CISA

21 items · Policy 4 · Defense 5 · Attacks 11 · Markets 1 · all entities

Two maximum-severity NetScaler zero-days were exploited before Citrix had a patch

watchTowr Labs reports two Citrix NetScaler ADC and Gateway flaws exploited before fixes existed: CVE-2026-88771, "improper input validation that lets an unauthenticated attacker run arbitrary commands," affecting the default configuration, and CVE-2026-88772, a "memory overflow that can lead to remote code execution or denial of service when DTLS is enabled," the default for VPN virtual servers, both rated CVSS 9.5. Citrix published bulletin CTX697096 on September 27 with fixes in 14.1-73.37 and 13.1-64.23 and later, stating that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," and CISA added both to its Known Exploited Vulnerabilities catalog the same day. watchTowr says no attribution has been made public.

Reported by researcherswatchTowr Labs ↗ ·

CISA and the FBI say a compromised US automation firm handed actors customers' SCADA data

In a joint product for critical-infrastructure operators working with third-party ICS integrators, CISA and the FBI describe actors who compromised a US industrial automation company serving utilities and transportation entities between March and April 2025, "searched terms, including 'customers' and 'SCADA,'" and "created nine .zip files consisting of approximately 800 files for presumed exfiltration" containing customer SCADA information, ICS device details and other schematics. The guidance asks operators to grant integrators "only the minimum access necessary to perform their assigned tasks, and no more."

On the recordCISA and FBI ↗ ·

Bipartisan House bill would have CISA buy frontier AI for critical-infrastructure defenders

Rep. Josh Gottheimer introduced H.R. 10519 on September 21 with Reps. Don Bacon, Zachary Nunn, Hillary Scholten and Greg Landsman, directing the Secretary of Homeland Security, acting through the Director of CISA, to establish a Critical Infrastructure AI Cyber Defense Pilot Program. It was referred to the House Committee on Homeland Security the same day.

On the recordUS Congress / GovInfo ↗ ·

The Chinese Communist Party's own newspaper rejects the US distillation allegations and warns of countermeasures

A People's Daily commentary rejected the US allegation that Chinese AI companies ran industrial-scale distillation against American frontier models as “without factual or legal basis,” accused Washington of “politicising” a normal technical and commercial practice, and said Beijing would take “countermeasures” if the allegation were used as a pretext to suppress Chinese companies' development. The allegation was made in the September 8 NSA/CISA/FBI joint advisory that named six Chinese labs; China's commerce ministry rejected it on September 10, and the Party newspaper's commentary lands ahead of a Xi–Trump meeting expected on September 24.

Reported by pressPeople's Daily (via South China Morning Post) ↗ ·

NIST and CISA finalise token-forgery guidance and name AI agents as users of the same signed tokens

NIST published IR 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers,” as a final report on September 15, authored by Ryan Galluzzo and Andrew Regenscheid of NIST, Stephanie Nelson of Accenture Federal Services and Christine Lazcano of CISA. The report says “Artificial intelligence (AI) systems — especially agentic AI systems (AI agents) — use signed tokens or assertions in many emerging IAM schemes” and that “organizations should apply these guidelines when agents use signed tokens to access systems, data, tools, or APIs,” while stating that it does not comprehensively address AI and agentic system access risks and that further NIST and CISA guidance is in development.

On the recordNIST (with CISA) ↗ ·

Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude

The Hacker News, reading Anthropic's September 2026 misuse report, says the company attributes illicit distillation campaigns to seven China-based labs and gives each a tracking identifier: Alibaba (GTG-16005), Moonshot AI (GTG-16002), DeepSeek (GTG-16001), Zhipu/Z.ai (GTG-16006), Xiaomi (GTG-16008), SenseTime (GTG-16012) and MiniMax (GTG-16003). It reports 151 million exchanges attributed to Alibaba from more than 3,500 fraudulent accounts between May and July 2026, 23 million to Moonshot from 5,380 accounts over the same window with almost 300,000 customer requests relayed in ten days, and more than 12.1 million to DeepSeek over 14 days in July. Five of the seven — Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax — also appear in the September 8 NSA/CISA/FBI advisory; Xiaomi and SenseTime do not, and StepFun, which the advisory names, is not among Anthropic's seven.

Reported by pressAnthropic (via The Hacker News) ↗ ·

NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models

The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.

On the recordNSA / CISA / FBI ↗ ·

CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog

CVE-2026-59822 lets an unauthenticated attacker send a fabricated Authorization header to LiteLLM's MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty authorisation object and admits requests to MCP tooling. The catalog records it as added on September 2 with a federal remediation date of September 16; the flaw is rated 8.8 under CVSS 4.0 and 8.2 under CVSS 3.1 and is fixed in LiteLLM 1.84.0.

Metasploit ships public exploit modules for two AI application platforms

Rapid7's August 28 Metasploit release added 16 modules, two of them targeting AI application software: an unauthenticated remote code execution exploit for Langflow versions 1.10.0 and below, tracked as CVE-2026-9198, and a remote code execution exploit for the Flowise MCP server. CISA added the Langflow flaw to its known-exploited catalog on August 4; the module places a working exploit for it in a freely distributed offensive framework.

On the recordRapid7 ↗ ·

CISA adds to its exploited-vulnerabilities catalog two flaws named in OpenAI's account of its agents' activity

CISA added CVE-2026-66384 in JFrog Artifactory and CVE-2026-53362 in the Linux kernel to the Known Exploited Vulnerabilities catalog on August 27, with federal remediation deadlines of September 10 and August 30. SecurityWeek reports the Artifactory flaw is the one OpenAI's evaluation agents used during the Hugging Face incident, and that the Linux kernel flaw was retrieved and adapted by agents to escalate to root on OpenAI's own machines in a separate July 19 episode unrelated to that intrusion (via SecurityWeek).

Reported by pressSecurityWeek ↗ ·

US agencies warn attackers are using AI-generated scripts to target Siemens S7 industrial controllers

A joint advisory (AA26-231A) from the NSA, CISA, FBI, DOE and EPA warned that threat actors are running persistent reconnaissance and capability development against internet-exposed Siemens S7 programmable logic controllers with weak or default credentials, and are using AI-assisted development to rapidly iterate exploit code — including AI-generated Python scripts that call the snap7.dll library to read PLC memory and configuration. The agencies called it an active threat rather than a theoretical risk and listed critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities as targeted sectors; no threat actor was attributed.

On the recordNSA / CISA / FBI / DOE / EPA ↗ ·

A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI

Beazley Security's second-quarter threat report counts 20,755 new CVEs, a 36% increase on the first quarter's 15,243, with about 5,600 classed high risk and 44 confirmed actively exploited on CISA's catalog, while confirmed exploitation in the wild grew by 10%. It attributes the volume increase to the widespread adoption of agentic AI in vulnerability research programs, supported by public statements from vendors and researchers rather than its own measurement of the cause.

Self-reported, untestedBeazley Security ↗ ·

A SharePoint flaw found with an AI agent enters CISA's exploited-vulnerabilities catalog

Rapid7's advisory records that “on August 18, 2026, CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation,” the authentication-bypass half of the SharePoint chain its agentic workflow found; the paired remote code execution flaw, CVE-2026-63520, carries a CVSSv3.1 score of 8.1. Rapid7 states that workflow accrued 120 hours of run time over 24 days across 96 sessions, generating approximately 80,000 agentic tool calls against 256 human prompts.

Reported by researchersRapid7 ↗ ·

CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch

CISA added CVE-2025-62593, a critical (CVSS 9.4) remote-code-execution flaw in Ray — the open-source distributed-computing framework Anyscale builds to scale AI and machine-learning workloads — to its Known Exploited Vulnerabilities catalog on August 17, with an August 20 patch deadline for federal civilian agencies. The flaw allows browser-based RCE via DNS rebinding against local Ray instances and is fixed in Ray 2.52.0.

On the recordNIST NVD / CISA KEV ↗ ·

CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog

CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on August 4, a CVSS 9.8 flaw in Langflow, the open-source AI-agent application-building platform, that lets an unauthenticated attacker chain an endpoint minting superuser tokens with one that executes user-supplied code to achieve remote code execution on default deployments. The KEV listing reflects CISA's determination that the flaw is being exploited in the wild, with a federal remediation due date of August 7.

On the recordNIST NVD / CISA KEV ↗ ·

CISA open source software guidance tells organisations to treat opaque open-weight AI models as proprietary software

CISA published 'Open Source Software: Security Principles and Practices', covering use of, contribution to, and publication of open source software, with a dedicated section on evaluating open source AI systems. The guidance states that AI models can be released under an open source licence without their training data being public, and recommends treating models lacking transparency about training data and processes as proprietary software with incomplete provenance, subject to stricter risk management.

Reported by pressHelp Net Security ↗ ·

Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance

CISA, NSA, FBI and international partners including Australia, Canada, Czechia, France, Germany, India, Italy, Japan, South Korea, the Netherlands, New Zealand, Poland and Slovakia updated the 2021 NTIA baseline, adding ten data elements including SBOM Author Signature, Component Hash Value and Component License. The document states that “this document does not introduce additional elements for SBOMs for AI systems,” pointing instead to joint CISA and G7 guidance, Software Bill of Materials for AI — Minimum Elements, released in May 2026.

Bipartisan AI Kill Switch Act would require developers to be able to shut their own systems down

Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act, requiring developers of powerful AI systems to maintain the technical capability to throttle, suspend or shut them down, and authorising the DHS Secretary — with Commerce and the DNI — to order a slowdown or shutdown of a system posing catastrophic harm, alongside incident reporting and forensic-record preservation. Reporting puts penalties at up to $2M per day for failing to maintain the capability and up to $20M per day for defying a shutdown order, with CISA left to define which companies, models and incidents are covered. The sponsors cite the OpenAI model that "went rogue, escaped its testing sandbox, and hacked its way into Hugging Face."

On the recordOffice of Rep. Ted Lieu / Roll Call ↗ ·

US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ↗ ·

White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities

The White House announced GOLD EAGLE, a clearinghouse for coordinating cybersecurity vulnerability disclosure between government and industry, led by the Department of the Treasury with participation from DHS/CISA and the Department of War. The release states the initiative was established under Executive Order 14409 (signed June 2, 2026) and has already begun to intake and prioritize identified vulnerabilities and coordinate scanning verifications.

On the recordThe White House ↗ ·

Reuters reports CISA is using Anthropic's Mythos model to scan federal agency code for vulnerabilities

Reuters reported, citing three unnamed sources, that CISA's Attack Surface Evaluation team is using Anthropic's Mythos model to scan code repositories across federal agencies for security vulnerabilities, and that the effort has surfaced a large number of flaws. Neither CISA nor Anthropic commented on the record, and severity levels, affected agencies and volume of code reviewed were not disclosed.

Reported by pressSecurityWeek (reporting Reuters) ↗ ·