Archive for CISA

The CISA cuts critical infrastructure security services, concerns grow over the shrinking agency 

Posted in Commentary with tags on September 5, 2026 by itnerd

The CISA is ending six free cybersecurity assessment programs used by critical infrastructure operators to identify weaknesses in their defenses against ransomware, supply-chain attacks and other cyber threats.

The cuts include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.

The assessments provided hands-on assistance from CISA regional advisers to organizations including water utilities, hospitals, local governments and other operators that may not have the resources to pay for comparable private-sector security reviews. CISA says it is retiring the programs to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.

The move comes amid broader concerns about CISA’s ability to protect U.S. critical infrastructure following significant reductions in its workforce and budget. The agency has lost roughly one-third of its workforce, while its 2026 budget was cut by approximately $300 million.

Denis Calderone, CTO, Suzu Labs:

“My apologies to those I told to leverage these free resources recently. We’ve been pointing to those how lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.

“The timing here stinks. CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, To be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone, we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.

“We’ve been worried about CISA’s capacity all year. The agency lost roughly a third of its workforce over the last 18 months. When DHS announced plans to hire 600 new staff and CISA started extending offers for 329 mission-critical positions, it felt like maybe the rebuilding was starting. But as of late August, it’s unclear how many of those hires have actually come on board, and now we’re watching assessment programs get cut instead. This during a year where critical infrastructure attacks are continuing to increase.

“CSET is open source and older versions on GitHub still include all six retired assessment modules. CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone. Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Do the people making these decisions have any access to the news?

“Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.

“And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?

“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments. Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services.

“This is crazy.

“We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs.

“Instead, we’re pulling resources away from them while the attacks are increasing.”

The White House and the US government are failing US citizens when the CISA is needed the most. And they will likely come to the conclusion after they get pwned by everyone rather than taking proactive measures to stop that from happening.

The CISA and FBI advise organizations to drop PR spin during major IT, OT outages 

Posted in Commentary with tags , on September 3, 2026 by itnerd

The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.

The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”

The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.

During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.

Joshua Marpet, Senior Product Security Consultant, Finite State:

“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”

“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”

Denis Calderone, CTO, Suzu Labs:

“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.

“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.

“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.

“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?

“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.

“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.

“Just as importantly, there needs to be political cover for the people who make those decisions.

“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”

Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.

Congress temporarily extends CISA 2015 through December

Posted in Commentary with tags on September 2, 2026 by itnerd

The House has approved a stopgap government funding bill that temporarily extends the Cybersecurity Information Sharing Act of 2015 through December 11, preventing the key cyber law from expiring at the end of September. The Senate previously passed the measure, which now heads to the President for his signature.

Industry groups and federal cyber officials have warned that allowing CISA 2015 protections to lapse could discourage companies from sharing breach and threat information and disrupt real-time intelligence sharing between government and the private sector.

CISA 2015 briefly expired during last year’s government shutdown, and efforts to secure a long-term reauthorization have repeatedly stalled despite calls from the White House and industry for a more permanent solution. The stopgap bill also extends the Technology Modernization Fund and National Cybersecurity Protection System through December 11.

Doc McConnell, Head of Policy and Compliance, Finite State:

“Although it is a positive sign that Congress has extended the Cybersecurity Information Sharing Act of 2015 through December rather than allow it to lapse, short-term renewals are counterproductive to our goals of shared cybersecurity responsibilities and free-flowing threat information.

“The United States has placed a bet that voluntary information-sharing is the best model for collective security. The benefit of pooling threat data means companies can learn from threat activity across the ecosystem and proactively defend themselves, rather than waiting to be targeted individually. CISA 2015 reduces the potential risks to sharing this data by creating liability protections, exemptions from antitrust concerns, and prohibitions on using this data for regulatory enforcement actions.

“Our voluntary approach stands in stark contrast to governments elsewhere, such as the European Union, that have strict mandatory reporting and disclosure requirements. If we want to demonstrate that the voluntary approach can be successful, we need a long-term, predictable structure to build trust. We cannot build that trust if companies expect their risk calculus to change every 90 days.”

Denis Calderone, CTO, Suzu Labs:

“Congress keeps telling us cybersecurity is a national priority and then governing it like it’s an afterthought. This is the second near-lapse of CISA 2015 in a year, and last year’s brief expiration during the shutdown sent legal teams scrambling. Some organizations paused their threat sharing programs entirely until the protections were confirmed back in place. The liability protections in CISA 2015 are what make private sector threat sharing work, and that kind of uncertainty slows down exactly the intelligence sharing that is so needed in the industry. The law has had broad bipartisan support since it was enacted in 2015 and the White House has been pushing for a permanent reauthorization. If you can’t get a long-term deal done on a law that virtually nobody opposes, that tells you everything about where cyber policy actually ranks on the Hill.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Every few months, the industry has to wonder whether the legal framework that makes threat sharing possible will still exist by the end of the quarter. Companies making decisions about what to share and with who are already calculating risk, and this kind of administrative instability changes those calculations before any law actually expires. Extending CISA 2015 to December 11 buys time, but it still doesn’t fix what the recurring uncertainty is doing to the underlying trust that makes information sharing work in the first place.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“It is disappointing that cybersecurity information sharing has once again proved so intractable in Washington.

“I share Senator Paul’s broader concerns about government overreach, but opening voluntarily-shared threat intelligence to FOIA, or stripping away the narrow good-faith liability protections that enable sharing, seems like solving the wrong problem.

“If Washington cannot provide a durable framework for collective defense, it only serves to make private-sector partnerships that are less dependent on Washington look more attractive.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In the early years of computer security, there was a huge reticence to publicly share information about breaches or vulnerabilities in products. Even penetration testing was something that was largely done in the shadows.

“Laws like this helped pull that information sharing out of the darkness. And that sharing is something the entire security industry now lives and breathes on. Researchers share vulnerabilities. Organizations share information about attacks. Security teams share indicators and techniques. That flow of information makes everybody better at defending their networks.

“So I think it’s incredibly important that they extended it. I’m just a little disappointed that this is another short-term extension that only buys us a few more months.

“This shouldn’t be something we have to keep revisiting every few months. It needs to be permanent. We need to make sure the level of information sharing we’ve developed over the past seven or eight years continues without organizations having to wonder whether the legal protections that helped enable it are suddenly going to disappear.”

The CISA does a lot of good work. Honestly, they need to funded in the long term. Otherwise the US is really going to come under threat from a cybersecurity standpoint.

The CISA Warns Users Of The Gitea Flaw

Posted in Commentary with tags on August 27, 2026 by itnerd

The CISA  warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. What’s Gitea you ask? CVE-2026-60004 which gets an almost perfect CVSS score of 9.8 centres around remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user.

In other words, it’s bad.

Noelle Murata, COO, Xcape, Inc. (https://www.linkedin.com/in/nmurata)

“Compromising developer infrastructure grants threat actors direct access to source code, intellectual property, and pipeline secrets, turning software management platforms into high-leverage launchpads for downstream supply chain attacks and malicious code insertion. Pipelines concentrate high-value trust and credentials, making developer tools a preferred target over hardened perimeters. The build pipeline is where trust and credentials concentrate, so attackers skip the hardened perimeter and target the choke point instead.

“Although the CISA advisory targets federal agencies, private industry should take note as well. This vulnerability requires an authenticated user; however, Gitea’s default configuration allows self-registration, enabling external adversaries to easily gain the required access. Default settings like open self-registration convert unauthenticated external threats into authenticated exploit paths.

“Most of the defense relies on configurations you already own: mounting directories with noexec, closing self-registration, monitoring for new user sign-ups, and using scoped tokens defangs the exploit before you ever reach the patch. Hardening existing configurations (disabling self-registration, enforcing noexec, and scoping tokens) defangs exploits while patches are deployed. Ultimately, hardening development environments requires security teams to enforce strict access controls and patch their systems without delay.

“Defense in build environments comes down to simple hygiene: lock down registration, scope your tokens, and patch your systems.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Gitea has been the target of other recent attacks. At first glance, it may appear that attackers are interested in going after software repos specifically, because development environments can be target rich. But considering the gaping security holes that are being discovered, its more likely that these are opportunistic.

“In the case of this vulnerability, it requires that the user be authenticated, and have write access. This sounds like it would be somewhat limiting, as proper permissions and IAM processes would effectively block attackers out. However by default, Gitea allows users to self-register their own accounts, and setup new repos which they then have write access to. Meaning that in practice, any unauthenticated attacker without write access can simply grant themself those permissions, and exploit away.

“The impact of this depends entirely on the motivations of the attackers. We’re seeing reports of this exploit being used for crypto mining. It’s common for low effort attacks to utilize RCE exploits to simply mine a bit of crypto. This wastes organizational resources, but only minimally interferes with normal operations, and cleanup tends to be straight forward. Higher impact attackers could perform more disruptive attacks, such as ransomware. Especially now that this is getting attention for how easy this one is to exploit. Same exploit, different monetization strategies.

“As always, patch your systems, people!”

Patching your systems should be the first thing that you do as 9.8 out of 10 isn’t good from a security standpoint.

The CISA orders federal agencies to patch actively exploited Oracle flaw by August 27

Posted in Commentary with tags on August 25, 2026 by itnerd

The CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.

The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.

Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.

CISA has ordered federal agencies to address the vulnerability by August 27.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs Had This To Say:

   “CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.

   “In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.

   “BOD 26-04’s 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA’s August 24 KEV addition produced an August 27 federal remediation deadline, while CISA’s obligation is to update the catalog “as quickly as possible,” with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA’s own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.

   “Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”

This of course means update all the things ASAP. But we’re getting to a point where patching anything is a losing battle. Thus we need to think of something new when this avenue exhausts itself.

UPDATE: Also Commenting on this is Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth

“The thousands of organizations relying on Oracle WebLogic to provide secure access to their applications are at risk of data loss, manipulation, and exfiltration. The unauthenticated access allows an attacker to make application calls to read data, as well as insert their own unauthorized changes. This issue affects any server accessible to an attacker, which is extremely problematic for many internet exposed applications.”

The CISA warns Medusa ransomware has hit over 500 critical infrastructure organizations  

Posted in Commentary with tags on August 19, 2026 by itnerd

The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech: 

“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.

To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”

The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:

   “It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.

   “The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.

   “Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.

   “Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.

   “While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.

   “Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.

   “Critical Takeaways

  • Hygiene failure: Medusa primarily weaponizes well-known, patchable vulnerabilities on Internet-facing systems rather than relying strictly on complex zero-days.
  • Administrative accountability: Lacking a dedicated security operations team does not absolve internal or third-party sysadmins from performing fundamental software maintenance.
  • Extortion escalation: Threat actors are increasingly turning to multi-stage extortion and re-extorting victims who pay, making immutable off-grid backups essential.

   “Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs. 

   “Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats. 

   “The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”

Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

Posted in Commentary with tags , , on August 11, 2026 by itnerd

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

UPDATE: Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this comment: 

“Gunra made multi-factor authentication (MFA) lie for them. In the South Korean case, the group modified virtual desktop infrastructure (VDI) authentication files to accept a hardcoded attacker-chosen one-time password, and every subsequent login looked legitimate to monitoring tools. Most organizations treat MFA as the last line of defense. Gunra treated it as the first thing to subvert.

“The sector targeting is economic. Healthcare, financial services, and government can’t tolerate downtime or survive a data leak. Encrypting their systems while threatening to publish stolen records hits both pressure points at once.

“CVE-2024-55591 and CVE-2025-24472, the two Fortinet authentication bypasses that got them initial access, are eighteen months old and have been exploited by multiple ransomware groups. Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.

“The advisory also flags a recoverable flaw in Gunra’s Linux encryptor. The variant seeds its ChaCha20 keys with time() instead of a secure random number generator, so defenders who preserve file timestamps can reconstruct keys without paying. Any organization hit by the Linux variant should get forensics involved before wiring cryptocurrency.

“Gunra created a “forticloud-sync” account with super user privileges and a hardcoded password on compromised Fortinet firewalls. That account survives a firmware update, and so do modified VDI authentication files. An organization that patches and stops there is giving Gunra a head start on round two.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The goal of targeting critical infrastructure is really twofold. With nation-state attacks, the objective can be straightforward. You want to create pain for your adversary. But with ransomware groups, I think there are two things we need to understand.

“First, critical infrastructure has become a dinner bell. Ransomware groups have seen how exposed and neglected some of this infrastructure is in countries like the United States, and now they’re swarming toward it because they recognize the opportunity.

“The second factor is pain. There’s been a major push in the security industry for organizations to refuse ransomware payments. But that position becomes much more complicated when an attack against critical infrastructure potentially impacts hundreds of thousands or even millions of people. It’s one thing to say you won’t pay the bad guys when the impact is contained to your organization. It’s another thing entirely when water, power, healthcare, or essential municipal services are disrupted. At that point, refusing to pay may sound principled, but elected officials also have to answer to the people whose lives are being disrupted. That creates enormous pressure to restore those services as quickly as possible.”

The CISA issues guidance to isolate critical systems during cyberattacks

Posted in Commentary with tags on July 29, 2026 by itnerd

The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.

The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.

The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.

The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.

“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.

“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.

“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”

Seemant Sehgal, Founder & CEO, BreachLock:

“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.

“That leaves every CISO with one unavoidable question. What are your compensating controls?

That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”

Dahvid Schloss, Chief Operating Officer, Suzu Labs:

“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement.  There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.

“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.

“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion.  Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”

Matt Wyckhouse. Founder & CEO, Finite State:

“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.

“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”

Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.

What the Oracle vulnerability says about today’s patching problem

Posted in Commentary with tags , on July 17, 2026 by itnerd

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite (EBS) financial application. The directive to repeat states that as mandated by Binding Operational Directive (BOD) 26-04, this needs to be patched by tomorrow. AKA Saturday.

Ted Miracco, Approov (https://www.linkedin.com/in/tedmiracco)

“Organizations continue to struggle to patch critical vulnerabilities quickly because enterprise resource planning (ERP) platforms like Oracle and SAP are highly customized and deeply interwoven with other business applications. Patching them isn’t like updating a web browser; a single database update can break custom API integrations, halting payroll, shipping, or manufacturing.

“The window for ‘safe testing’ no longer exists for edge-facing systems. In the past, organizations had 30 to 90 days to test and deploy patches before exploits were widely weaponized. Today, threat actors reverse-engineer patches and deploy exploits within days or even hours.

“To better prioritize and respond to these types of threats, security teams must implement strict Web Application Firewall (WAF) rules, sever internet exposure, or place vulnerable assets behind a Zero Trust Network Access (ZTNA) gateway until patches can be safely tested. When patches can be deployed to a staging environment, tested automatically, and instantly rolled back if they fail, emergency deployments become a low-risk routine rather than a weekend crisis.”

Damon Small, Board Member, Xcape, Inc. (https://www.linkedin.com/in/damon-small-7400501)

“Deploying a patch on a single computer may seem like a trivial task, but doing it across an enterprise that may have hundreds, or even thousands, of servers is daunting.  That said, we have seen incidents where a patched vulnerability is exploited months after it was resolved.  As an industry, we must strike a balance between operational readiness and patching fatigue.

The first open source vulnerability scanner was released in 1995.  Since then, vulnerability management has remained the least sexy, yet the most important, directive in cyber security.  Frankly, as an industry, we struggle to update software quickly, and this fact will become more problematic as the time between vulnerabilities being discovered and them being actively exploited continues to shrink.

Security leaders should first and foremost ensure that their organizations have accurate software and hardware inventories. You cannot defend what you can’t see. Additionally, as ‘silent’ or no-reboot patching becomes an industry standard, automatic updates may follow.”

Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)

“Organizations rarely fail to patch because they lack another alert: they struggle when they lack reliable asset inventories, clear ownership, tested maintenance paths, or the authority to interrupt business-critical systems and processes. In today’s machine-scale, machine-speed adversarial environment, IT organizations must deploy critical security patches far more quickly.  When immediate patching is not possible, leaders must prioritize vulnerabilities based on active exploitation, internet exposure, mission impact and potential blast radius, not severity scores alone.  They should know in advance who owns each critical system, how it can be isolated, and how emergency changes can be made safely.  

“Patching is not the finish line: organizations must determine whether an adversary arrived before the fix was applied. Find material exposure before an adversary does, fix it, and prove the risk actually went down.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“Patching is rarely as simple as installing an update. Critical enterprise applications are often deeply connected to financial systems, databases, customized workflows, and third-party software, so teams fear that an untested patch could interrupt essential operations. 

“The deeper problem is that many organizations do not have an accurate, continuously updated inventory of their systems. They may not know which servers are exposed to the internet, which versions are running, who owns them, or whether a patch was successfully applied.

“In this case, Oracle released the patch in May, exploitation was observed by late June, and more than 1,000 Oracle E Business Suite systems were still exposed to the internet in July. That is not primarily a technology failure. It is a failure of ownership, visibility, testing capacity, and executive accountability.

“Urgent federal patching orders and extremely short remediation deadlines are becoming more visible, but this particular action was not technically a standalone Emergency Directive. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog under Binding Operational Directive 26 04 and required remediation within three days.

“The significance is the deadline. CISA is effectively telling agencies that once exploitation is confirmed, the traditional patching cycle is no longer acceptable. Attackers are weaponizing vulnerabilities faster, while many organizations are still operating through monthly maintenance windows, lengthy approval processes, and manual asset reviews.

“These directives also reveal an uncomfortable truth: too many organizations still need an external government deadline to force action on vulnerabilities that vendors have already patched.

“Security leaders should prioritize vulnerabilities based on actual exploitation, internet exposure, business importance, and the potential impact of compromise, not simply on the severity score. A vulnerability that is being actively exploited against an exposed financial system should move immediately ahead of a higher scoring flaw on an isolated test machine.

“Every critical system needs a named business owner, a technical owner, a tested emergency patching procedure, and a clearly defined authority capable of accepting the operational risk of patching or the security risk of delaying it. When exploitation is confirmed, teams should be able to patch, isolate, restrict network access, or temporarily remove a system from service without waiting through days of meetings.

“Organizations should also assume that patching may come too late. Organizations must review logs for evidence of earlier exploitation, rotate potentially exposed credentials, inspect connected systems, and protect privileged access with hardware based biometric assured identity.

“Biometric assured identity would not prevent an unauthenticated Oracle software exploit such as this one. It can, however, stop attackers from turning stolen administrator credentials into broader access after the initial compromise. Patching closes the software vulnerability. Biometric assured identity helps contain what attackers can do next.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Patching is a big thankless task, and it rarely gets the resourcing it would require to actually patch all the things quickly. In order to have any chance at keeping up with patching, organizations need to implement solutions to automate both patching and vulnerability scanning.

“A lot of organizations are hesitant to patch immediately, because there have been enough issues with bad patches being released over the years, that the risk of patching slowly is preferred over the risk of patching fast and breaking things.

“Patching automation is great for those systems which are consistently deployed across the organization. However, the applications that are only on a few systems are those least likely to have automated patching. This would be fine, except for that there tends to be a lot of applications that fall into this category. Practically, that means staff can patch the vast majority of things consistently and in a timely manner, and still always have a long tail of vulnerabilities that are more challenging to fix.

“This is compounded when ownership is split between different teams. Especially so when organizational priorities are split. If teams are under pressure to hit tight deadlines, the last thing they want to do is spend time fixing/patching things that don’t directly assist in that goal. This results in a lot of vulnerability management teams spending much of their time providing reports on what needs patching, to teams that will get to it when they get to it.

“As for what leadership can do to better prioritize and respond to new vulnerabilities? A big part of is keeping metrics so that the work being done isn’t invisible anymore. If the team is consistently patching 90% of all published CVEs in a timely manner, and yet all that leadership sees are reports showing the remaining 10%, it can look like the team just isn’t doing much patching when the opposite is true.

“Track stale vulnerabilities in the organization, and prioritize those. Stale can be older than 30, 90, or 365 days for example. Depending on how mature existing processes are. Once all of the stale vulnerabilities are remediated, build automation to handle as much repeatable work as is possible. Provide developers with vulnerability feedback as early in the process as you can, as it costs much less time and money to fix code early on, than it does after release.”

While it is beyond time to patch all the things, organizations need rethink how they go about keeping their environments safe. Because patching is clearly not enough.

CISA to shift vulnerability program toward risk-based prioritization

Posted in Commentary with tags on June 10, 2026 by itnerd

The CISA’s Acting Director Nick Andersen announced Tuesday plans to overhaul how the agency evaluates and prioritizes software vulnerabilities, moving beyond severity scores alone to focus more heavily on real-world risk and operational impact. The agency said the changes are intended to help organizations better prioritize remediation efforts as the volume of disclosed vulnerabilities continues to grow.

Under the new approach, CISA plans to place greater emphasis on factors such as active exploitation, asset criticality, attack complexity, and the potential consequences of a successful attack. Agency officials said the goal is to help defenders focus resources on vulnerabilities that pose the greatest operational risk rather than relying solely on CVSS scores or the total number of disclosed flaws.

The initiative follows broader efforts by CISA to improve vulnerability management programs, including opening nominations for its KEV Catalog and expanding collaboration with security researchers and vendors. Officials said the updated framework is intended to provide organizations with more actionable guidance for addressing the vulnerabilities most likely to affect critical systems and infrastructure.

Denis Calderone, CTO, Suzu Labs:

   “A risk-based approach to vulnerability management makes a lot of sense to us, and how we approach vulnerability management with our own clients. CVSS alone has never been a reliable way to decide which vulnerabilities to prioritize. Just in the last two weeks we’ve seen a Palo Alto GlobalProtect vulnerability rated 7.8 that was operationally critical, a SolarWinds Serv-U DoS at 7.5 against a product with a documented history of nation-state and ransomware targeting, and a Check Point zero-day where CISA’s own three-day remediation deadline told a completely different story than the score. So, the policy direction here is right. Where we get skeptical is the execution. Risk-based prioritization is significantly harder than “patch everything as fast as you can.” It requires understanding what assets you have, what functions they support, how they’re exposed, and what the real-world consequences of compromise look like. Who is going to ensure that each entity is actually performing effective risk-based assessments and not just checking a compliance box?

   “That question gets harder to answer when you look at the resource picture. CISA has faced roughly half a billion dollars in proposed budget cuts and lost about a third of its workforce. Andersen is describing an approach where CISA engages directly with critical infrastructure entities to identify specific critical functions and the assets that support them. That kind of hands-on, entity-by-entity engagement requires more analytical capacity, not less. The 329 new hires are a good step forward and show the agency is serious about rebuilding operational capability, but risk-based prioritization at the scale of the federal government and critical infrastructure sectors is an enormous undertaking even for a fully staffed agency.

   “The other thing we’d like to see this framework to address is chainability. CVSS scores vulnerabilities in isolation and doesn’t model scenarios where an attacker combines a medium-severity information disclosure with a medium-severity privilege escalation and ends up with critical impact. Neither bug scores as urgent on its own, but together they give you full system compromise. If the goal is to prioritize based on real-world risk, the methodology has to account for how vulnerabilities interact in actual attack chains, not just how they score individually. 

   “Organizations shouldn’t wait for this directive to be fully operationalized. Start building your own prioritization stack now: KEV status, EPSS exploitation probability, and your own environmental context. That combination has been more reliable than CVSS alone for a while now.”

Ryan McCurdy, VP of Marketing, Liquibase:
 

   “CISA’s shift is the right move because severity scores alone do not tell defenders what actually puts the business at risk. A vulnerability on a low-impact system is very different from one affecting a production database, deployment pipeline, or system tied to customer data and critical operations.

   “The next step is connecting vulnerability prioritization to proof of control. Security teams need to know not only which issues are being exploited, but where they sit, what they can impact, who remediated them, and whether the fix moved through a controlled change process. Otherwise, teams can patch one risk while introducing another through rushed, manual, or poorly governed changes.”

Doc McConnell, Head of Policy and Compliance, Finite State:

   “The pace of vulnerability identification is accelerating thanks to AI, and the volume is outpacing response even for well-resourced teams. It makes sense that the federal government is moving from blanket timelines to more individualized, risk-based prioritization.

   “But this approach demands more sophistication from cyber defenders. In order to make an effective risk-based assessment, they need to understand what they’re protecting. For example, device manufacturers need a deep understanding of their own firmware, including third-party components, to know whether a new vulnerability is present and exploitable in their product.

   “Organizations need to ask themselves: do they have the context they need to make informed prioritization decisions about new vulnerabilities? If not, building that context has to be priority number one.”

Damon Small, Board of Directors, Xcape, Inc.:

   “The Cybersecurity and Infrastructure Security Agency (CISA) is shifting the federal vulnerability baseline from predictable, severity-based scoring to a risk-centric paradigm. While moving beyond Common Vulnerability Scoring System (CVSS) numbers helps manage patch fatigue, calculating real-world operational risk requires localized context that most organizations struggle to automate. This subjective approach demands greater effort from analysts to extract local context, but it shifts the metric from superficial scorekeeping to actionable, risk-aligned defense.

   “Security teams must integrate localized threat intelligence with strict asset discovery to ensure asset criticality tags match actual business functions. Chief Information Security Officers (CISOs) should audit their pipelines immediately to ingest CISA’s expanded Vulnrichment telemetry, prioritizing active exploitation data over static metrics to justify mitigation exceptions to auditors and business units.

   “Critical Takeaways

  •    “Context Over Score: Severity scores are officially deprecated as standalone metrics, forcing security leaders to justify patching decisions based on active exploitation and asset criticality.
  •    “Telemetry Upgrade Required: Security teams must immediately update vulnerability management pipelines to ingest and process CISA’s expanded context data, rather than relying on traditional automated scanner outputs.
  •    “Audit Local Asset Context: CISOs need to establish strict, defensible asset discovery and business-criticality tagging, as automated risk prioritizations are useless without precise local context.

   “It turns out that counting to ten over and over was a terrible way to run a security program, even if it did look nice on an executive dashboard.”

Sunil Gottumukkala, CEO, Averlon:

   “Glad to see CISA’s acting director focusing on real-world risk, this shift is overdue. Knowing a vulnerability is exploited in the wild, which the KEV catalog already delivers, answers only half the question. The other half is whether it matters in your environment. Do the specific conditions the exploit depends on, a particular configuration, an exposed or reachable service, actually exist in your fleet. 

   “This directive pushes agencies to answer that second half. Doing it well requires two things: knowing what assets you have and how they are deployed and configured, and understanding how a given CVE is being exploited to assess its real impact on your environment.”

My advice is to take risk and operational impact and make those operational now. Then tweak things based on what is finalized. That way there is forward movement in term of making environments safer for all.