Cybersecurity and Infrastructure Security Agency

As US CVE Database Fumbles, EU ‘Replacement’ Goes Live
Richi Jennings | | CERT-EU, cisa, CISA Research, common vulnerabilities and exposures, CVE, CVE (Common Vulnerabilities and Exposures), CVE database, CVE Program, Cybersecurity and Infrastructure Security Agency, cybersecurity funding, Department of Homeland Security, DHS, ENISA, eu, EU Agency for Cybersecurity, European Union, European Union (EU), EUVD, Funding & Grants, Juhan Lepassaar, MITRE, MITRE Framework, National Institute of Standards and Technology, National Institute of Standards and Technology (NIST), NIS2, NIS2 Directive, NIST, SB Blogwatch, U.S. Department of Homeland Security, vulnerability database
Diesen Kuß der ganzen Welt! European Union Vulnerability Database (EUVD) launches this week. And not a moment too soon ...
Security Boulevard

MITRE Crisis: CVE Cash Ends TODAY — CISA says ‘No Lapse’
Richi Jennings | | cisa, CISA Research, common vulnerabilities and exposures, CVE, CVE (Common Vulnerabilities and Exposures), CVE database, CVE Program, Cybersecurity and Infrastructure Security Agency, cybersecurity funding, Department of Homeland Security, DHS, Funding & Grants, MITRE, MITRE Framework, National Institute of Standards and Technology, National Institute of Standards and Technology (NIST), NIST, SB Blogwatch, U.S. Department of Homeland Security
These are “interesting” times: U.S. government funding for the Common Vulnerabilities and Exposures program expires April 16 ...
Security Boulevard

CISA/FDA Warn: Chinese Patient Monitors Have BAD Bugs
Richi Jennings | | cisa, CISA Advisories, CISA Advisory, CISA Alert, CISA cybersecurity advisory, CISA Report, CISA Research, Contec, CVE-2024-12248, CVE-2025-0626, CVE-2025-0683, Cyber Threat on Healthcare, cyberattacks in healthcare, Cybersecurity and Infrastructure Agency, Cybersecurity and Infrastructure Security Agency, Cybersecurity for Healthcare, cybersecurity in healthcare, Epsimed, FDA, FDA guidance, fda medical device cybersecurity, Food and Drug Administration, health care, Health Care Security, healthcare, Healthcare & Life Sciences, Healthcare company, Healthcare Compliance, SB Blogwatch, USFDA
China crisis? Stop using this healthcare equipment, say Cybersecurity & Infrastructure Security Agency and Food & Drug Administration ...
Security Boulevard
What to Know About the CISA Software Bill of Materials Sharing Lifecycle Phases
Esther Shein | | Application Security, cisa, Cybersecurity and Infrastructure Security Agency, SBOM, software bill of materials, Uncategorized
As Software Bill of Materials (SBOM) adoption efforts mature, a report recently released by the Cybersecurity and Infrastructure Security Agency (CISA) provides guidance to users in selecting suitable SBOM sharing platforms based on ...

CISA Order Highlights Persistent Risk at Network Edge
BrianKrebs | | Adam Boileau, Barracuda Networks, cisa, CVE-2023-27997, Cybersecurity and Infrastructure Security Agency, Fortinet, Fortra, GoAnywhere, Latest Warnings, Mandiant, MOVEit Transfer, Patrick Gray, Progress Software, risky-business-podcast, The Coming Storm, Time to Patch
The U.S. government agency in charge of improving the nation's cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes ...

Christopher Krebs to Keynote in Live Fireside Chat/Q&A Session at DevOps Connect: DevSecOps at RSA Conference 2021
Charlene O’Hanlon | | Christopher Krebs, cisa, Cybersecurity and Infrastructure Security Agency, Department of Homeland Security, DevOps Connect, DevOps Connect: DevSecOps, DevSecOps, RSA Conference 2021
Former Director of Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to headline free one-day event Boca Raton, FL, April 26, 2021 — MediaOps, the place to tell your story in ...
Security Boulevard

SolarWinds Hack Could Affect 18K Customers
BrianKrebs | | Alan Paller, Andrew Morris, Center for Strategic and International Studies, cisa, Cybersecurity and Infrastructure Security Agency, Data breaches, fireeye, GreyNoise Intelligence, James Lewis, Microsoft, Orion software, SANS Institute, SolarWinds breach, U.S. Securities and Exchange Commission, Vinoth Kumar
The still-unfolding breach at network management software firm SolarWinds may have resulted in malicious code being pushed to nearly 18,000 customers, the company said in a legal filing on Monday. Meanwhile, Microsoft ...

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
BrianKrebs | | APT29, Cybersecurity and Infrastructure Security Agency, Data breaches, Department of Commerce, FireEye hack, Microsoft, Orion, Reuters, SolarWinds breach, The Coming Storm, U.S. Treasury Department
Communications at the U.S. Treasury and Commerce Departments were reportedly compromised by a supply chain attack on SolarWinds, a security vendor that helps the federal government and a range of Fortune 500 ...

Trump Fires Security Chief Christopher Krebs
BrianKrebs | | A Little Sunshine, Christopher Krebs, cisa, Cybersecurity and Infrastructure Security Agency, president trump, Rumor Control, Sen. Angus King, Sen. Richard Burr, U.S. Department of Homeland Security, Y2K
President Trump on Tuesday fired his top election security official Christopher Krebs (no relation). The dismissal came via Twitter two weeks to the day after Trump lost an election he baselessly claims ...
Department of Homeland Security Cybersecurity: Top 10 Vulnerabilities Still Being Exploited
April Downey | | Apache Struts2, Cybersecurity and Infrastructure Security Agency, Department of Homeland Security, Struts2 vulnerability, Vulnerabilities
The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (DHS CISA) recently released a list of the top 10 most commonly exploited software vulnerabilities across the last four years. Apache Struts ...