CISA released an updated Insider Threat Mitigation Guide to help organizations address evolving insider threats, including those linked to hybrid work and AI, with practical mitigation steps.
U.S. cybersecurity agencies warn Chinese AI firms are using illicit knowledge distillation to extract proprietary U.S. AI models, accelerating their development at the expense of American innovation.
CISA released an advisory detailing red team assessments at two critical infrastructure organizations, highlighting differences in detection and response capabilities to inform cybersecurity improvements across sectors.
CISA released the Logging Reference Architecture to help federal agencies meet OMB logging requirements by November 2026, improving network monitoring and cyber defense through structured logging standards.
CISA released a K-12 Cybersecurity Foundations Resource Package to help schools and districts address rising cyber threats with cost-effective, actionable guidance.
U.S. agencies and South Korea’s police issued a joint advisory warning of the Gunra ransomware threat to critical infrastructure sectors, citing double extortion tactics and specific CVEs used for initial access.
CISA released guidance for federal agencies on securely using and contributing to open source software, aligning with recent executive orders to strengthen software supply chain security.
CISA and partners released updated 2026 Minimum Elements for a Software Bill of Materials (SBOM), expanding guidance to cover all software types and incorporating feedback from over 90 public comments.
CISA and allied agencies released joint guidance to help critical infrastructure operators isolate vital operational technology systems during cyber incidents or geopolitical crises.
U.S. agencies warn of Russian state-backed hackers exploiting a zero-click flaw in Zimbra Collaboration Suite to steal email data from Western organizations, including government and defense entities.
U.S. agencies updated a joint advisory warning of Iranian-affiliated cyber actors targeting industrial control systems, including Rockwell Automation, Schneider Electric, and Siemens PLCs, across critical infrastructure...
CISA and international partners released guidance to help software makers and online services collaborate with security researchers through structured vulnerability disclosure programs.
CISA and partners issued a joint advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in critical infrastructure sectors worldwide, urging immediate mitigation steps.
CISA launched ANCHOR-CI, a new advisory framework to enhance public-private collaboration on securing critical infrastructure against evolving threats.