Archive for CISA

The CISA releases election security plan 40 days before midterms

Posted in Commentary with tags on September 25, 2026 by itnerd

The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials.

The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.

CISA also designated its 10 regional directors as Election Security Advisors responsible for connecting state and local officials with federal cybersecurity resources. The plan comes after staffing and program reductions affected CISA’s election security operations, with some state election officials raising concerns about reduced federal support ahead of the midterms.

Ted Miracco, CEO, Approov:

“CISA’s new 2026 Election Infrastructure Security Plan is right to insist on paper ballots and hand audits. But it never once mentions mobile devices, apps or APIs, which is a strange gap given how much of American voting now runs through them.

“Most US jurisdictions check voters in on electronic poll books, and the most widely used one runs on Apple iPads. Forty-two states and D.C. let people register online, and millions of voters track their mail ballots by text message.

“Bangladesh, which went to the polls in February, took a clearer-eyed approach. Its Election Commission built a mobile app that registered more than 450,000 overseas voters and let them follow their ballots. Then it had every one of them mark a paper ballot and mail it home. The same commission had already scrapped electronic voting machines for all future elections. That is the right design: phones for access and tracking, paper for the vote itself, and serious security for the digital layer in between. Nobody can hack a paper ballot from abroad. They can hijack the phone number that gets a county clerk into the voter rolls. America already has the paper half. What it lacks is a federal plan that treats the phone in a voter’s pocket, and in an election official’s hand, as election infrastructure. While the ballot itself can stay analogue, the threat model cannot.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security:

“My firsthand work as an offensive security tester has taught me that election security extends beyond voting equipment to the people, infrastructure, vendors, and processes supporting elections. A plan or scan is a starting point; the safeguards need to be tested in practice.”

Cyber and physical threats are clearly present when it comes to the midterms. And I am glad that someone is securing them from being tampered with. I hope that true with any threat that comes along.

The CISA, FBI warn critical infrastructure operators of third-party ICS risks

Posted in Commentary with tags , on September 24, 2026 by itnerd

The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege.

The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities. The attackers searched for customer and SCADA information and created nine ZIP files containing approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details and schematics.

CISA and the FBI recommend that operators secure and monitor third-party remote access, minimize internet exposure, inventory hardware and software supplied by integrators, include cybersecurity and supply chain requirements in contracts, and maintain offline backups and manual operating capabilities.

Denis Calderone, CTO, Suzu Labs:

“The ugly side of the outsourced ICS model is the amount of trust that goes along with it. Integrators are a vital part of this ecosystem, especially for smaller operators that could never staff all of that engineering expertise themselves. The integrator needs the keys to the castle. They will be responsible for maintaining network diagrams, device configurations and SCADA details while maintaining a privileged path into the operational environment. CISA and the FBI have now documented exactly why this can be a problem and how this extension of trust directly alters the risk profile of the operator.

“The FBI has not said whether this company was selected because of its role as an integrator, but the post-compromise activity strongly suggests the actors knew what they were after. They searched specifically for ‘customers’ and ‘SCADA’ and staged roughly 800 files of device details and schematics. That is targeted intelligence collection against a company that holds a map of multiple critical infrastructure environments in one place. We have been concerned about how third-party integrators implement operational security for decades. As a professional penetration tester for more than 25 years, I have repeatedly seen integrators or all sorts (ICS, building security systems, environmental controls systems, etc) ignore basic security standards while the client fails to notice because, after all, they outsourced that headache. The more than 100 water systems compromised across the US since July illustrate the consequences of the same kinds of implementation failures. Weak or default passwords, architectures designed without meaningful isolation, little or no monitoring across ICS and SCADA networks, and PLCs placed directly on the internet where anyone can find and attack them. The fact that the integrator became the target itself is of no surprise to me.

“The way to manage this relationship is through the contract and then through audit. Put least privilege, named accounts, unique credentials, MFA, data location and retention, patching, incident notification, access termination and a right to audit into the agreement. Then verify those obligations in the environment. Inventory every component and connection the integrator supplied, inspect the remote-access logs, confirm default credentials are gone, make sure no controller is sitting on the public internet, and prove that your team can cut off the vendor, restore from a local offline backup and operate safely without them. If you cannot see, limit and terminate the integrator’s access, you have outsourced more than engineering.”

