Changeflow GovPing Cybersecurity

Recent changes

This role tracks sources covering Guidance, Enforcement, Rule, Notice, and Consultation instruments. It currently monitors 41 sources for this role out of 2,348 total GovPing sources, with 311 changes in the last 7 days.

Recent alerts include a SAP Patchday disclosing 13 critical vulnerabilities (CVSS 9.9) and an Adobe Acrobat zero‑day (CVE‑2026‑34621) actively exploited. Also flagged are critical ArcGIS CVSS 9.8 flaws and a SharePoint flaw added to CISA's Known Exploited Vulnerabilities catalog.

Favicon for wid.cert-bund.de

OpenClaw Critical Vulnerabilities - Remote Code Execution Risk

CERT-Bund issued advisory WID-SEC-2026-1005 warning of critical vulnerabilities in OpenClaw personal AI assistant software. Multiple security flaws with CVSS Base Score 9.8 (critical) enable remote attackers to execute arbitrary code, escalate privileges, bypass security controls, and access or manipulate data. Affected products include Open Source OpenClaw versions prior to 2026.4.8 running on Linux and UNIX systems.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

IBM App Connect Enterprise Critical Vulnerabilities, CVSS 9.1

CERT-Bund published a critical security advisory (WID-SEC-2026-1007) warning of multiple severe vulnerabilities in IBM App Connect Enterprise with a CVSS Base Score of 9.1. The vulnerabilities allow remote attackers to bypass security controls, execute arbitrary code, perform SQL injection and XSS attacks, conduct denial of service, and disclose sensitive information. Organizations running affected versions on Linux, UNIX, Windows, or other platforms must apply mitigations immediately.

Urgent Notice Cybersecurity
Favicon for wid.cert-bund.de

Critical Golang Go Vulnerabilities, CVSS 9.8, Remote Code Execution

CERT-Bund issued a critical security advisory (WID-SEC-2026-1006) regarding multiple vulnerabilities in Golang Go versions prior to 1.26.2 and 1.25.9. The vulnerabilities carry a CVSS Base Score of 9.8 (critical) and enable attackers to execute arbitrary code remotely, cause memory corruption, bypass security controls, or trigger denial-of-service conditions. Organizations using affected Go versions must apply available mitigations or update immediately.

Urgent Guidance Cybersecurity
Favicon for changeflow.com

Bitcoin Depot 8-K cybersecurity incident disclosure

Bitcoin Depot Inc. filed Form 8-K Item 1.05 disclosing a material cybersecurity incident discovered on March 23, 2026. An unauthorized party accessed company IT systems and transferred approximately 50.903 Bitcoin (valued at $3.665 million) from company-controlled wallets without authorization. The company engaged cybersecurity experts and law enforcement, contained the incident to its corporate environment, and has not identified evidence of customer PII exfiltration. Investigation and remediation efforts remain ongoing.

Routine Notice Cybersecurity
Favicon for changeflow.com

Bitcoin Depot Cybersecurity Incident Disclosure (Form 8-K Item 1.05)

Bitcoin Depot filed a Form 8-K Item 1.05 disclosure with the SEC reporting a material cybersecurity incident. The filing describes the nature of the incident, the date of discovery, and its scope. As a publicly traded company, Bitcoin Depot is subject to SEC cybersecurity disclosure rules requiring prompt reporting of material cyber events.

Priority review Rule Cybersecurity
Favicon for www.cisa.gov

CVE-2026-1340 Ivanti EPMM Code Injection Vulnerability Added to KEV Catalog

CISA added CVE-2026-1340, an Ivanti Endpoint Manager Mobile (EPMM) code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerability poses significant risk as a frequent attack vector for malicious cyber actors targeting federal enterprises. Federal Civilian Executive Branch agencies are required to remediate vulnerabilities identified in the KEV Catalog pursuant to BOD 22-01.

Priority review Notice Cybersecurity
7d ago DHS Press Releases
Favicon for www.dhs.gov

CBP Arrests Five Fugitives in Five Days at Southern Border

U.S. Customs and Border Protection officers in the Laredo Field Office arrested five individuals with active felony warrants between March 27 and March 31, 2026. The arrests occurred at ports of entry including the Colombia-Solidarity Bridge in Laredo and the Gateway Bridge in Brownsville, Texas. Charges among the five fugitives included indecency with a child, homicide and abuse of office, aggravated assault with a deadly weapon, and burglary of a habitation.

Routine Notice Immigration
Favicon for wid.cert-bund.de

Windows privilege escalation, NT AUTHORITYSYSTEM access, unpatched

Windows privilege escalation, NT AUTHORITYSYSTEM access, unpatched

Routine Notice
Favicon for wid.cert-bund.de

Apache Cassandra Multiple Vulnerabilities - Privilege Escalation, Information Disclosure, DoS

CERT-Bund issued a security advisory warning of multiple vulnerabilities in Apache Cassandra database systems with a CVSS Base Score of 8.8. The flaws affect versions prior to 4.1.11, 5.0.7, and 4.0.20 across Linux, Windows, and UNIX platforms. Attackers can exploit these vulnerabilities to achieve privilege escalation, disclose information, and execute denial-of-service attacks.

