Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
13 results for “infrastructure security”
Critical Progress LoadMaster flaw now actively exploited in attacks
CISA issued an alert confirming active exploitation of a critical command injection vulnerability in Progress Kemp LoadMaster load balancers, posing immediate risk to organizations using the appliance.
Aug 10, 2026
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA added CVE-2026-63077 — a critical remote code execution vulnerability in on-premise JetBrains TeamCity — to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation.
Aug 6, 2026
Trump blames Tim Walz for water hacks even though it’s probably Iran
Donald Trump publicly blamed Minnesota Governor Tim Walz for cyberattacks on water systems despite U.S. federal agencies indicating Iran is the likely perpetrator — a misattribution that risks undermining public trust in official threat assessments and inflaming political tensions around critical infrastructure security.
Aug 1, 2026
CISA warns of cyberattacks disrupting U.S. water utilities
CISA issued a public warning about rising cyberattacks on internet-connected PLCs used in U.S. water and wastewater utilities, highlighting an acute operational risk to critical infrastructure.
Jul 31, 2026
US investigating if Iran launched cyberattack on Minnesota water facilities
A US cybersecurity investigation is underway into a coordinated cyberattack targeting over 30 municipal water facilities in Minnesota, with preliminary indicators pointing to possible Iranian actor involvement.
Jul 31, 2026
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
A zero-day vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) software is actively exploited, allowing unauthenticated remote access via static credentials — posing a material risk to organizations relying on this critical network security infrastructure.
Jul 30, 2026
Rethinking critical infrastructure security for the age of AI
A government release frames AI-driven critical infrastructure security risks as systemic interdependencies rather than isolated flaws, signaling a shift toward holistic, cross-sector cyber resilience policy.
Jul 30, 2026
Closing the Identity Gaps in Critical Infrastructure Security
Specops Software advocates for extending Zero Trust frameworks to include device trust verification alongside user identity in critical infrastructure access control, citing credential theft and compromised devices as common attack vectors.
Jul 21, 2026
CISA warns admins to patch actively exploited SharePoint flaws
CISA issued an emergency advisory warning that three SharePoint Server vulnerabilities are under active exploitation, requiring immediate patching to prevent compromise of internet-exposed on-premises deployments.
Jul 15, 2026
CISA warns of actively exploited RCE flaws in Joomla extensions
CISA issued an advisory warning that two Joomla extensions—iCagenda and Balbooa Forms—are under active exploitation via arbitrary file upload flaws enabling remote code execution.
Jul 13, 2026
CISA orders feds to prioritize patching Langflow auth bypass flaw
CISA issued an emergency directive requiring federal agencies to patch a critical, actively exploited authentication bypass vulnerability in Langflow—a low-code AI agent development framework—within days.
Jul 9, 2026
CISA orders feds to patch max severity ColdFusion flaw by Friday
CISA mandated federal agencies to urgently patch a critical, actively exploited vulnerability in Adobe ColdFusion by Friday, reflecting an immediate operational cybersecurity risk to U.S. government systems.
Jul 9, 2026
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
A security vulnerability in Google's Dialogflow CX platform—dubbed a 'rogue agent' flaw—allowed unauthorized data exfiltration from AI chatbots, was reported by Varonis in late 2025, and has since been patched.
Jul 9, 2026