John Strand, Owner, Black Hills Information Security:

“Whenever I see stories like this, I keep coming back to the fundamentals. One of my mentors used to say, ‘Good security is nothing more than an inspired application of the fundamentals.’ And that still holds true.

“We talk about reviewing third-party access into systems, but that’s basic access control and authorization. These aren’t new security concepts. What stories like this continue to expose is just how often the fundamentals still aren’t implemented.

“For all the money we’ve spent and all the technology we’ve deployed, there are still legacy systems, legacy network connections, and old pathways into critical environments. We keep seeing the same lessons repeated because organizations haven’t fully addressed the lessons we should have learned years ago.

“The fundamentals are still fundamental. And unfortunately, we’re still failing at them.”

Critical infrastructure has been a target for threat actors forever. Now is the time to secure it. Because if not now, when?

The CISA tells organizations to use fake systems and data to catch hackers 

Posted in Commentary with tags on September 17, 2026 by itnerd

CISA has released new guidance encouraging defensive teams to deploy cyber decoys, including fake systems, accounts, credentials and data, to detect and disrupt attackers already inside their networks.

The guidance targets a growing detection problem in which attackers use legitimate credentials, built-in tools and “living off the land” techniques to move through networks without triggering traditional security defenses.

Decoys such as honeypots, honeytokens, breadcrumbs and tripwires are designed to look legitimate but generate high-confidence alerts when an unauthorized user interacts with them. CISA says organizations can begin deploying decoys without major infrastructure changes or significant new spending, including by using existing endpoint detection, identity and access management, and data loss prevention tools.

The agency recommends incorporating decoys into Zero Trust and “assume compromise” strategies to identify attackers earlier, collect threat intelligence and reduce the time between an intrusion and its detection.

Donald McFarlane, Board Member, Xcape Inc.:

“I have advocated deception for decades because it can be one of the highest-ROI controls in cybersecurity.

“Most security monitoring tries to distinguish malicious activity from an enormous volume of legitimate activity. Well-designed deceptive controls turn that problem on its head: nobody conducting legitimate business should be touching certain combinations of decoy accounts, identities, credentials, servers, systems or data. When someone does, the signal can be extraordinarily high confidence.

“Deception also changes the economics for the attacker. The attacker has to distinguish the real from the fake every time. The defender only needs them to touch the wrong thing once.

“CISA is right to push this as part of an assume-compromise strategy. More broadly, cybersecurity has much to learn from military doctrine. Effective defense is not simply building higher castle walls and trying to defend every point equally. Cyber defenders should be employing deception and manoeuvre; shaping the battlespace; channeling adversaries toward ground of the defenders’ choosing; and creating opportunities to detect and disrupt them.”

John Strand, Owner, Black Hills Information Security:

“This is one of the coolest bits of security news I’ve seen in a long time. I’ve been pushing cyber deception for years, teaching it at Black Hat and through Anti-Siphon Security Training, and I love the recognition that this does not have to be expensive. You don’t need some massive commercial product to get started. You can create accounts in Active Directory that should never be used and trigger an alert the second somebody tries to authenticate with them. You can deploy simple honey tokens for free. Yes, there are great commercial offerings too, but cost should not be the reason you aren’t doing deception.

“The bigger issue is that too many security teams treat cyber deception as something you deploy after you get everything else right. I completely disagree. Deception should go in immediately, right alongside your other security controls. It gives you something incredibly valuable. An attacker touching something that no legitimate user should ever touch. That is a signal worth paying attention to. This is nothing but good news for defenders.”

This is cool and scary at the same time. I say that because that shifts the responsibility for law enforcement outside law enforcement. We will have to see if that works out well, or goes horribly bad.

The CISA cuts critical infrastructure security services, concerns grow over the shrinking agency 

Posted in Commentary with tags on September 5, 2026 by itnerd

The CISA is ending six free cybersecurity assessment programs used by critical infrastructure operators to identify weaknesses in their defenses against ransomware, supply-chain attacks and other cyber threats.

The cuts include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.

The assessments provided hands-on assistance from CISA regional advisers to organizations including water utilities, hospitals, local governments and other operators that may not have the resources to pay for comparable private-sector security reviews. CISA says it is retiring the programs to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.

