CISA updates cybersecurity performance goals with governance component
CISA released CPG 2.0, adding a governance component and measurable actions for IT and OT to reach a foundational cybersecurity level.
Decision Insights Threat Desk • December 11, 2025
CISA released CPG 2.0, adding a governance component and measurable actions for IT and OT to reach a foundational cybersecurity level.
Decision Insights Threat Desk • December 11, 2025
CISA issued 12 ICS advisories covering products from Johnson Controls, Siemens, AzeoTech, OpenPLC_V3, GDCM, and Varex Imaging.
Decision Insights Threat Desk • December 11, 2025
CISA added CVE-2025-58360, an OSGeo GeoServer XML external entity vulnerability, to the Known Exploited Vulnerabilities Catalog.
Decision Insights Threat Desk • December 9, 2025
CISA and partners report pro-Russia hacktivists exploit internet-facing VNC to access OT control devices and cause physical damage.
Decision Insights Threat Desk • December 9, 2025
CISA added CVE-2025-6218 and CVE-2025-62221 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.
Decision Insights Threat Desk • December 9, 2025
CISA details PCIe IDE specification flaws that can allow local actors to cause receivers to accept stale or corrupted data.