Changeflow GovPing Cybersecurity

Recent changes

This role tracks sources covering Guidance, Enforcement, Rule, Notice, and Consultation instruments. It currently monitors 41 sources for this role out of 2,348 total GovPing sources, with 311 changes in the last 7 days.

Recent alerts include a SAP Patchday disclosing 13 critical vulnerabilities (CVSS 9.9) and an Adobe Acrobat zero‑day (CVE‑2026‑34621) actively exploited. Also flagged are critical ArcGIS CVSS 9.8 flaws and a SharePoint flaw added to CISA's Known Exploited Vulnerabilities catalog.

Favicon for wid.cert-bund.de

OPNsense Firewall Vulnerability Allows Remote Information Disclosure (CVSS 8.2)

CERT-Bund has issued a security advisory (WID-SEC-2026-1044) regarding a vulnerability in OPNsense, an open-source firewall distribution based on FreeBSD. The vulnerability, with a CVSS Base Score of 8.2 (high), allows remote, anonymous attackers to disclose sensitive information. Affected versions include OPNsense prior to version 26.1.6. A mitigation measure is available as of April 10, 2026.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Multiple Critical Vulnerabilities in MISP Threat Intelligence Platform

CERT-Bund issued security advisory WID-SEC-2026-1045 warning of multiple critical vulnerabilities in Open Source MISP (threat intelligence sharing platform) versions prior to 2.5.36. The vulnerabilities carry a CVSS Base Score of 9.6 (critical) and Temporal Score of 8.3 (high). Attackers can exploit these flaws to bypass security measures, conduct Cross-Site-Scripting attacks, and cause unspecified impacts via remote attack.

Priority review Notice Cybersecurity
5d ago DHS Press Releases
Favicon for www.dhs.gov

DHS Issues Statement on Criminal Alien Convicted of Assaulting High School Girls in Fairfax County

DHS issued a press release regarding the conviction of Israel Christopher Flores-Ortiz, an illegal alien from El Salvador, for nine counts of assault and battery committed at Fairfax County High School. The statement criticizes Virginia sanctuary policies and calls on Governor Spanberger not to release the defendant before sentencing on April 21.

Routine Notice Immigration
Favicon for www.cert.ssi.gouv.fr

Multiple IBM Product Vulnerabilities Allow Remote Code Execution

CERT-FR published advisory CERTFR-2026-AVI-0424 on April 10, 2026 disclosing multiple critical vulnerabilities in IBM products including QRadar AI Assistant, Sterling External Authentication Server, Sterling Secure Proxy, and WebSphere Application Server Liberty. Affected versions span QRadar AI Assistant prior to 1.4.0, Sterling products prior to 6.1.1.3 GA and 6.2.1.2 GA, and WebSphere Liberty 17.0.0.3 to 26.0.0.3 without APAR PH70510. The vulnerabilities expose systems to remote code execution, data confidentiality breaches, denial of service, and security policy bypass.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Red Hat Linux Kernel Multiple Vulnerabilities Alert

CERT-FR issued an advisory alerting organizations to multiple kernel vulnerabilities in Red Hat Linux affecting numerous products across multiple architectures (x86_64, aarch64, s390x, ppc64le). The vulnerabilities expose affected systems to data confidentiality breaches, security policy bypass, remote denial of service, arbitrary code execution, and privilege escalation risks. Organizations running Red Hat Enterprise Linux, CodeReady Linux Builder, and related products must patch immediately.

Urgent Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

SUSE Linux Kernel Multiple Vulnerabilities Advisory

CERT-FR published advisory CERTFR-2026-AVI-0422 disclosing multiple vulnerabilities in the SUSE Linux kernel affecting openSUSE Leap, SUSE Linux Enterprise Server, and related product lines across versions 12 SP5 through 15 SP7. The vulnerabilities, sourced from 13 SUSE security bulletins, could allow an attacker to cause unspecified security impacts. Affected parties are advised to apply patches referenced in the vendor security bulletins.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple Ubuntu Linux Kernel Vulnerabilities Allow Privilege Escalation

CERT-FR published advisory CERTFR-2026-AVI-0421 warning of multiple Linux kernel vulnerabilities affecting Ubuntu 16.04 ESM through 25.10. The vulnerabilities allow privilege escalation, data confidentiality breaches, data integrity breaches, and denial of service attacks. System administrators should apply patches referenced in 16 Ubuntu security notices (USN-8145-3 through USN-8165-1) covering CVE-2022-49465, CVE-2022-49635, CVE-2023-53041, CVE-2023-53421, CVE-2023-53520, and additional CVEs.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple Vulnerabilities in Microsoft Azure Linux, 6 CVEs

ANSSI's CERT-FR issued an alert covering 6 CVEs in Microsoft Azure Linux components affecting azl3 kernel (versions prior to 6.6.130.1-1), azl3 libsoup (prior to 3.4.4-15), and azl3 xz (prior to 5.4.4-3). The vulnerabilities could allow an attacker to cause unspecified security issues. No specific risk severity was stated by the vendor. French organizations using Azure Linux are advised to apply vendor patches immediately via Microsoft Security Response Center.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple Vulnerabilities in Mattermost Desktop App