The move comes amid broader concerns about CISA’s ability to protect U.S. critical infrastructure following significant reductions in its workforce and budget. The agency has lost roughly one-third of its workforce, while its 2026 budget was cut by approximately $300 million.

Denis Calderone, CTO, Suzu Labs:

“My apologies to those I told to leverage these free resources recently. We’ve been pointing to those how lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.

“The timing here stinks. CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, To be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone, we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.

“We’ve been worried about CISA’s capacity all year. The agency lost roughly a third of its workforce over the last 18 months. When DHS announced plans to hire 600 new staff and CISA started extending offers for 329 mission-critical positions, it felt like maybe the rebuilding was starting. But as of late August, it’s unclear how many of those hires have actually come on board, and now we’re watching assessment programs get cut instead. This during a year where critical infrastructure attacks are continuing to increase.

“CSET is open source and older versions on GitHub still include all six retired assessment modules. CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone. Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Do the people making these decisions have any access to the news?

“Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.

“And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?

“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments. Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services.

“This is crazy.

“We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs.

“Instead, we’re pulling resources away from them while the attacks are increasing.”

The White House and the US government are failing US citizens when the CISA is needed the most. And they will likely come to the conclusion after they get pwned by everyone rather than taking proactive measures to stop that from happening.

The CISA and FBI advise organizations to drop PR spin during major IT, OT outages 

Posted in Commentary with tags , on September 3, 2026 by itnerd

The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.

The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”

The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.

During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.

Joshua Marpet, Senior Product Security Consultant, Finite State:

“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”

“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”

Denis Calderone, CTO, Suzu Labs:

“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.

“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.

“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.

“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?

“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.

“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.

“Just as importantly, there needs to be political cover for the people who make those decisions.

“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”

Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.

Congress temporarily extends CISA 2015 through December

Posted in Commentary with tags on September 2, 2026 by itnerd

The House has approved a stopgap government funding bill that temporarily extends the Cybersecurity Information Sharing Act of 2015 through December 11, preventing the key cyber law from expiring at the end of September. The Senate previously passed the measure, which now heads to the President for his signature.

Industry groups and federal cyber officials have warned that allowing CISA 2015 protections to lapse could discourage companies from sharing breach and threat information and disrupt real-time intelligence sharing between government and the private sector.

CISA 2015 briefly expired during last year’s government shutdown, and efforts to secure a long-term reauthorization have repeatedly stalled despite calls from the White House and industry for a more permanent solution. The stopgap bill also extends the Technology Modernization Fund and National Cybersecurity Protection System through December 11.

Doc McConnell, Head of Policy and Compliance, Finite State:

“Although it is a positive sign that Congress has extended the Cybersecurity Information Sharing Act of 2015 through December rather than allow it to lapse, short-term renewals are counterproductive to our goals of shared cybersecurity responsibilities and free-flowing threat information.

“The United States has placed a bet that voluntary information-sharing is the best model for collective security. The benefit of pooling threat data means companies can learn from threat activity across the ecosystem and proactively defend themselves, rather than waiting to be targeted individually. CISA 2015 reduces the potential risks to sharing this data by creating liability protections, exemptions from antitrust concerns, and prohibitions on using this data for regulatory enforcement actions.

“Our voluntary approach stands in stark contrast to governments elsewhere, such as the European Union, that have strict mandatory reporting and disclosure requirements. If we want to demonstrate that the voluntary approach can be successful, we need a long-term, predictable structure to build trust. We cannot build that trust if companies expect their risk calculus to change every 90 days.”

Denis Calderone, CTO, Suzu Labs:

“Congress keeps telling us cybersecurity is a national priority and then governing it like it’s an afterthought. This is the second near-lapse of CISA 2015 in a year, and last year’s brief expiration during the shutdown sent legal teams scrambling. Some organizations paused their threat sharing programs entirely until the protections were confirmed back in place. The liability protections in CISA 2015 are what make private sector threat sharing work, and that kind of uncertainty slows down exactly the intelligence sharing that is so needed in the industry. The law has had broad bipartisan support since it was enacted in 2015 and the White House has been pushing for a permanent reauthorization. If you can’t get a long-term deal done on a law that virtually nobody opposes, that tells you everything about where cyber policy actually ranks on the Hill.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Every few months, the industry has to wonder whether the legal framework that makes threat sharing possible will still exist by the end of the quarter. Companies making decisions about what to share and with who are already calculating risk, and this kind of administrative instability changes those calculations before any law actually expires. Extending CISA 2015 to December 11 buys time, but it still doesn’t fix what the recurring uncertainty is doing to the underlying trust that makes information sharing work in the first place.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“It is disappointing that cybersecurity information sharing has once again proved so intractable in Washington.

