← BACK TO FEED
TAG

cisa3 articles

CISA Confirms Active Exploitation of Critical FortiSandbox Bugs — Patch Now or Pull the Plug

CISA has added two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089), both scoring 9.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The OS command injection flaws allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests, with fixes already released by Fortinet in April and June. CISA also flagged a critical Microsoft SharePoint Server deserialization flaw (CVE-2026-58644, CVSS 9.8), which enables authenticated attackers with Site Owner privileges to remotely execute arbitrary code.

18 Jul 2026

CISA Is Quietly Using Anthropic's Mythos to Hunt Bugs in Federal Government Code

CISA is reportedly using Anthropic's AI model, Mythos, to scan federal government code repositories for security vulnerabilities, with sources indicating the effort has already uncovered a large number of software flaws. The initiative is led by CISA's Attack Surface Evaluation team, with the NSA also believed to be utilizing the model. Despite this growing government reliance on Mythos, Anthropic has faced political tensions with the administration over its refusal to remove safeguards against autonomous weapons and surveillance use, and its public-facing model, Fable, experienced a temporary global shutdown following a dispute over foreign access.

13 Jul 2026

CISA Left Its Passwords in a Public GitHub Repo Called 'Private-CISA'

CISA, the US cybersecurity agency, had a trove of sensitive credentials — including plaintext passwords, SSH private keys, and tokens — exposed in a public GitHub repository called "Private-CISA" since at least November 2025, with GitHub's default secret-protection features deliberately disabled. Security testing confirmed the leaked credentials provided high-privilege access to multiple AWS GovCloud accounts, and the repo appears to have been managed by CISA contractor Nightwing. The incident marks yet another security embarrassment for CISA, following a separate January 2026 incident in which the acting director uploaded sensitive government documents to ChatGPT.

20 May 2026