
New TP-Link zero-day surfaces as CISA warns other flaws are exploited
News

New TP-Link zero-day surfaces as CISA warns other flaws are exploited

While CISA cautions that other router vulnerabilities have been used in attacks, TP-Link has verified the existence of an unpatched zero-day vulnerability affecting several router models. Mehrun (ByteRay), a freelance threat researcher, found the zero-day vulnerability and submitted it to TP-Link on May 11, 2024. BleepingComputer was informed by the Chinese networking equipment company that it is now looking into the vulnerability's disclosure and exploitability. Work is in progress to create updates for U.S. and international firmware versions, though no precise timeline has been provided, despite the fact that a patch is allegedly already built for European models. According to the statement TP-Link Systems Inc. issued read more about New TP-Link zero-day surfaces as CISA wa...
CISA and FBI warn of escalating Interlock ransomware attacks
News

CISA and FBI warn of escalating Interlock ransomware attacks

On Tuesday, CISA and the FBI issued a warning about a surge in Interlock ransomware activity that targets critical infrastructure organizations and businesses through double extortion assaults. The Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Department of Health and Human Services (HHS) collaborated to create today's advisory, which gives network defenders mitigation strategies to shield their networks from attacks by this ransomware gang as well as indicators of compromise (IOCs) gathered during incident investigations as recently as June 2025. Since its emergence in September 2024, the relatively new ransomware operation Interlock has targeted victims globally in a variety of industry sectors, with a particular emphasis on the healthcare sector. The th...
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation
News

CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation

Following indications of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a recently discovered critical security weakness affecting CrushFTP to its Known Exploited Vulnerabilities (KEV) list. An unauthenticated attacker could take control of vulnerable instances due to the vulnerability, which is a case of authentication bypass. Versions 10.8.4 and 11.3.1 have fixed it. A remote, unauthenticated attacker might authenticate to any known or guessable user account (such as crushadmin) using CrushFTP's authentication bypass vulnerability in the HTTP permission header, which could result in a complete compromise, according to a CISA advisory. The CVE number for the vulnerability is CVE-2025-31161 (CVSS score: 9.8). It is importan...
CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability
News

CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability

A security vulnerability affecting Trimble Cityworks' GIS-centric asset management software has been actively exploited in the field, according to a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This vulnerability, CVE-2025-0994 (CVSS v4 score: 8.6), is a deserialization of untrusted data flaw that may allow remote code execution by an attacker. According to a February 6, 2025, CISA advisory, this might enable a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server by an authenticated user read more about CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage o...
CISA tags Progress Kemp LoadMaster flaw as exploited in attacks
News

CISA tags Progress Kemp LoadMaster flaw as exploited in attacks

A significant OS command injection that affects Progress Kemp LoadMaster is one of three new vulnerabilities that the U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added to its list of known exploited vulnerabilities (KEVs). The vulnerability was fixed in an update published on February 21, 2024, after being identified by Rhino Security Labs and recorded as CVE-2024-1212. But this is the first time that its active exploitation in the wild has been documented. The description of the bug states, "Progress Kemp LoadMaster has an OS command injection vulnerability that permits arbitrary system command execution by granting an unauthenticated, remote attacker access to the system via the LoadMaster management interface read more about CISA tags Progress Kemp LoadMast...
CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability
News

CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a severe security hole that has been patched and affects Palo Alto Networks Expedition to its list of known exploited vulnerabilities (KEVs). The Expedition migration program has a vulnerability known as CVE-2024-5910 (CVSS score: 9.3) that involves a situation of missing authentication that could result in an admin account takeover. According to an alert from CISA, Palo Alto Expedition has a missing authentication vulnerability that enables a network-connected attacker to take control of an admin account and perhaps acquire credentials, configuration secrets, and other data read more about CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulner...