Changeflow GovPing Cybersecurity

Recent changes

Favicon for wid.cert-bund.de

OpenClaw Multiple Critical Vulnerabilities Allow Remote Code Execution

CERT-Bund issued security advisory WID-SEC-2026-1065 alerting to multiple critical vulnerabilities in OpenClaw, a personal AI assistant for local devices. The flaws carry a CVSS Base Score of 8.8 (high) and enable remote attackers to gain administrator privileges, execute arbitrary code, bypass security controls, and disclose or manipulate data. The affected version is Open Source OpenClaw prior to version 2026.3.25. Users are advised to apply available mitigations and update to the patched release.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Red Hat OpenShift AI Vulnerability Enables Information Disclosure and Privilege Escalation

CERT-Bund issued a security advisory regarding a vulnerability in Red Hat OpenShift AI (affecting versions 2.16.4, 2.25.4, 3.3.1, and 3.2). The vulnerability, with a CVSS Base Score of 8.5 (high) and Temporal Score of 7.4 (high), allows a remote, authenticated attacker to exploit the flaw to disclose confidential information and potentially escalate privileges. Mitigation measures are available.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

Critical Remote Code Execution Vulnerability in Red Hat Enterprise Linux Cockpit

CERT-Bund, operating under the German Federal Office for Information Security (BSI), issued a critical security advisory regarding a remote code execution vulnerability in Red Hat Enterprise Linux Cockpit. The vulnerability carries a CVSS Base Score of 9.8 (critical) and a Temporal Score of 8.5 (high). Affected versions include Red Hat Enterprise Linux 9.6 and Red Hat Enterprise Linux 10. Organizations using these systems should apply available mitigations immediately.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Red Hat Enterprise Linux Multiple Vulnerabilities, Remote Attack

Red Hat Enterprise Linux Multiple Vulnerabilities, Remote Attack

Routine Notice
Favicon for www.cisa.gov

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The CVEs affect Microsoft, Adobe, and Fortinet products. Binding Operational Directive 22-01 requires Federal Civilian Executive Branch agencies to remediate these vulnerabilities by specified due dates. CISA strongly urges all organizations to prioritize timely remediation of these vulnerabilities as part of their vulnerability management practice.

Priority review Rule Cybersecurity
2d ago DHS Press Releases
Favicon for www.dhs.gov

ICE Requests Missouri Not Release Illegal Alien Accused of Rape and Kidnapping

U.S. Immigration and Customs Enforcement (ICE) announced the arrest of Cristian Lopez-Gomez, a Honduran illegal alien, in connection with charges of rape and kidnapping of a woman in Kirksville, Missouri on Easter Sunday. Lopez-Gomez allegedly entered the United States illegally in 2024 and was released into American communities by the prior administration. ICE has formally requested Missouri authorities not release him while he faces criminal prosecution.

Routine Notice Immigration
Favicon for www.cert.ssi.gouv.fr

Critical Adobe Acrobat Vulnerability CVE-2026-34621 Actively Exploited

CERT-FR issued advisory CERTFR-2026-AVI-0429 warning of a critical vulnerability in Adobe Acrobat (CVE-2026-34621) that allows arbitrary code execution. The vulnerability affects Acrobat 2024, Acrobat DC, and Acrobat Reader DC on Windows and macOS. Adobe has confirmed the vulnerability is being actively exploited in the wild. Users are advised to apply vendor patches immediately.

Urgent Notice Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiples vulnérabilités dans les produits Microsoft - 13 CVE

CERT-FR issued advisory CERTFR-2026-AVI-0428 notifying of 13 vulnerabilities (CVE-2026-35385, CVE-2026-35386, CVE-2026-35388, CVE-2026-35535, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790, CVE-2026-39881, CVE-2026-40024, CVE-2026-40025, CVE-2026-40026) affecting Microsoft products. Affected systems include azl3 openssh, openssl, sleuthkit, sudo, and vim packages. Risk level not specified by the vendor.

Routine Notice Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple Microsoft Edge Security Vulnerabilities Affecting Bypass and Remote Code Execution

ANSSI/CERT-FR published advisory CERTFR-2026-AVI-0427 warning of 86+ vulnerabilities in Microsoft Edge (CVE-2026-33118 through CVE-2026-5905 and beyond). Source bulletins were released by Microsoft on April 10, 2026. Vulnerabilities include security bypass and remote code execution risks affecting all organizations and users of Microsoft Edge browser.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple Security Vulnerabilities in Python Allow Security Bypass

CERT-FR issued advisory CERTFR-2026-AVI-0426 on April 13, 2026, alerting that multiple vulnerabilities were discovered in Python (CPython). These vulnerabilities allow attackers to cause security policy bypass and unspecified security issues. Affected systems are CPython installations without the latest security patches. Two CVEs are referenced: CVE-2026-1502 and CVE-2026-3446.

