CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.
Guidance
CISA
2026-08-26
CISA's Vulnerability Review highlights common software weaknesses and provides steps to address them proactively.
Most compromises exploit basic security failures and well-known software vulnerabilities rather than advanced techniques. The CISA Vulnerability Review analyzes vulnerability data from fiscal years 2024 and 2025 to establish a baseline and promote Secure by Design principles, helping organizations reduce systemic vulnerabilities instead of just reacting to individual flaws.
▸ DO Review the CISA Vulnerability Review to identify common software weaknesses and implement Secure by Design principles in your software development lifecycle.
#mitigations#guidance#vulnerability
Guidance
CISA
2026-08-25
CISA red team assessments reveal how detection tuning and response processes determine whether an organization can contain a breach.
CISA conducted red team assessments at two organizations, showing that Organization B's rapid detection and isolation contrasted with Organization A's failure to contain the attack. The advisory highlights lessons on detection tuning, response processes, and mitigations for IT, cloud, and OT environments.
▸ DO Review detection tool baselines and alert filtering to reduce false positives, and establish clear incident response procedures and defender authority.
#mitigations#detection#incident-response#ot#cloud#it
Guidance
CISA
2026-07-30
CISA released new guidance on securely managing open source software across its lifecycle.
This guidance helps agencies securely use, evaluate, and publish open source software by covering risk management, the C4 Framework for trust assessment, vulnerability management, software bill of materials, secure development, and handling open source AI systems.
▸ DO Review and apply the C4 Framework for trust assessment and update your open source software risk management processes.
#mitigations#oss#guidance
Guidance
CISA
2026-07-29
CISA and partners released updated 2026 minimum elements for Software Bills of Materials (SBOMs) to improve software supply chain transparency and risk management.
This joint guidance from CISA, NSA, and FBI updates the 2021 NTIA SBOM minimum elements, incorporating stakeholder feedback and current tools. Organizations should apply these baseline elements to all software, with additional considerations for AI and cloud SaaS, to better understand their software makeup and supply chains.
▸ DO Review and update your SBOM generation process to align with the 2026 minimum elements.
#guidance#supply-chain#mitigations
Guidance
CISA
2026-07-28
CISA and international partners released joint guidance on isolating vital operational technology systems during cyber incidents or crises.
This guidance provides practical steps for critical infrastructure organizations to isolate vital operational technology and enabling systems from all other networks in the event of disruption or crisis. By following these recommendations, organizations can enhance resilience, minimize disruption, and maintain essential services during cyber incidents or geopolitical crises.
▸ DO Review the guidance and implement isolation steps for vital operational technology systems.
#mitigations#ot#dib-sector
Guidance
CISA
2026-07-15
CISA, NSA, and partners release joint guidance on establishing Coordinated Vulnerability Disclosure (CVD) programs to work with security researchers.
This guidance provides best practices for software manufacturers and online service providers to design and implement a CVD program, including a clear vulnerability disclosure policy and process for triaging, remediating, and assigning CVE identifiers. Organizations can leverage third-party intermediaries like CISA to supplement their CVD program.
▸ DO Review and implement a Coordinated Vulnerability Disclosure (CVD) program aligned with this guidance.
#mitigations#vulnerability