Priority review Notice Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiples vulnérabilités dans OpenSSL - Avis CERT-FR 2026-AVI-0403

CERT-FR issued an advisory alerting organizations to multiple critical vulnerabilities in OpenSSL affecting versions 1.0.2 through 3.6.x. Seven CVEs were identified including CVE-2026-28386 through CVE-2026-28390 and CVE-2026-31789-CVE-2026-31790. The vulnerabilities enable remote code execution, denial of service, and data confidentiality breaches. Organizations running affected OpenSSL versions must apply vendor patches immediately.

Priority review Guidance Cybersecurity

Showing 301–310 of 1,347 changes

1 29 30 31 32 33 135
RSS

Get daily alerts for cybersecurity

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

Filters

41 official sources tracked

CERT-Bund Security Advisories

Updated 4m ago

USPTO Patent Applications - Networking (H04L)

Updated 9h ago

USPTO Patent Applications - AI & Computing (G06N)

Updated 5m ago

CERT-FR Security Advisories

Updated 32m ago

USPTO Patent Grants - Networking (H04L)

Updated 7d ago

DHS Press Releases

Updated 19m ago

CISA ICS-CERT Advisories

Updated 2d ago

CSA Alerts & Advisories (Singapore)

Updated 4m ago

CISA Known Exploited Vulnerabilities (KEV)

Updated 4h ago

NIST Publications

Updated 19d ago

EDGAR: Cybersecurity Incidents (8-K 1.05)

Updated 4d ago

DHS News

Updated 9d ago

NIST AI News & Updates

Updated 12d ago

JD Supra Technology & Cyber

Updated 18d ago

UK NCSC Alerts & Advisories

Updated 8d ago

DHS OIG Reports

Updated 18d ago

NIST News

Updated 18d ago

FFIEC IT Examination Handbook Updates

Updated 26d ago

CISA Cybersecurity Advisories

Updated 2m ago

IEEE Standards News

Updated 20d ago

EU AI Act Updates

Updated 4d ago

EPO Patent Bulletin - Networking (H04L)

Updated 17m ago

TSA Press Releases

Updated 15d ago

ENISA News

Updated 12d ago

Regs.gov: Office of the National Cyber Director

Updated 14d ago

NCSC UK News

Updated 21d ago

FR: Office of the National Cyber Director

Updated 15d ago

NSA Cybersecurity Advisories

Updated 6d ago

NIST Cybersecurity Framework Updates

Updated 22d ago

NCSC UK Threat Reports

Updated 1mo ago

USPTO Patent Grants - AI & Computing (G06N)

Updated --

EPO Patent Bulletin - AI & Computing (G06N)

Updated --

HITRUST News & Advisories

Updated 1mo ago

PCI SSC Press Releases

Updated 1mo ago

FR: Information Security Oversight Office

Updated 1mo ago

FR: National Crime Prevention and Privacy Compact Council

Updated 1mo ago

FedRAMP Changelog

Updated 1mo ago

Regs.gov: Cybersecurity and Infrastructure Security Agency

Updated 1mo ago

Regs.gov: First Responder Network Authority

Updated 1mo ago

Regs.gov: Privacy and Civil Liberties Oversight Board

Updated 1mo ago

Regs.gov: Information Security Oversight Office

Updated 1mo ago

Frequently asked questions

What does this feed cover?

CISA Known Exploited Vulnerabilities catalog, ICS-CERT industrial control system advisories, NSA/CISA joint alerts, NIST Cybersecurity Framework updates, FedRAMP authorization changes, and ENISA EU guidance.

Who is this for?

CISOs, SOC teams, and security compliance officers who need to track government cybersecurity directives and mandatory patching deadlines.

How often is this updated?

GovPing checks source pages multiple times daily. CISA KEV catalog additions are flagged as urgent.

Does this cover NIST framework updates?

Yes. We monitor NIST CSF, 800-series publications, and FedRAMP authorization pages.

Why are KEV additions flagged as urgent?

CISA's Known Exploited Vulnerabilities catalog carries binding operational directives for federal agencies, and most organizations treat it as a mandatory patch list. A new addition means active exploitation in the wild.

Is GovPing free?

Yes. GovPing is free, and always will be. We believe government regulatory data should be accessible to everyone. For custom monitoring of pages we don't cover yet, Changeflow starts at $99/mo.

Need to monitor something else?

GovPing covers the common sources. For niche pages specific to your team, add custom URL monitoring with Changeflow.

Get Cybersecurity alerts

Daily digest of cybersecurity regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.