#cisa

2026-02-14

🦅 America's Cyber Defense Agency Is Burning Down and Nobody's Coming to Put It Out | ThreatHunter.ai

「 CISA went from roughly 3,400 staff at the start of 2025 to about 2,400 by December. That's a thousand people. A third of the agency's workforce. Most of those departures weren't voluntary retirements. They were the result of workforce reduction programs, political turbulence, and an environment where experienced professionals saw no future 」

threathunter.ai/blog/americas-

#cisa #cybersecurity

New.

"The town hall meetings are scheduled to begin March 9."

Schedule:

The Federal Register: federalregister.gov/documents/

CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure cisa.gov/news-events/news/cisa #CISA #infosec

The CEMIRTheCEMIR
2026-02-13

open.substack.com/pub/thecemir/p/public-hearings-town-halls-on-proposed

Public Hearings Town Halls - on proposed U.S. cyberthreat rulemaking

From DHS' CISA regarding the CIRCIA Act

the CEMIR's Substack
Patrick CoylePjcoyle@qoto.org
2026-02-13

OMB Approves CISA CVD Program ICR – 2-12-26 – Coordinated vulnerability disclosure process – tinyurl.com/veuksvh #ICR #CISA #cvdProgram

CISA has updated the KEV catalogue. I see Notepad++ has made it to the list.

- CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability cve.org/CVERecord?id=CVE-2025-

- CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability cve.org/CVERecord?id=CVE-2025-

- CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2024-

- CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026-

There are also several industrial advisories here: cisa.gov/ #CISA #infosec #vulnerability #Apple #Microsoft #Notepad #SolarWinds

CISA posted a year-in-review yesterday, if you missed it cisa.gov/about/2025YIR.

"Back on Mission - Modern, Efficient and Protecting What Matters Most."

PR: CISA’s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure cisa.gov/news-events/news/cisa #CISA #infosec

AllAboutSecurityallaboutsecurity
2026-02-12

BRICKSTORM-Backdoor: CISA warnt vor neuer Malware-Variante aus China

US-Behörden dokumentieren weiterentwickelte Schadsoftware für Virtualisierungsplattformen

all-about-security.de/bricksto

Geeky Malcölm 🇨🇦geekymalcolm@ioc.exchange
2026-02-11
2026-02-11

CISA dodaje kolejną lukę w GitLab do katalogu KEV

Niektóre podatności muszą poczekać na aktywne wykorzystanie dłużej, niż inne. Musiało upłynąć zdecydowanie więcej czasu, aby podatność dotycząca SSRF w GitLab oznaczona symbolem CVE-2021-39935 została dodana przez CISA do katalogu aktywnie wykorzystywanych podatności (KEV). Jest to okres znacznie dłuższy niż w przypadku poprzednio opisywanej podatności, również dotykającej serwery kontroli wersji. Dla przypomnienia,...

#WBiegu #Cisa #Cve #Ssrf

sekurak.pl/cisa-dodaje-kolejna

CISA has updated the KEV catalogue, and Microsoft is the winner.

- CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability cve.org/CVERecord?id=CVE-2026-

More:

CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps cisa.gov/news-events/alerts/20 #CISA #infosec #Microsoft #vulnerability

2026-02-10

𝙏𝙝𝙧𝙚𝙖𝙩 𝙈𝙤𝙙𝙚𝙡: 𝘾𝙮𝙗𝙚𝙧𝙨𝙚𝙘𝙪𝙧𝙞𝙩𝙮
𝘧𝘰𝘳 Feb. 10th, 2026
𝘣𝘺 𝘪𝘯𝘥𝘦𝘱𝘦𝘯𝘥𝘦𝘯𝘵 𝘫𝘰𝘶𝘳𝘯𝘢𝘭𝘪𝘴𝘵 @violetblue

- #Discord alternatives (ranked) to its doomed new age-check policy after losing age-check data in a huge hack

- US states are scrambling for #electionsecurity solutions after #CISA abandons them

- Horrific reports of #AI surgery disasters

- Trauma tips for surviving 2026

- A rage check tool to see if you’re being deliberately provoked online

- How to check claims of extraterrestrial life

- Apparently US #redteams have poor standards

...and much more.

