CISA Demonstrates the Defensive Gap in Two Critical Infrastructures
CISA has published the results of two red team assessments conducted in parallel against two critical infrastructure organizations. In both environments, the testers were able to a
CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Pro
CISA adds four critical vulnerabilities to KEV catalog for active exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming their acti
CISA pushes vendors toward more disciplined coordinated vulnerability disclosure
CISA and allied agencies published new coordinated vulnerability disclosure guidance aimed at helping vendors handle reports more consistently. The guidance arrived shortly after C

