ZeroHour

Search: “patch review”

12 stories in the last 30d

CISA review makes the case for eliminating vulnerability classes

CISA's FY2024-2025 vulnerability review urges eliminating recurring vulnerability classes, finding 41.5% of 2025 KEV entries map to persistent 'stubborn weaknesses'.

CISA's Vulnerability Review for fiscal years 2024 and 2025 found most compromises stemmed from opportunistic exploitation of known, exposed vulnerabilities rather than nation-state zero-days or advanced tradecraft. The review found 41.5% of 2025 KEV catalog entries map to 'stubborn weaknesses' - injection flaws, improper input validation, memory-safety failures, path traversal and broken access control - recurring on the CWE Top 25 since 2019. CISA advocates Secure by Design practices, vulnerability class elimination, and buyer-driven 'Secure by Demand' contract requirements, while warning that AI-enabled vulnerability discovery will soon accelerate exploitation.

Help Net Security · 16d agoPolicy & legal

Severity Is Not a Strategy: What CISA BOD 26-04 Means for the Future of Federal Software Security

CISA's BOD 26-04 replaces severity-based federal patching with risk-based remediation deadlines of 3, 14, or 60 days.

CISA's Binding Operational Directive 26-04, released June 10, 2026, replaces BOD 19-02 and BOD 22-01 for Federal Civilian Executive Branch agencies and shifts remediation prioritization from CVSS scores to risk context. Agencies assess four factors: public exposure, KEV listing, exploit automatability, and whether exploitation grants partial or total asset control, resulting in 3-, 14-, or 60-day remediation windows or next-upgrade fixes. In CISA's first review at a large civilian agency, only 1% of vulnerabilities required three-day remediation while over 60% could wait for future system upgrades. The directive also requires forensic analysis when exploitation is suspected, and Checkmarx argues the same risk-based logic must extend upstream into software development and SBOM-driven exposure management.

Checkmarx · 7d agoPolicy & legal

Risky Bulletin: Two TeamPCP members arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members behind supply-chain worm attacks that stole over 500,000 credentials from compromised open-source libraries.

The AFP arrested alleged TeamPCP leader Ruben Thomson, 21, and Louis Gaebler, 23, near Perth; both were charged and remain in custody. The group inserted a self-spreading credential-stealing worm into open-source projects including Trivy, KICS, LiteLLM, and Telnyx, harvesting more than 500,000 credentials used for network access, ransomware, extortion, and sales. About 78,000 tokens and secrets from nearly 2,200 organizations leaked online last month, and the FBI supported the investigation that began in April.

Risky Business News · 20d agoPolicy & legal in the wild1

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

Trump signed an executive order declaring an emergency to bar foreign bulk-power equipment deemed a national security cyber risk.

The executive order, 'Declaring a National Energy Emergency to Secure the United States Bulk-Power System,' prohibits acquiring, importing, transferring, or installing foreign-produced bulk-power equipment and software deemed risky, citing fears of digital backdoors in Chinese-made grid gear. China supplies roughly 85% of solar supply chain capacity and is a major transformer manufacturer. The Energy Department has 120 days to develop implementing rules; the order revives a 2020 Trump-era measure the Biden administration had suspended after utilities found compliance difficult.

CyberScoop · 21d agoPolicy & legal1

Lawmakers seek watchdog review of federal hacking of Americans

Sen. Wyden and Rep. Casar asked the GAO to review the federal government's use of spyware and hacking tools against Americans.

Sen. Ron Wyden and Rep. Greg Casar sent a letter to the Government Accountability Office requesting a review of federal law enforcement hacking operations, including spyware use, Rule 41 hacking powers, and acquisition of hacking tools. The letter cites ICE's confirmed work with spyware vendor Paragon and concerns about abuse of invasive surveillance capabilities. The lawmakers note the government publishes no annual reports on hacking operations unlike wiretaps.

CyberScoop · 26d agoPolicy & legal

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 17d agoPolicy & legal

Bipartisan Senate bill aims to prepare energy sector for Q

Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.

CyberScoop · 23d agoPolicy & legal

A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over

404 Media reveals DHS Border Patrol's secretive Predictive Intelligence Targeting Teams (PITT) analyzing Americans' financial activity and feeding intelligence to local police for traffic stops.

404 Media identified Predictive Intelligence Targeting Teams (PITT) in the Spokane Sector (Washington) and Laredo Sector (Texas), which review law enforcement-sensitive databases including Americans' financial activity and pass intelligence to local police. In one case, a PITT analyst flagged financial patterns associated with narcotics activity, leading Montana Highway Patrol to stop a driver for an obstructed license plate and charge him with DUI and possession with intent to distribute. CBP declined to say what financial data is monitored or whether warrants are obtained; the program extends AP's earlier reporting on ALPR-based predictive policing.

404 Media · 9d agoPolicy & legal

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia's ASD is replacing the Essential Eight with an outcomes-based Essentials series covering IT, cloud, OT and likely agentic AI, with deprecation from mid-2027.

The Australian Signals Directorate announced in June 2026 that the Essential Eight will be replaced by an outcomes-focused Essentials series structured as chapters covering enterprise IT (including identity and SaaS), cloud, OT, and likely agentic AI. Deprecation begins around mid-2027 with full retirement around mid-2028, though timelines are targets; the Essential Eight is mandatory for roughly 98 non-corporate Commonwealth entities but voluntary for private firms. Tenable argues the shift demands continuous security posture evidence via exposure management rather than point-in-time checklist assessments.

Tenable Blog · 2d agoPolicy & legal1

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail

A whistleblower alleges USPS is rushing untested IT systems that could reject thousands of mail-in ballots ahead of the 2026 midterm elections.

A whistleblower complaint released by Sen. Richard Blumenthal says USPS is deploying three new, largely untested IT systems — including the Federal Ballot Mail Portal — that could reject entire ballot batches over single scan errors. The systems were developed in weeks without standard testing or interoperability checks, and USPS allegedly continued work despite court injunctions against its rule changes. House Oversight Democrats demanded USPS halt implementation, and election experts warn the design could lead to new lawsuits and mass ballot denials.

CyberScoop · 15d agoPolicy & legal

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 13d agoPolicy & legal

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1