CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.
Vulnerability
CISA ICS
2026-07-07
Hitachi Energy PROMOD V versions <=1.0.10 use insecure HTTP, enabling interception of credentials and session data.
Hitachi Energy disclosed a critical vulnerability in PROMOD V where insecure HTTP communication allows attackers to intercept or manipulate sensitive data in transit. Affected versions are 1.0.10 and prior; vendors must upgrade to version 1.0.11 and enable HTTPS on the Digipede server.
AFFECTEDHitachi Energy PROMOD V
▸ DO Patch Hitachi Energy PROMOD V to version 1.0.11 and enable HTTPS on the Digipede server.
#vulnerability#patch-available#credential-theft#http-insecure#energy-sector
Vulnerability
CISA
2026-07-07
CISA added three new CVEs to the KEV Catalog, including JoomShaper and Langflow flaws exploited in the wild.
Three vulnerabilities affecting JoomShaper, Langflow, and Joomlack have been added to CISA's KEV Catalog due to evidence of active exploitation. DIB organizations should prioritize patching these components to prevent unauthorized access and file upload attacks.
AFFECTEDJoomShaperLangflowJoomlack
▸ DO Prioritize patching JoomShaper, Langflow, and Joomlack components per BOD 26-04.
#exploited-in-wild#patch-available#vulnerability#access-control#authorization-bypass#unrestricted-upload
Vulnerability
CISA
2026-07-07
CISA added CVE-2026-48282 (Adobe ColdFusion path traversal) to the KEV Catalog due to active exploitation.
This vulnerability allows attackers to traverse paths in Adobe ColdFusion, granting full control of the asset. Federal agencies must prioritize rapid remediation per BOD 26-04, and CISA encourages all organizations to adopt risk-based vulnerability management.
AFFECTEDAdobe ColdFusion
▸ DO Patch Adobe ColdFusion immediately.
#exploited-in-wild#patch-available#vulnerability#dib-sector