CISA

Security agency adds CVE-2012-4792 to its catalogue of known vulns and warns it can "execute arbitrary code via a crafted web site"

Fix up, look sharp: Uncle Sam is running out of patience with tech firms shipping insecure software. Vendors? Get familiar with the phrase "query parameterization"...

Cybersecurity agency's cybersecurity appliance breached (yes, everything is broken) but no exfiltration seen says CISA

CISA has posted a new directive for US government agencies regarding targeted attacks by the Midnight Blizzard hacking team that also hit Microsoft

CISA is moving into what it hopes is the home stretch for drafting and enforcing stricter reporting rules for cybersecurity incidents

CISA has just two federal staff and five contractor staff working on its OT-specific threat hunting and/or incident response services...