Tag: CISA

VINCE-NT and the Nationalization of the Bug: When CISA Cuts the Academic Cord

CISA officially migrated its Coordinated Vulnerability Disclosure (CVD) platform on September 17. Behind the acronym VINCE-NT (Vulnerability Information and Coordination Environment – New Technology), which replaces the venerable VINCE operated since 2020 by the CERT/CC, lies much more than a mere interface facelift or a welcome alignment with CSAF status frameworks. This is an act…

Oracle’s September 2026 CSPU: 673 security patches

Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware. TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use. Published 16 September 2026 Subject Oracle, September 2026 CSPU Distribution Public Confidence…

What AI Is Changing in Responsible Disclosure

CTI Analysis · Disclosure Doctrine The Embargo Is No Longer a Protection: What AI Is Changing in Responsible Disclosure Six dnsmasq CVEs, a maintainer exhausted by the tsunami of AI-generated bug reports, and the public admission of a major doctrinal pivot. Reading a weak signal that could foreshadow the end of a model thirty years…

INTELLIGENCE REPORT : MERCURY (MuddyWater)

TLP:CLEAR | CTI Team | Updated: March 2026 1. IDENTIFICATION & ATTRIBUTION Designations (vendor aliases) The group is tracked under the following designations by vendors: MERCURY (Microsoft, historical designation), MuddyWater (ClearSky, common usage designation), Mango Sandstorm (Microsoft, current designation), Seedworm (Symantec/Broadcom), Static Kitten (CrowdStrike), Earth Vetala (Trend Micro), TEMP.Zagros (Mandiant/FireEye pre-attribution), TA450 (Proofpoint), Boggy Serpens…

Russian Intelligence Services Espionage Campaign Targeting Signal Accounts and Encrypted Messaging Applications

Technical and Strategic AnalysisFBI/CISA PSA I-032026-PSA — March 20, 2026 | TLP:CLEAR 1. Executive Summary — Board Level / Strategic View On March 20, 2026, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) jointly published a public service announcement (PSA I-032026-PSA) alerting the public to an active campaign by…