Showing posts with label CISA. Show all posts
Showing posts with label CISA. Show all posts

Saturday, September 19, 2026

CISA Announces VINCE-NT

Earlier this week CISA announced their upgraded coordinated vulnerability disclosure platform, VINCE-NT. This new platform will replace the VINCE CVD hosted by Carnegie Mellon University’s Software Engineering Institute; which was primarily focused on vulnerabilities in industrial control systems. The old VINCE site reports that “after November 17, 2026, all CISA vulnerability reports must be submitted through VINCE-NT. 

According to CISA’s CVD landing page the new VINCE-NT program is designed to expand the CISA CVD program to include: 

  • Operational technology (OT) and industrial control systems (ICS),  
  • Internet of things (IoT) devices,    
  • Medical devices,  
  • Open source software,  
  • Artificial intelligence (AI), and 
  • IT systems.  

The new VINCE-NT data collection form is hosted on a CISA.gov web page. As such it is required to provide a reference to the OMB Control Number for that information collection to show that it has been appropriately reported to, and reviewed by, OMB’s Office of Information and Regulatory Affairs (OIRA) to ensure that it conforms to the requirements of the Paperwork Reduction Act (PRA). This new VINCE-NT data collection page does not provide an OMB Control Number. Back in February, OIRA did approve a new ICR for a “CISA Coordinated Vulnerability Disclosure (CVD) Platform” with an OMB Control Number of 1670-0058. 

Friday, September 11, 2026

CISA Adds 2 MikroTik Vulnerabilities to KEV Catalog – 9-10-26

Yesterday, CISA announced that it was adding two vulnerabilities in the MikroTik OS to their Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: 

MikroTik reported both vulnerabilities on September 3rd, 2026. The two vulnerabilities were among six initially reported by SÅ‚awomir Rozbicki from CERT Polska, with fixed versions available. CERT Polska subsequently reported active exploitation in the wild on September 5th, citing proof-of-concept code developed by Nick Pratley using version diff analysis. 

Based upon the CERT Polska reports the following vulnerabilities may also end up being added to the KEV catalog: 

  • Improper verification of cryptographic signature - CVE-2026-67276, CVE-2026-67278,  
  • Improper enforcement of behavioral workflow - CVE-2026-67279, and 
  • Path traversal - CVE-2026-67281 

CISA has directed federal agencies using the affected products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

CISA has established a compliance date of September 13th, 2026. 

Thursday, September 10, 2026

CISA Adds FortiGuard Vulnerability to KEV Catalog – 9-9-26

Yesterday, CISA announced that it had added a heap-based buffer overflow vulnerability in the FortiGuard FortiOS and FortiSwitchManager products to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard published their advisory on the vulnerability in January 2026, and most recently updated it in February. Fixed versions are available. 

On Tuesday, SOCRadar published an article detailing their discovery of the “PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool.” They report seeing evidence of exploits in the wild as far back as July of this year. The article provides a detailed technical analysis of the fortirun.bin component of PivotC2 as well as indicators of compromise. 

CISA has directed federal agencies using the affected FortiGuard products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance deadline of September 12th, 2026 has been established. 

Tuesday, September 8, 2026

GAO Publishes Report on Chemical Plant Personnel Screening

Today, the Government Accountability Office (GAO) announced the publication of their report on “Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties”. GAO was asked to evaluate the effects of the end of the CFATS program in 2023 and the decline in CISA chemical security staffing since 2025 on chemical facility security.  

The report noted that (pg 5): 

According to CISA officials and representatives from the private sector coordinating council, the three selected chemical associations, and the six selected chemical companies we interviewed, losing the Personnel Surety Program is the most significant challenge high-risk chemical facility owners and operators have faced following the discontinuation of the CFATS program. CISA officials also stated that discontinuing the Personnel Surety Program left a gap in chemical facility security that poses significant risks. 

The Report made one recommendation (pg 16): 

Identify, evaluate, and implement voluntary options for chemical facility owners and operators to address insider terrorist security risks by vetting their personnel and unescorted visitors with access to restricted areas or critical assets, and, if necessary, seek the legislative authority to do so. 

The official CISA response to the recommendation (pg 16): 

The voluntary collection and handling of sensitive personal information necessary to conduct such vetting would raise significant legal, privacy, compliance, and resource considerations. These considerations include proper collection, use, maintenance, and protection of sensitive personal information necessary to support such activities, as well as requirements associated with safeguarding personal data and providing appropriate redress 

 
/* Use this with templates/template-twocol.html */