Please turn on your JavaScript for this page to function normally.
JPCERT/CC
CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a …
CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108)
CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities …
Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932)
CVE-2025-61932, an “improper verification of source of a communication channel” vulnerability affecting Lanscope Endpoint Manager, has been exploited as a zero-day …
Featured news
Resources
Don't miss
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
- Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
- AI-Infra-Guard: Open-source security scanner for AI systems
- Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results
- What breach and attack simulation needs to become in the AI era