“I share Senator Paul’s broader concerns about government overreach, but opening voluntarily-shared threat intelligence to FOIA, or stripping away the narrow good-faith liability protections that enable sharing, seems like solving the wrong problem.

“If Washington cannot provide a durable framework for collective defense, it only serves to make private-sector partnerships that are less dependent on Washington look more attractive.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In the early years of computer security, there was a huge reticence to publicly share information about breaches or vulnerabilities in products. Even penetration testing was something that was largely done in the shadows.

“Laws like this helped pull that information sharing out of the darkness. And that sharing is something the entire security industry now lives and breathes on. Researchers share vulnerabilities. Organizations share information about attacks. Security teams share indicators and techniques. That flow of information makes everybody better at defending their networks.

“So I think it’s incredibly important that they extended it. I’m just a little disappointed that this is another short-term extension that only buys us a few more months.

“This shouldn’t be something we have to keep revisiting every few months. It needs to be permanent. We need to make sure the level of information sharing we’ve developed over the past seven or eight years continues without organizations having to wonder whether the legal protections that helped enable it are suddenly going to disappear.”

The CISA does a lot of good work. Honestly, they need to funded in the long term. Otherwise the US is really going to come under threat from a cybersecurity standpoint.

The CISA Warns Users Of The Gitea Flaw

Posted in Commentary with tags on August 27, 2026 by itnerd

The CISA  warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. What’s Gitea you ask? CVE-2026-60004 which gets an almost perfect CVSS score of 9.8 centres around remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user.

In other words, it’s bad.

Noelle Murata, COO, Xcape, Inc. (https://www.linkedin.com/in/nmurata)

“Compromising developer infrastructure grants threat actors direct access to source code, intellectual property, and pipeline secrets, turning software management platforms into high-leverage launchpads for downstream supply chain attacks and malicious code insertion. Pipelines concentrate high-value trust and credentials, making developer tools a preferred target over hardened perimeters. The build pipeline is where trust and credentials concentrate, so attackers skip the hardened perimeter and target the choke point instead.

“Although the CISA advisory targets federal agencies, private industry should take note as well. This vulnerability requires an authenticated user; however, Gitea’s default configuration allows self-registration, enabling external adversaries to easily gain the required access. Default settings like open self-registration convert unauthenticated external threats into authenticated exploit paths.

“Most of the defense relies on configurations you already own: mounting directories with noexec, closing self-registration, monitoring for new user sign-ups, and using scoped tokens defangs the exploit before you ever reach the patch. Hardening existing configurations (disabling self-registration, enforcing noexec, and scoping tokens) defangs exploits while patches are deployed. Ultimately, hardening development environments requires security teams to enforce strict access controls and patch their systems without delay.

“Defense in build environments comes down to simple hygiene: lock down registration, scope your tokens, and patch your systems.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Gitea has been the target of other recent attacks. At first glance, it may appear that attackers are interested in going after software repos specifically, because development environments can be target rich. But considering the gaping security holes that are being discovered, its more likely that these are opportunistic.

“In the case of this vulnerability, it requires that the user be authenticated, and have write access. This sounds like it would be somewhat limiting, as proper permissions and IAM processes would effectively block attackers out. However by default, Gitea allows users to self-register their own accounts, and setup new repos which they then have write access to. Meaning that in practice, any unauthenticated attacker without write access can simply grant themself those permissions, and exploit away.

“The impact of this depends entirely on the motivations of the attackers. We’re seeing reports of this exploit being used for crypto mining. It’s common for low effort attacks to utilize RCE exploits to simply mine a bit of crypto. This wastes organizational resources, but only minimally interferes with normal operations, and cleanup tends to be straight forward. Higher impact attackers could perform more disruptive attacks, such as ransomware. Especially now that this is getting attention for how easy this one is to exploit. Same exploit, different monetization strategies.

