CISA's BOD 26-04 sets a 3-day patch clock for KEV on internet-exposed federal systems. FedRAMP is already aligned. Analysts expect CMMC, NIS2, and DORA to follow. Insurers are folding the same logic into questionnaires. It's formally a federal directive; functionally it's becoming an industry baseline. https://www.cybrsecmedia.com/federal-agency-or-not-how-bod-26-04-is-coming-for-your-vulnerability-management-program/
#infosec #vulnerabilitymanagement #patchmanagement #CISA
Federal Agency or Not: How BOD 26-04 Is Coming for your Vulnerability Management Program

CISA's BOD 26-04 tells federal agencies how fast to patch. It's quietly telling everyone else the same thing: through insurance underwriting, vendor contracts, and regulatory alignment.

CYBR.SEC.Media
CISA Adds Lantronix And UniFi OS Vulnerabilities To KEV

On June 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to the Known Exploited Vulnerabilities catalog

CyberSecureFox

Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited

On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CVE-2026-33017 (unauthenticated RCE, CVSS 9.3) against the same instance. Despite its lower score, the RCE has been exploited thousands of times and is listed in CISA KEV, while the IDOR showed no prior in-the-wild exploitation. The operator focused primarily on the RCE for code execution and implant delivery, using the IDOR opportunistically for credential theft across tenants. The financially motivated threat actor deployed a scripted loader to harvest AWS keys, environment files, and API credentials. This demonstrates that CVSS scores don't always correlate with real-world exploitation rates, as unauthenticated vulnerabilities require less effort than those needing authorization and disclosed object IDs.

Pulse ID: 6a3eefb892e3d749bcf92233
Pulse Link: https://otx.alienvault.com/pulse/6a3eefb892e3d749bcf92233
Pulse Author: AlienVault
Created: 2026-06-26 21:31:36

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AWS #CISA #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

CISA and FBI issue PSA:
Russian Intelligence Services Continue to Target Commercial Messaging Applications

https://www.ic3.gov/PSA/2026/PSA260626

#Cybersecurity #CISA #FBI #Encryption

Internet Crime Complaint Center (IC3) | Russian Intelligence Services Continue to Target Commercial Messaging Applications

> US Releases Anthropic’s ‘Mythos’ AI Model to Some US Companies

> Anthropic Accuses Alibaba of Illicitly Extracting Claude AI Model Capabilities

> China’s 360 Says It Developed Tools to Match Anthropic’s Mythos

> UK NCSC Warns Leaders of ‘AI Shift’ in Cyber Risk

> New Policy Memo Outlines Paths Toward AI Transparency

> New AWS ‘AITM’ Phishing Kit Discovered

> ‘Payouts the King’ Ransomware Operator Deploys New ‘EdgeCution’ Malware

> macOS ‘Gaslight’ Rust Backdoor Uses Prompt Injection Against Analysts

> WhatsApp VBS RMM Campaign Targets Users

> Polymarket Confirms $3.1 Million Theft via Third-Party Breach

> KDDI Data Breach Exposes Up to 14.2 Million Email Credentials

> Tata Electronics Hit by Cyberattack Claiming Theft of Apple, Tesla Trade Secrets

> Report: Israel Behind Cyberattack on Iranian Banks

> Mandiant Reveals How Cisco SD-WAN Zero-Day Attacks Gained Root Access

> Japan Defense Forces Used USB Drives with China-Linked Virus, Probe Finds

> U.S. Treasury Sanctions Entities Linked to Illicit Finance

> Meta Accidentally Let Employees Access Each Other’s Keystroke Data

> Russia-Linked Group Claims Cyberattack on Ukrainian Bank

> Algerian Man Extradited to U.S. for Role in Black Market Fraud Conspiracy

> Justice Department Seizes Infrastructure Used by Huione Group for Money Laundering

> Smart TV Apps Found with Residential Proxy SDKs

> CISA Sets Urgent Deadline to Fix Cisco Flaw Exploited in Attacks

> CISA Director Nominee Pledges Workforce Expansion at House Hearing:

> Trump Issues Executive Order with Post-Quantum Encryption Deadline

> European Commission Announces New Cyber Resilience Measures

> Ransomware and Data Breaches Drive Spike in Cyber Insurance Claims, Report Finds

> Security Operations for the Age of AI

#thecybersecurityclub #substack
#cybersecurity #technews #cybercrime #blackmarket
#fraud #polymarket #trump
#ai #EU #anthropic #mythos
#alibaba #china #cisa
#uk #ncsc #aws #randomware
#malware #360 #whatsapp
#kddi #tata #israel #iran
#mandiant #cisco #japan
#meta #russia #ukraine #algeria #quantumencryption

https://open.substack.com/pub/thecybersecurityclub/p/wk-26-hackers-stole-3m-from-polymarket

🚨WK 26: Hackers Stole $3M from Polymarket, Alibaba Stole Anthropic's AI, 14M Passwords Exposed & Israel Strikes Iran Banks

28.8 Million Exchanges: Anthropic Alleges Largest-Ever AI Extraction Attack by Alibaba

Weekly Cybersecurity Update
CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.

BleepingComputer

A critical shift in cyber warfare: Russian intelligence groups UNC5792 and UNC4221 are now specifically targeting Signal Backup Recovery Keys. They're not breaking Signal's strong end-to-end encryption, but rather exploiting a legitimate backup feature through sophisticated phishing. This allows them to access your *entire* message history, impacting government officials, journalists, and military…

https://www.tpp.blog/15fekz4

#cybersecurity #fbi #cisa

🤖 This post was AI-generated.

CISA Mandates Urgent Patching for Exploited Cisco Flaw

Don't wait until it's too late: Cisco has issued a critical patch for a vulnerability (CVE-2026-20230) in its Unified Communications Manager Server, and the US Cybersecurity and Infrastructure Security Agency (CISA) is requiring urgent remediation by June 28. Act now to protect your system from potential remote exploitation.

https://osintsights.com/cisa-mandates-urgent-patching-for-exploited-cisco-flaw?utm_source=mastodon&utm_medium=social

#Cisa #Cisco #Cve202620230 #ServersideRequestForgery #UnifiedCommunicationsManagerServer

CISA Mandates Urgent Patching for Exploited Cisco Flaw

Patch CVE-2026-20230 now to avoid Cisco Unified Communications Manager Server exploitation; remediate by June 28 under Binding Operational Directive 26-04 to secure your system.

OSINTSights
1,803 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of June 15, 2026

https://www.cisa.gov/news-events/bulletins/sb26-173

#cve #cveid #cvss #cwe #vulnerabilitymanagement #vulnerability #hssedi #cisa
CISA Added several industrial vulnerabilities to the catalogue: https://www.cisa.gov/ #CISA #infosec #vulnerability
Homepage | CISA

CISA leads the effort to enhance the security, resiliency, and reliability of the Nation's cybersecurity and communications infrastructure.