Opinion | Can we Afford the Risk? Measuring the cost of the Expiration of the Chemical Facilities Anti-Terrorism Standards Program

  • Post author:
  • Post category:

October 26, 2023,It has been nearly three months since the American people lost an essential program guarding against the threat of terrorist exploitation of dangerous chemicals. For more than 15 years, the Chemical Facility Anti-Terrorism Standards (CFATS) program helped protect communities across the nation.Through the CFATS program, the Cybersecurity and Infrastructure Security Agency (CISA) identified

Continue ReadingOpinion | Can we Afford the Risk? Measuring the cost of the Expiration of the Chemical Facilities Anti-Terrorism Standards Program

CISA Issues Request for Comment on Software Identification Ecosystem Analysis White Paper

  • Post author:
  • Post category:

October 26, 2023,WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) is announcing a request for comment on our analysis or approaches in “Software Identification Ecosystem Option Analysis,” white paper that was published today outlining a collective, community goal for a more harmonized software identification ecosystem that can be used across the complete, global software space

Continue ReadingCISA Issues Request for Comment on Software Identification Ecosystem Analysis White Paper

CISA Releases Nine Industrial Control Systems Advisories

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Cybersecurity &

Continue ReadingCISA Releases Nine Industrial Control Systems Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2023-5631 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Note: To view other newly added vulnerabilities in the catalog, click on the

Continue ReadingCISA Adds One Known Exploited Vulnerability to Catalog

VMware Releases Security Advisory for vCenter Server

  • Post author:
  • Post category:

VMware released a security advisory for a vulnerability (CVE-2023-34048) affecting the VMware vCenter Server and (CVE-2023-34056) affecting [VMware Cloud Foundation]. A remote cyber actor could exploit these vulnerabilities to obtain information or take control of an affected system. CISA encourages users and administrators to review the VMware vCenter Server Out-of-Bounds Write Vulnerability VMSA-2023-0023 advisory and apply the

Continue ReadingVMware Releases Security Advisory for vCenter Server