“As always, patch your systems, people!”

Patching your systems should be the first thing that you do as 9.8 out of 10 isn’t good from a security standpoint.

The CISA orders federal agencies to patch actively exploited Oracle flaw by August 27

Posted in Commentary with tags on August 25, 2026 by itnerd

The CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.

The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.

Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.

CISA has ordered federal agencies to address the vulnerability by August 27.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs Had This To Say:

   “CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.

   “In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.

   “BOD 26-04’s 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA’s August 24 KEV addition produced an August 27 federal remediation deadline, while CISA’s obligation is to update the catalog “as quickly as possible,” with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA’s own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.

   “Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”

This of course means update all the things ASAP. But we’re getting to a point where patching anything is a losing battle. Thus we need to think of something new when this avenue exhausts itself.

UPDATE: Also Commenting on this is Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth: 

“The thousands of organizations relying on Oracle WebLogic to provide secure access to their applications are at risk of data loss, manipulation, and exfiltration. The unauthenticated access allows an attacker to make application calls to read data, as well as insert their own unauthorized changes. This issue affects any server accessible to an attacker, which is extremely problematic for many internet exposed applications.”

The CISA warns Medusa ransomware has hit over 500 critical infrastructure organizations  

Posted in Commentary with tags on August 19, 2026 by itnerd

The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech: 

“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.

To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”

The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:

   “It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.

   “The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.

   “Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.

   “Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.

   “While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.

   “Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.

   “Critical Takeaways

  • Hygiene failure: Medusa primarily weaponizes well-known, patchable vulnerabilities on Internet-facing systems rather than relying strictly on complex zero-days.
  • Administrative accountability: Lacking a dedicated security operations team does not absolve internal or third-party sysadmins from performing fundamental software maintenance.
  • Extortion escalation: Threat actors are increasingly turning to multi-stage extortion and re-extorting victims who pay, making immutable off-grid backups essential.

   “Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs. 

   “Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats. 

   “The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”

Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

Posted in Commentary with tags , , on August 11, 2026 by itnerd

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

UPDATE: Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this comment: 

“Gunra made multi-factor authentication (MFA) lie for them. In the South Korean case, the group modified virtual desktop infrastructure (VDI) authentication files to accept a hardcoded attacker-chosen one-time password, and every subsequent login looked legitimate to monitoring tools. Most organizations treat MFA as the last line of defense. Gunra treated it as the first thing to subvert.

“The sector targeting is economic. Healthcare, financial services, and government can’t tolerate downtime or survive a data leak. Encrypting their systems while threatening to publish stolen records hits both pressure points at once.

“CVE-2024-55591 and CVE-2025-24472, the two Fortinet authentication bypasses that got them initial access, are eighteen months old and have been exploited by multiple ransomware groups. Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.

“The advisory also flags a recoverable flaw in Gunra’s Linux encryptor. The variant seeds its ChaCha20 keys with time() instead of a secure random number generator, so defenders who preserve file timestamps can reconstruct keys without paying. Any organization hit by the Linux variant should get forensics involved before wiring cryptocurrency.

“Gunra created a “forticloud-sync” account with super user privileges and a hardcoded password on compromised Fortinet firewalls. That account survives a firmware update, and so do modified VDI authentication files. An organization that patches and stops there is giving Gunra a head start on round two.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The goal of targeting critical infrastructure is really twofold. With nation-state attacks, the objective can be straightforward. You want to create pain for your adversary. But with ransomware groups, I think there are two things we need to understand.

“First, critical infrastructure has become a dinner bell. Ransomware groups have seen how exposed and neglected some of this infrastructure is in countries like the United States, and now they’re swarming toward it because they recognize the opportunity.

“The second factor is pain. There’s been a major push in the security industry for organizations to refuse ransomware payments. But that position becomes much more complicated when an attack against critical infrastructure potentially impacts hundreds of thousands or even millions of people. It’s one thing to say you won’t pay the bad guys when the impact is contained to your organization. It’s another thing entirely when water, power, healthcare, or essential municipal services are disrupted. At that point, refusing to pay may sound principled, but elected officials also have to answer to the people whose lives are being disrupted. That creates enormous pressure to restore those services as quickly as possible.”