This Week in Security: Messing with AI, 7Zip and Notepad++ Vulnerabilities, HTTP2 Bomb, and More

https://fed.brid.gy/r/https://hackaday.com/2026/06/05/this-week-in-security-messing-with-ai-7zip-and-notepad-vulnerabilities-http2-bomb-and-more/

🚨 EXECUTIVE ADVISORY: CISA flags CVE-2026-45247 in Mirasvit Cache Warmer as an active ransomware threat vector. Total business interruption risk. Mandatory remediation deadline is June 6, 2026. Protect your edge.
https://thecybermind.co/y1lw

#Cybersecurity #CISA #RiskManagement #TheCyberMind

CVE-2026-45247 CISA CSUITE Brief: Ransomware Alert | TCM

Urgent executive risk advisory tracking CVE-2026-45247 in Mirasvit Cache Warmer. Active ransomware threat vector requires mandatory corporate mitigation.

The Cyber Mind
U.S. CISA adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog.

Security Affairs
CISA warns of cyberattacks targeting fuel tank monitoring systems

CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors.

BleepingComputer
CISA has listed several industrial vulnerabilities:https://www.cisa.gov/ #CISA #vulnerability #infosec
Homepage | CISA

CISA leads the effort to enhance the security, resiliency, and reliability of the Nation's cybersecurity and communications infrastructure.

The Record: Andersen: CISA directive for AI executive order to be released this week https://therecord.media/cisa-directive-for-ai-exec-order-release

Earlier:

"Mullin hinted that the White House intends to announce a nominee to run the department’s cyber wing, which has been without a Senate-confirmed chief since Trump was sworn back into office."

“We've got a person, soon to be nominated, that will be running CISA, that has the ability to recruit and focus on the authorities we have. We want CISA to be the leader in cybersecurity. They should be and they will be.”

DHS chief signals efforts to reshape CISA https://therecord.media/dhs-chief-signals-efforts-to-reshape-cisa @therecord_media #CISA #infosec

CISA directive for AI executive order to be released this week, Andersen says

The binding operational directive will focus in part on “vulnerability alleviation and vulnerability management,” Andersen said in remarks delivered at the TechNet Cyber conference in Baltimore.

CISA's Binding Operational Directive 18-01 required all federal civilian agencies to implement DMARC at p=reject by October 2018.

if you're a federal contractor, a supplier to government agencies, or in a regulated industry watching where compliance trends go — BOD 18-01 is the blueprint.

the pattern is consistent:

- mandate
- monitor
- enforce
- reject

every major mailbox provider has followed the same playbook.

https://dmarcguard.io/learn/dmarc/

#DMARC #EmailSecurity #CISA #Compliance

DMARC Email Auth Guide [2026] | DMARCguard

Learn how DMARC protects your domain from email spoofing. Covers DMARC records, policies (none/quarantine/reject), alignment, reporting, and SPF/DKIM.

DMARCguard
CISA warns of active attacks exploiting Android, Linux bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.

BleepingComputer

CISA Warns of Exploited Magento Extension Flaw

A critical flaw in the Mirasvit Full Page Cache Warmer Magento extension, tracked as CVE-2026-45247, has been exploited by hackers, allowing them to execute remote code without authentication. This vulnerability, rated 9.8 on the CVSS scale, enables attackers to wreak havoc by supplying a malicious PHP object in the CacheWarmer…

https://osintsights.com/cisa-warns-of-exploited-magento-extension-flaw?utm_source=mastodon&utm_medium=social

#MagentoExtensionFlaw #Cve202645247 #DeserializationVulnerability #RemoteCodeExecution #Cisa

CISA Warns of Exploited Magento Extension Flaw

Protect your Magento site from exploited extension flaw CVE-2026-45247. Learn how to patch Mirasvit Full Page Cache Warmer vulnerability now and prevent remote code execution attacks.

OSINTSights

Mullin Targets 2,800 Staff for Optimal CISA Operations

Department of Homeland Security Secretary Markwayne Mullin aims to boost the Cybersecurity and Infrastructure Security Agency's effectiveness with a targeted workforce of 2,800 personnel, leveraging public partnerships and strategic grant usage to fortify national security.

https://osintsights.com/mullin-targets-2800-staff-for-optimal-cisa-operations?utm_source=mastodon&utm_medium=social

#Cisa #Cybersecurity #Government #NationalSecurity #PublicPartnerships

Mullin Targets 2,800 Staff for Optimal CISA Operations

Learn how Secretary Markwayne Mullin targets 2800 staff for optimal CISA operations and discover the strategy behind this goal - read now and stay informed.

OSINTSights