Priority review Notice Cybersecurity

Showing 101–110 of 1,434 changes

1 9 10 11 12 13 144
RSS

Get daily alerts for cybersecurity

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

Filters

41 official sources tracked

CERT-Bund Security Advisories

Updated 5m ago

USPTO Patent Applications - Networking (H04L)

Updated 9h ago

USPTO Patent Applications - AI & Computing (G06N)

Updated 4m ago

CERT-FR Security Advisories

Updated 32m ago

USPTO Patent Grants - Networking (H04L)

Updated 7d ago

EPO Patent Bulletin - Networking (H04L)

Updated 5m ago

DHS Press Releases

Updated 13m ago

CISA ICS-CERT Advisories

Updated 2d ago

CSA Alerts & Advisories (Singapore)

Updated 18m ago

CISA Known Exploited Vulnerabilities (KEV)

Updated 4h ago

NIST Publications

Updated 19d ago

EDGAR: Cybersecurity Incidents (8-K 1.05)

Updated 4d ago

DHS News

Updated 9d ago

NIST AI News & Updates

Updated 12d ago

JD Supra Technology & Cyber

Updated 18d ago

DHS OIG Reports

Updated 18d ago

NIST News

Updated 18d ago

UK NCSC Alerts & Advisories

Updated 8d ago

CISA Cybersecurity Advisories

Updated 2m ago

FFIEC IT Examination Handbook Updates

Updated 26d ago

IEEE Standards News

Updated 20d ago

EU AI Act Updates

Updated 4d ago

TSA Press Releases

Updated 15d ago

ENISA News

Updated 12d ago

NCSC UK News

Updated 21d ago

NSA Cybersecurity Advisories

Updated 6d ago

FR: Office of the National Cyber Director

Updated 15d ago

Regs.gov: Office of the National Cyber Director

Updated 14d ago

NIST Cybersecurity Framework Updates

Updated 22d ago

EPO Patent Bulletin - AI & Computing (G06N)

Updated --

USPTO Patent Grants - AI & Computing (G06N)

Updated --

FedRAMP Changelog

Updated 1mo ago

Regs.gov: Cybersecurity and Infrastructure Security Agency

Updated 1mo ago

Regs.gov: First Responder Network Authority

Updated 1mo ago

Regs.gov: Privacy and Civil Liberties Oversight Board

Updated 1mo ago

Regs.gov: Information Security Oversight Office

Updated 1mo ago

FR: National Crime Prevention and Privacy Compact Council

Updated 1mo ago

FR: Information Security Oversight Office

Updated 1mo ago

PCI SSC Press Releases

Updated 1mo ago

HITRUST News & Advisories

Updated 1mo ago

NCSC UK Threat Reports

Updated 1mo ago

Frequently asked questions

What does this feed cover?

CISA Known Exploited Vulnerabilities catalog, ICS-CERT industrial control system advisories, NSA/CISA joint alerts, NIST Cybersecurity Framework updates, FedRAMP authorization changes, and ENISA EU guidance.

Who is this for?

CISOs, SOC teams, and security compliance officers who need to track government cybersecurity directives and mandatory patching deadlines.

How often is this updated?

GovPing checks source pages multiple times daily. CISA KEV catalog additions are flagged as urgent.

Does this cover NIST framework updates?

Yes. We monitor NIST CSF, 800-series publications, and FedRAMP authorization pages.

Why are KEV additions flagged as urgent?

CISA's Known Exploited Vulnerabilities catalog carries binding operational directives for federal agencies, and most organizations treat it as a mandatory patch list. A new addition means active exploitation in the wild.

Is GovPing free?

Yes. GovPing is free, and always will be. We believe government regulatory data should be accessible to everyone. For custom monitoring of pages we don't cover yet, Changeflow starts at $99/mo.

Need to monitor something else?

GovPing covers the common sources. For niche pages specific to your team, add custom URL monitoring with Changeflow.

Get Cybersecurity alerts

Daily digest of cybersecurity regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.