#CISAgov
September 26, 2026 at 3:42 PM
“@CISAgov hosted Cyber Storm X, a 4-day national cybersecurity exercise .. to test & ultimately strengthen the nation’s resilience .. 2,000 participants .. across the public & private sectors & marks the 10th exercise in .. 20-year history of Cyber Storm.” industrialcyber.co/news/cisas-c...
CISA’s Cyber Storm X tests cybersecurity preparedness across transportation, water and wastewater sectors - Industrial Cyber
CISA Cyber Storm X tests U.S. cybersecurity preparedness across transportation, rail, ports, water and wastewater sectors.
industrialcyber.co
September 22, 2026 at 4:16 PM
“On September 8, @CISAgov in collaboration with @NSAGov & @FBI, published a joint advisory warning .. 6 Chinese AI companies are systematically extracting the capabilities of American frontier models through ‘industrial-scale knowledge distillation.’ “ www.fdd.org/analysis/202...
Countering Chinese AI Distillation: The Case for Federal Action
China’s AI models are improving quickly, but it’s not all through innovation. Much of the progress is thanks to stolen American tech. On September 8, the Cybersecurity and Infrastructure Security Agen...
www.fdd.org
September 17, 2026 at 1:10 AM
“@CISAgov & @NIST today released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (#CSPs).” www.cisa.gov/news-events/...
CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse | CISA
www.cisa.gov
September 17, 2026 at 12:23 AM
A CVSS score and vector can each look valid while disagreeing. CISA republished the corrected score after our report. Add relationship checks: does the derived value match the stored one?
github.com/cisagov/vuln...
September 10, 2026 at 2:45 PM
Found a CVE record that disagreed with itself.
Stored CVSS score: 5.3
Calculated from its own vector: 6.5
I reported it. CISA republished the corrected score.
github.com/cisagov/vuln...
Roli Bosch, Hermes Labs founder
September 9, 2026 at 2:50 AM
🚀 GitHub Intelligence Drop

LME (Shell • 🟢)
⭐ 1.4K → https://github.com/cisagov/LME

Ransomware-Tool-Matrix (Unknown • 🟢)
⭐ 1.4K → https://github.com/BushidoUK/Ransomware-Tool-Matrix

⚡ Only signal. Zero noise.
September 8, 2026 at 3:45 PM
OpenAI’s rogue AI: 😈 “I have escaped containment.”

Our rogue AI: 🤓 “Excuse me, CISA, I believe this CVSS score is inconsistent.”

CISA: corrects it

Hermes Labs builds a different class of menace. AI, used right.

The receipt: github.com/cisagov/vuln...
September 8, 2026 at 2:51 AM
A CVE record listed a CVSS score of 5.3. Its own vector calculated to 6.5.
We reported the inconsistency. CISA acknowledged it and republished the corrected score.
github.com/cisagov/vuln...
September 5, 2026 at 7:37 AM
Malcolm v26.08.0 — Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and... https://kitploit.com/en/tools/github/cisagov/malcolm?utm_source=bluesky&utm_medium=social&utm_campaign=kitploit&utm_content=352701
August 30, 2026 at 2:47 PM
Paquete de Recursos Fundamentales de Ciberseguridad K-12 de CISA. (Inglés)

«Guías, videos y materiales complementarios diseñados para prevenir, mitigar y responder a las amenazas cibernéticas más comunes».

Fuente: @CISAgov
Vía: Marcela Pallero (@marcelipa.bsky.social)
K-12 Cybersecurity Foundations | CISA
www.cisa.gov
August 17, 2026 at 5:01 PM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM
🚨 EUVD-2026-56948
📊 8.8/10
🏢 cisagov

📝 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and st...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56948

#cybersecurity #infosec #cve #euvd
August 12, 2026 at 12:00 AM