CERT-FR published security advisory CERTFR-2026-AVI-0419 alerting to multiple vulnerabilities in Mattermost Desktop App affecting versions prior to 5.13.5.0. The vulnerabilities could allow an attacker to cause unspecified security issues. Organizations using Mattermost Desktop App should consult the vendor security bulletins and apply available patches.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Apache Tomcat Multiple Vulnerabilities

CERT-FR issued an advisory warning of multiple vulnerabilities in Apache Tomcat affecting versions 10.1.x prior to 10.1.54, 11.0.x prior to 11.0.21, and 9.0.x prior to 9.0.117. The vulnerabilities allow attackers to compromise data confidentiality, data integrity, and bypass security policies. Organizations running affected Tomcat deployments must apply available patches referenced in Apache security bulletins.

Priority review Notice Cybersecurity

Showing 231–240 of 1,457 changes

1 22 23 24 25 26 146
RSS

Get daily alerts for cybersecurity

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

Filters

41 official sources tracked

CERT-Bund Security Advisories

Updated 4m ago

USPTO Patent Applications - Networking (H04L)

Updated 9h ago

USPTO Patent Applications - AI & Computing (G06N)

Updated 4m ago

CERT-FR Security Advisories

Updated 32m ago

USPTO Patent Grants - Networking (H04L)

Updated 7d ago

EPO Patent Bulletin - Networking (H04L)

Updated 39m ago

DHS Press Releases

Updated 13m ago

CISA ICS-CERT Advisories

Updated 2d ago

CSA Alerts & Advisories (Singapore)

Updated 18m ago

CISA Known Exploited Vulnerabilities (KEV)

Updated 4h ago

NIST Publications

Updated 19d ago

EDGAR: Cybersecurity Incidents (8-K 1.05)

Updated 4d ago

DHS News

Updated 9d ago

NIST AI News & Updates

Updated 12d ago

JD Supra Technology & Cyber

Updated 18d ago

DHS OIG Reports

Updated 18d ago

NIST News

Updated 18d ago

UK NCSC Alerts & Advisories

Updated 8d ago

CISA Cybersecurity Advisories

Updated 2m ago

FFIEC IT Examination Handbook Updates

Updated 26d ago

IEEE Standards News

Updated 20d ago

EU AI Act Updates

Updated 4d ago

TSA Press Releases

Updated 15d ago

ENISA News

Updated 12d ago

NCSC UK News

Updated 21d ago

NSA Cybersecurity Advisories

Updated 6d ago

FR: Office of the National Cyber Director

Updated 15d ago

Regs.gov: Office of the National Cyber Director

Updated 14d ago

NIST Cybersecurity Framework Updates

Updated 22d ago

EPO Patent Bulletin - AI & Computing (G06N)

Updated --

USPTO Patent Grants - AI & Computing (G06N)

Updated --

FedRAMP Changelog

Updated 1mo ago

Regs.gov: Cybersecurity and Infrastructure Security Agency

Updated 1mo ago

Regs.gov: First Responder Network Authority

Updated 1mo ago

Regs.gov: Privacy and Civil Liberties Oversight Board

Updated 1mo ago

Regs.gov: Information Security Oversight Office

Updated 1mo ago

FR: National Crime Prevention and Privacy Compact Council

Updated 1mo ago

FR: Information Security Oversight Office

Updated 1mo ago

PCI SSC Press Releases

Updated 1mo ago

HITRUST News & Advisories

Updated 1mo ago

NCSC UK Threat Reports

Updated 1mo ago

Frequently asked questions

What does this feed cover?

CISA Known Exploited Vulnerabilities catalog, ICS-CERT industrial control system advisories, NSA/CISA joint alerts, NIST Cybersecurity Framework updates, FedRAMP authorization changes, and ENISA EU guidance.

Who is this for?

CISOs, SOC teams, and security compliance officers who need to track government cybersecurity directives and mandatory patching deadlines.

How often is this updated?

GovPing checks source pages multiple times daily. CISA KEV catalog additions are flagged as urgent.

Does this cover NIST framework updates?

Yes. We monitor NIST CSF, 800-series publications, and FedRAMP authorization pages.

Why are KEV additions flagged as urgent?

CISA's Known Exploited Vulnerabilities catalog carries binding operational directives for federal agencies, and most organizations treat it as a mandatory patch list. A new addition means active exploitation in the wild.

Is GovPing free?

Yes. GovPing is free, and always will be. We believe government regulatory data should be accessible to everyone. For custom monitoring of pages we don't cover yet, Changeflow starts at $99/mo.

Need to monitor something else?

GovPing covers the common sources. For niche pages specific to your team, add custom URL monitoring with Changeflow.

Get Cybersecurity alerts

Daily digest of cybersecurity regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.