Laundry Bear exploits Zimbra zero-click flaw to steal emails
CISA warns that Russian state‑sponsored group Laundry Bear is using a zero‑click Zimbra vulnerability to exfiltrate email data from unpatched servers.
CISA warns that Russian state‑sponsored group Laundry Bear is using a zero‑click Zimbra vulnerability to exfiltrate email data from unpatched servers.
A CISA contractor exposed AWS GovCloud keys on GitHub for six months. We dissect the leak, response gaps, and essential takeaways for security professionals.
A CISA contractor’s public GitHub repo exposed AWS GovCloud credentials and internal passwords, sparking concerns over government cloud security.
Congressional leaders demand answers after a CISA contractor posted AWS GovCloud keys on GitHub, sparking concerns over agency security and oversight.
CISA adds Cisco SD-WAN CVE-2026-20182 to KEV list, mandating federal patch by May 17, 2026. Critical authentication bypass already exploited. Details inside.
CISA mandates federal agencies patch a critical Ivanti EPMM zero-day by May 12, 2026. Attackers already exploited it. Here’s what you need to know.
CISA issues urgent guidance for critical infrastructure operators to master isolation and recovery from cyberattacks. Full analysis on what it means for tech teams. May 06, 2026.
CISA adds ConnectWise ScreenConnect and Windows flaws to KEV catalog on April 29, 2026, warning of active exploitation. Immediate action urged for IT teams. Read more.
A new backdoor called FIRESTARTER compromised a federal Cisco Firepower device in September 2025, surviving patches and evading detection. Details from CISA and NCSC..
CISA adds four actively exploited flaws in SimpleHelp, Samsung, and D-Link systems to its KEV catalog, mandating federal patching by May 2026. Details on risks and implications.