Russian hackers keep finding their way into critical networks through neglected routers

Russian state-backed hackers are exploiting neglected routers to access critical infrastructure networks, prompting agencies worldwide to urge organizations to replace outdated equipment and tighten basic network security.

US cyber agency CISA had to build its incident playbook during the incident, agency reveals

CISA said it “missed” an opportunity to get ahead of the security incident by not creating a response plan ahead of time.

CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

Check Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government.

Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

US cyber agency CISA exposed reams of passwords and cloud keys to the open web

The federal cybersecurity agency left plaintext passwords in a spreadsheet uploaded to a public GitHub repository, per a report by independent journalist Brian Krebs.

Trump’s pick to run US cyber agency CISA asks to drop out

Sean Plankey has requested to withdraw his name to run the U.S. cybersecurity agency after a tumultuous year of chaotic temporary leadership.

Trump administration plans to cut cybersecurity agency’s budget by $700 million

The budget proposal would force CISA to operate with a significantly lower budget than previous years, citing the government’s claims that the election misinformation programs were used to “target the President.”

CISA urges companies to secure Microsoft Intune systems after hackers mass-wipe Stryker devices

The U.S. cybersecurity agency urged companies to prevent access to systems used for remotely managing their fleets of employee devices after hackers broke into a major U.S. medical tech giant and remotely wiped thousands of phones and computers.

CISA replaces acting director after a bumbling year on the job

The U.S. cybersecurity agency’s acting director Madhu Gottumukkala will be replaced, after a year of cuts, layoffs, and staff reassignments, and allegations of security lapses and claims he struggled to lead the agency.

Cisco says hackers have been exploiting a critical bug to break into big customer networks since 2023

The U.S. government and its allies said hackers have been exploiting the newly identified bug in Cisco networking gear around the world for years, and urged organizations to patch.