#CISA
This archive brings together coverage of the U.S. cybersecurity agency, its regulatory activity, and the alerts it issues on threats, vulnerabilities, and best practices. It also tracks how those guidelines affect organizations in Latin America, where they often serve as a benchmark for defense teams, incident response, and risk management.
FBI, CISA warn on U.S. water attacks
FBI, CISA and EPA flagged attacks on U.S. critical infrastructure, including water systems and tankers, plus exposed utility credentials.
Oct 3, 2026 · 3 min
CISA Adds CVE-2026-88772 in Citrix NetScaler
CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC
Sep 30, 2026 · 2 min
CISA, FBI issue ICS integrator guidance
The guide urges tighter remote access controls, stronger contracts, and manual operations for critical infrastructure using third-party ICS integrators.
Sep 29, 2026 · 3 min
CISA adds SharePoint CVE-2026-65660 to KEV
CISA added CVE-2026-65660 to the KEV catalog after active exploitation was reported. Microsoft has already released patches.
Sep 27, 2026 · 2 min
CISA Confirms Active Exploitation of ScreenConnect
CISA confirmed active exploitation of CVE-2026-84869 in ScreenConnect. ConnectWise told customers to update to 26.6.5
Sep 22, 2026 · 2 min
Ransomware Targets VMware vCenter in Latin America
CISA said ransomware is exploiting a critical VMware vCenter flaw, while reports point to victims and active campaigns in Latin America.
Sep 20, 2026 · 2 min
Cisco confirms CVE-2026-76460 in ISE
Cisco disclosed an auth bypass in ISE and ISE-PIC with active exploitation and no workaround. Patches are required for 3.1 to 3.5.
Sep 18, 2026 · 2 min
CVE-2026-76461 Hits Cisco Secure Email Gateway
Cisco confirmed active exploitation in Secure Email Gateway. The flaw can let attackers run commands as root through a crafted email.
Sep 16, 2026 · 2 min
CISA adds 7 critical flaws to KEV
CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.
Sep 12, 2026 · 3 min
Microsoft fixes 974 flaws, including two zero-days
Microsoft’s September 2026 Patch Tuesday fixed 974 vulnerabilities, including two actively exploited Windows zero-days.
Sep 9, 2026 · 3 min
Google patches Chrome for CVE-2026-85046
Google issued an emergency Chrome update fixing CVE-2026-85046, an actively exploited flaw in V8.
Sep 8, 2026 · 3 min
CISA adds active PaperCut flaws to KEV
CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut
Sep 6, 2026 · 2 min
CISA Adds Citrix, SQL Server CVEs to KEV
CISA added exploited flaws in August, including Citrix NetScaler, Microsoft SQL Server and VMware vCenter, to its KEV catalog.
Aug 29, 2026 · 3 min
CISA exposes flaws in two U.S. SOCs
AA26-237A details two red team tests against U.S. critical infrastructure and finds gaps in phishing and Active Directory defenses.
Aug 27, 2026 · 3 min
CISA warns on active Siemens S7 PLCs
CISA expanded its alert on Siemens S7 PLCs and said more than 100 water systems were hit in July, with limited but real impacts.
Aug 24, 2026 · 4 min
Medusa tops 500 victims in health sector
FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
Aug 22, 2026 · 2 min
CISA adds five critical CVEs to KEV catalog
CISA added CVE-2026-73570 in Zimbra to KEV and set the federal remediation deadline for Aug. 24.
Aug 22, 2026 · 4 min
US Alerts on Gunra, Unlimited Breach Hits 3.8M
US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.
Aug 16, 2026 · 3 min
THEGENTLEMEN, Gunra, INC Ransom hit Latin America
THEGENTLEMEN, Gunra and INC Ransom added victims and alerts across the region, with a focus on VPNs, firewalls
Aug 15, 2026 · 3 min
US Water Attacks Hit 12 States, NY Funds Defense
Water attacks in the U.S. affected at least 12 states. New York is funding 153 systems as Latin America exposes energy gaps.
Aug 10, 2026 · 38 min