CISA Cyber
@CISACyber
Part of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
🎉 We are excited to share that CERT@VDE is now a CVE Program Root, helping recruit and onboard partners as CVE Numbering Authorities! For more info on global efforts to protect #ICS or how to become a CVE Numbering Authority, visit 👉 cve.org/PartnerInforma…

We are working side-by-side with cloud service providers to foster discovery and discussion of best practices for strengthening cloud identity security. See how we’re helping to secure cloud identity infrastructure: 👉 go.dhs.gov/wvX

Happy #SysAdminAppreciationDay! 🌟 Cheers to the unsung champions of the digital realm! Your expertise ensures seamless systems, and your commitment keeps us safe and secure. Thank you for being the backbone of our digital infrastructure! 💻👩💻👨💻
Update: See newly added info to our #ToolShell Alert. We’ve included info on ransomware deployment, new webshells involved in exploitation, & detection guidance 👉 go.dhs.gov/i4J

⚠️ @CISAgov issued six NEW public #ICS advisories. These advisories provide info about current security issues, vulnerabilities, & exploits surrounding ICS. More at go.dhs.gov/i47

🛡️We added 4️⃣ CVEs—affecting CrushFTP, Google Chrome, & SysAid On-Prem—to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec

⚠️ @CISAgov issued nine NEW public #ICS advisories. These advisories provide info about current security issues, vulnerabilities, & exploits surrounding ICS. More at go.dhs.gov/i4U

Update: As we continue to monitor the scope & impact of #ToolShell, we’ll update our related Alert with new info. Today, we’ve added info on new CVEs & additional mitigations on exploitation activity. 👉 go.dhs.gov/i4J

🛡️We added Microsoft SharePoint vulnerabilities CVE-2025-49704 & CVE-2025-49706 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec #ToolShell

🛡️ Interlock ransomware is on the rise. Interlock actors are targeting businesses & #CriticalInfrastructure with double extortion ransomware attacks. Learn more and see our top recommended actions in our joint Cybersecurity Advisory. 👉 go.dhs.gov/iZa #StopRansomware

Interested in becoming a cyber assessor? CISA’s AES Program offers free, on-demand assessment training courses that provide you with the skills you need to safeguard the nation’s critical infrastructure. Learn more about the program: cisa.gov/aes

📢 Stay informed on the latest vulnerabilities with @CISAgov's Vulnerability Bulletin & gain valuable insights into emerging threats. 💡Check out the latest updates: go.dhs.gov/iZL #Cybersecurity #InfoSec #VulnerabilityManagement

We added Microsoft SharePoint server remote code execution vulnerability CVE-2025-53770 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #ToolShell

Malicious actors are exploiting RCE vulnerability CVE-2025-53770 to compromise on-prem SharePoint servers. See our Alert for info & mitigations on exploitation activity, known as #ToolShell. 👉go.dhs.gov/iZZ

🛡️We added Fortinet FortiWeb SQL injection vulnerability CVE-2025-25257 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec

⚠️ @CISAgov issued three NEW public #ICS advisories. These advisories provide info about current security issues, vulnerabilities, & exploits surrounding ICS. More at go.dhs.gov/ikD

⚠️@CISAgov issued six NEW public #ICS advisories. These advisories provide info about current security issues, vulnerabilities, & exploits surrounding ICS. More at go.dhs.gov/wtv

🛡️We added Wing FTP Server improper neutralization of null byte or NUL character vulnerability CVE-2025-47812 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec

📢 Stay informed on the latest vulnerabilities with @CISAgov's Vulnerability Bulletin & gain valuable insights into emerging threats. 💡Check out the latest updates: go.dhs.gov/wtF #Cybersecurity #InfoSec #VulnerabilityManagement

🛡️We added Citrix NetScaler ADC and Gateway out-of-bounds read vulnerability CVE-2025-5777 to our Known Exploited Vulnerabilities Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec
