CiberLATAMbywhalemate

#CISA

This archive brings together coverage of the U.S. cybersecurity agency, its regulatory activity, and the alerts it issues on threats, vulnerabilities, and best practices. It also tracks how those guidelines affect organizations in Latin America, where they often serve as a benchmark for defense teams, incident response, and risk management.

Medusa tops 500 victims in health sector

FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.

Aug 22, 2026 · 2 min

CISA Adds Four Critical CVEs to KEV Catalog

CISA added four actively exploited flaws in Apple, Microsoft and VMware to its KEV catalog and set the federal deadline for Aug. 21.

Aug 22, 2026 · 3 min

US Alerts on Gunra, Unlimited Breach Hits 3.8M

US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.

Aug 16, 2026 · 3 min

THEGENTLEMEN, Gunra, INC Ransom hit Latin America

THEGENTLEMEN, Gunra and INC Ransom added victims and alerts across the region, with a focus on VPNs, firewalls

Aug 15, 2026 · 3 min

US Water Attacks Hit 12 States, NY Funds Defense

Water attacks in the U.S. affected at least 12 states. New York is funding 153 systems as Latin America exposes energy gaps.

Aug 10, 2026 · 38 min

CISA adds CVE-2026-34486 to KEV catalog

CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.

Aug 10, 2026 · 2 min

CVE-2026-8037 lands in CISA's KEV catalog

CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.

Aug 10, 2026 · 2 min

INCIBE warns on 5 critical VMware flaws

INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.

Aug 3, 2026 · 2 min

US Alerts on Water System Attacks

CISA and the FBI report a rise in OT attacks on water and wastewater systems, including lockouts and password changes in several states.

Aug 1, 2026 · 2 min

CISA Adds Cisco FMC CVE-2026-20316 to KEV

CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.

Jul 30, 2026 · 2 min

CISA adds CVE-2026-16812 to KEV catalog

CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.

Jul 28, 2026 · 2 min

CISA Warns on CVE-2025-66376 in Zimbra

CISA, NSA and FBI warned on a Zimbra flaw abused by LAUNDRY BEAR to steal email, 2FA codes and passwords with a single message.

Jul 24, 2026 · 1 min

CISA warns on three SharePoint flaws

CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.

Jul 19, 2026 · 3 min

NSA warns on Russia-linked routers

US and allies warned of a Russia-attributed campaign exploiting routers with weak SNMP, default passwords and unpatched firmware.

Jul 19, 2026 · 2 min

CVE-2026-56291 hits Balbooa Forms on Joomla

Balbooa Forms for Joomla had a critical RCE abused as a zero-day. Patch 2.4.1 landed July 9, and CISA added it to KEV.

Jul 15, 2026 · 3 min

Qilin and Securotrop in Q2 2026

Between May and June 2026, multiple trackers and intelligence reports linked Qilin to active ransomware campaigns that escalated around a critical Check

Jul 7, 2026 · 39 min