By industry

Government security news

All industries →

Thu, 10 Sept 2026

  1. CISA is on the verge of filling hundreds of critical vacancies

    The agency is also working to finalize an incident-reporting regulation and set up a new industry coordination structure, its acting director said.

    Cybersecurity Dive
  2. CISA Updates Insider Threat Guide With New Mitigation Advice

    CISA has updated its insider threat guide with new advice on remote work, AI and risk detection

    Infosecurity Magazine
  3. Governments ‘buying time’ in race between innovation, security, national cyber director says

    Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones.

    CyberScoop
  4. 2026-004: Critical Vulnerability in SharePoint Exploited

    On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.

    CERT-EUMicrosoft, SharePoint
  5. FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

    The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors

    Infosecurity Magazine
  6. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

    CriticalThe Hacker NewsCitrix, Cisco, Fortinet
  7. Organizations Warned of Cisco Secure FMC Exploitation

    Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

    CriticalSecurityWeekCisco
  8. CISA: WatchGuard RCE flaw now exploited in ransomware attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.

    BleepingComputer
  9. EU Cyber Resilience Act to Enforce New Reporting Requirements

    Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.

    Dark Reading

Wed, 9 Sept 2026

  1. CISA head says agency must change quickly to prevent the 'worst that could happen'

    CISA's cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says.

    The Record

Latest government briefing

Government Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

40 stories affecting government tracked in the last seven days, 5 rated critical, 2 vulnerabilities added to the CISA Known Exploited catalogue.

About government news

135
Stories
57
In the last 7 days
7
Critical in the last 7 days