* 𝙏𝙝𝙧𝙚𝙖𝙩 𝙈𝙤𝙙𝙚𝙡 𝘪𝘴 𝘧𝘳𝘦𝘦 𝘵𝘰 𝘳𝘦𝘢𝘥 -- 𝘱𝘭𝘦𝘢𝘴𝘦 𝘩𝘦𝘭𝘱 𝘬𝘦𝘦𝘱 𝘪𝘵 𝘢𝘤𝘤𝘦𝘴𝘴𝘪𝘣𝘭𝘦 𝘵𝘰 𝘢𝘭𝘭 𝘣𝘺 𝘣𝘦𝘤𝘰𝘮𝘪𝘯𝘨 𝘢 𝘱𝘢𝘵𝘳𝘰𝘯, 𝘦𝘷𝘦𝘯 $1/𝘮𝘰𝘯𝘵𝘩 𝘮𝘢𝘬𝘦𝘴 𝘢 𝘥𝘪𝘧𝘧𝘦𝘳𝘦𝘯𝘤𝘦 *

patreon.com/posts/cybersecurit

#ThreatModel #ThreatModelCybersecurity #ThreatModelNewsletters #VioletBlue #infosec #cybersec #CovidIsNotOver

Odd that CISA would put this up after the Super Bowl - and written by the acting director, no less. It reads like a commercial.

CISA: Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships cisa.gov/news-events/news/supe

On a more serious note, CISA has added one industrial vulnerability to the ever-expanding catalogue: cisa.gov/news-events/alerts/20 #CISA #infosec #vulnerability

Brian Greenberg :verified:brian_greenberg@infosec.exchange
2026-02-10

We spend billions on firewalls and zero-trust architecture, only to be undone by a copy-paste command by someone who should know better. The U.S. cyber defense chief "accidentally" feeding classified intelligence to an unsecured version of ChatGPT is the ultimate reminder that the greatest vulnerability in any system is the person using it. Technology is outpacing our muscle memory. When a tool feels like a helpful colleague, we treat it like one—forgetting that LLMs are basically giant, permanent digital sponges. If the person in charge of the nation's digital shield can trip over the AI threshold, your team probably is too.

🧠 Convenience is the enemy of confidentiality
⚡ Your data is the product, even in a chat box
🎓 Policy without automated guardrails is just a wish
🔍 The UI is designed to make you forget the risks

arstechnica.com/tech-policy/20
#CyberSecurity #ArtificialIntelligence #Leadership #security #privacy #cloud #infosec #CISA

CVE ProgramCVE_Program
2026-02-09

837 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of January 26, 2026

cisa.gov/news-events/bulletins

2026-02-07

Senator, who has repeatedly warned about secret US #GovernmentSurveillance, sounds new alarm over ‘#CIA activities’

by Zack Whittaker, February 6, 2026

Excerpt: "In 2011, #RonWyden said that the U.S. government was relying on a secret interpretation of the #PatriotAct, which he said — without disclosing the nature of his concerns — created a 'gap between what the public thinks the law says and what the American government secretly thinks the law says.'

"Two years later, then-#NSA contractor #EdwardSnowden revealed that the National Security Agency was relying on its secret interpretation of the Patriot Act to force U.S. phone companies, including Verizon, to turn over the call records of hundreds of millions of Americans on an ongoing basis.

"Since then, Wyden has sounded the alarm on how the U.S. government collects the contents of people’s communications; revealed that the Justice Department barred Apple and Google from disclosing that federal authorities had been secretly demanding the contents of their customers’ push notifications; and said that an unclassified report that #CISA has refused to release contains 'shocking details' about national security threats facing U.S. phone companies.

"As noted by Techdirt’s Mike Masnick, we may not know yet why Wyden sounded the siren about the CIA’s activities, but every time Wyden has warned, he has also been vindicated."

Full article:
techcrunch.com/2026/02/06/sena

#USPol #Fascism #Authoritarianism #SilencingDissent #Spying #USCitizens #WarrantlessSurveillance

Robert [KJ5ELX] :donor:FuturisticRobert@infosec.exchange
2026-02-06

Friendly reminder. CISA is fascist because Emperor Trump's regime is fascist. Do not trust CISA.

#cisa #fucktrump

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst