Cisa articles

cisa united states firewall vpn state-sponsored attacks routers infrastructure

CISA is ordering US federal agencies to remove outdated routers and firewalls

Obsolete edge gear is now seen as a primary intrusion path for state-backed hackers
TL;DR: When attackers probe government systems, they often begin not with stolen credentials or phishing emails but with aging routers and firewalls left running long past their expiration dates. Those neglected edge devices have become a top federal concern, and US agencies are now being told to remove them before attackers take advantage.
cisa signal whatsapp messaging encryption

New CISA alert: encryption isn't what's failing on Signal and WhatsApp

State-backed hackers aren't cracking Signal. They're cracking your phone.
Why it matters: Hackers are bypassing encryption used in messenger apps by compromising the phones and convenience features like QR-based sign-ins. The latest campaign targets high-value targets. The attacks have scraped device data, text messages, and even audio recordings. Their techniques require no user interaction and can remain hidden for years.
worldwide microsoft sharepoint hacking zero day cisa sharepoint servers

Worldwide cyberattack underway as hackers exploit Microsoft SharePoint zero-day vulnerability

CISA has identified the exploit as a top-level security threat, a patch is now out
A hot potato: A newly uncovered security flaw in Microsoft's SharePoint software has sparked a widespread series of cyberattacks targeting government organizations, educational institutions, energy companies, and private enterprises around the globe. This threat has prompted coordinated investigations by authorities in the United States, Canada, and Australia, with cybersecurity experts warning that these intrusions represent one of the most serious server-level breaches seen in recent memory.