WASHINGTON — In response to a rapidly shifting corporate and operational landscape, the Cybersecurity and Infrastructure Security Agency (CISA) has officially released a comprehensive, updated version of its foundational Insider Threat Mitigation Guide. Published on September 9, the revised framework incorporates fresh case studies, contemporary empirical data, and targeted guidance to help organizations navigate the […]
Lessons in Transparency: A Postmortem of CISA’s Six-Month Credential Leak
In an era where the Cybersecurity and Infrastructure Security Agency (CISA) stands as the vanguard of American digital defense, the irony of a massive internal data leak originating from within its own ranks has sent shockwaves through the cybersecurity community. For six months, hundreds of sensitive credentials—including high-level Amazon AWS GovCloud administrative keys and plaintext […]
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing […]

