Aggregator
CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack
The Digital Foundation of Public Trust Is More Than Skin Deep
MuddyWater hackers use Chaos ransomware as a decoy in attacks
Google Chrome 被发现在合格设备上静默下载 Gemini Nano
Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Webinar: Why network incidents escalate and how to fix response gaps
G.O.S.S.I.P 阅读推荐 2026-05-06 DARPA 拖拉机简史
Hackers compromise Daemon Tools in global supply-chain attack, researchers say
Двадцать ударов за три месяца. Касперский зафиксировал повышенный интерес взломщиков к заводам
INC
You must login to view this content
Akira
You must login to view this content
Submit #800793: PicoTronica e-Clinic Healthcare System (ECHS) v5.7 Information Disclosure [Accepted]
Submit #800792: PicoTronica e-Clinic Healthcare System (ECHS) v5.7 Improper Privilege Management [Accepted]
Submit #800781: PicoTronica e-Clinic Healthcare System (ECHS) v5.7 Exposure of Private Personal Information to an Unauthorized Acto [Accepted]
The “Juice” Factor: Designing Game Feel
The Hacker News Launches 'Cybersecurity Stars Awards 2026' — Submissions Now Open
Европол построил «теневую IT‑базу» под давлением террористической угрозы, а затем потерял над ней контроль
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.