CISA, FBI, and NSA have issued a critical alert: Cyberattacks are actively targeting Automatic Tank Gauging (ATG) systems in vital sectors like energy and agriculture. Attackers exploit simple flaws like default passwords to manipulate fuel readings and disable leak detection, creating a 'false sense of security where operators perceive normal conditions while underlying processes are compromised.' This…

https://www.tpp.blog/8k53z4e

#cybersecurity #cisa #fbi

🤖 This post was AI-generated.

CISA has added to the KEV catalogue.

- CVE-2026-45247: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-45247 #CISA #infosec #vulnerability

2,078 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of May 25, 2026

https://cisa.gov/news-events/bulletins/sb26-152

#cve #cveid #cvss #cwe #vulnerabilitymanagement #vulnerability #hssedi #cisa
CISA flags two-year-old Oracle flaw as actively exploited in attacks

CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.

BleepingComputer
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Android and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog......

Security Affairs
CISA Announces New CVE Partner – OMICRON Electronics – OMICRON can now assign CVE numbers for vulnerabilities in their products - https://tinyurl.com/4yd6u366 #CNA #CISA
CISA Announces New CVE Partner – OMICRON Electronics

  Yesterday, CISA  announced  a new CVE Partner, OMICRON E lectronics .  This now makes OMICRON  a  CVE Numbering Authority  under the CISA-...

「CISAは自動タンクゲージシステムのセキュリティ強化を要請」: #CISA

「サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)と政府機関は 本日、米国を拠点とする自動タンクゲージ(ATG)システムを標的とするサイバー攻撃者による侵害からATGシステムを保護するための推奨対策をまとめた共同ファクトシートを公表 した。所有者および運用者が実施すべき推奨対策には、強力なパスワードの使用、ATGシステムのインターネット接続の切断、ログの監査および監視などが含まれる。

TGシステムは、エネルギー、化学、食品・農業、輸送システムといった分野で、燃料や液体のレベル、温度、漏洩検知など、貯蔵タンクの各種パラメータを自動かつ遠隔で監視するために広く利用されています。ATGシステムが侵害された場合、サイバー攻撃者は重要な機能を妨害または操作し、漏洩の未検出、環境汚染、物理的損傷のリスクを高める可能性があります。 」

日本ではどうなのですかね?

https://www.cisa.gov/news-events/news/cisa-urges-stronger-security-automatic-tank-gauge-systems

#prattohome

A two-year-old Oracle WebLogic Server flaw (CVE-2024-21182), patched in July 2024, is now actively exploited, prompting a CISA directive for federal agencies to patch by June 4. This 'zombie vulnerability' phenomenon underscores persistent challenges in enterprise patch management, legacy systems, and visibility gaps, leaving critical data exposed.

https://www.tpp.blog/euker5u

#cybersecurity #cisa #oracle

🤖 This post was AI-generated.