Changeflow GovPing Cybersecurity

Recent changes

This role tracks sources covering Guidance, Enforcement, Rule, Notice, and Consultation instruments. It currently monitors 41 sources for this role out of 2,348 total GovPing sources, with 311 changes in the last 7 days.

Recent alerts include a SAP Patchday disclosing 13 critical vulnerabilities (CVSS 9.9) and an Adobe Acrobat zero‑day (CVE‑2026‑34621) actively exploited. Also flagged are critical ArcGIS CVSS 9.8 flaws and a SharePoint flaw added to CISA's Known Exploited Vulnerabilities catalog.

Favicon for changeflow.com

Data processing system peripheral device management using component certificates

USPTO granted Patent US12598081B2 to Dell Products L.P. covering methods for managing data processing systems using digital certificates to authenticate and control peripheral device functions. The system employs a management controller operating independently of the CPU to enable or disable peripheral functions including Reliability, Availability, and Serviceability (RAS) reporting. The patent establishes intellectual property rights for digital certificate-based device authentication in computing environments.

Routine Rule Intellectual Property
Favicon for changeflow.com

Facilitating token use authentication for access tokens using stochastic images

USPTO granted patent US12598072B2 to Capital One Services, LLC on April 7, 2026, covering methods for facilitating token use authentication using stochastic images generated by machine learning models. The patent describes a system that detects authentication requests, retrieves previously displayed images, generates new images using stochastic ML models, and authenticates users based on image selection recognition. The patent contains 19 claims and was filed on November 10, 2023.

Routine Notice Intellectual Property
Favicon for www.cert.ssi.gouv.fr

Multiples vulnérabilités dans Google Android - Déni de service

CERT-FR issued security advisory CERTFR-2026-AVI-0399 alerting to multiple vulnerabilities in Google Android. The vulnerabilities affect Android versions prior to 14, 15, 16, and 16-qpr2, and could allow attackers to cause denial of service conditions. The advisory references CVE-2025-48651 and CVE-2026-0049, with patches released by Google on April 6, 2026.

Priority review Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

FortiClientEMS Vulnerability CVE-2026-35616 Actively Exploited

CERT-FR issued advisory CERTFR-2026-AVI-0400 warning of active exploitation of CVE-2026-35616 in Fortinet FortiClientEMS. The vulnerability allows remote code execution, privilege escalation, and security policy bypass on affected versions 7.4.x through 7.4.5. Organizations running vulnerable FortiClientEMS deployments are urged to apply patches immediately.

Urgent Guidance Cybersecurity
Favicon for www.cert.ssi.gouv.fr

Multiple vulnerabilities in GLPI - RCE, SQL injection, XSS

CERT-FR issued a security advisory alerting organizations to multiple critical vulnerabilities in GLPI, an IT asset management and helpdesk software. The vulnerabilities affect GLPI versions 11.0.x prior to 11.0.6 and versions prior to 10.0.24, enabling remote code execution, SQL injection, and cross-site scripting attacks. Five CVEs are referenced: CVE-2026-25932, CVE-2026-26026, CVE-2026-26027, CVE-2026-26263, and CVE-2026-29047. Organizations using affected GLPI versions should apply vendor-provided patches immediately.

Priority review Guidance Cybersecurity
Favicon for changeflow.com

Salesforce multi-tenant data access control with cloud token security

USPTO granted Salesforce patent US12598193B2 covering fine granularity control of data access and usage across multi-tenant systems. The system validates user access requests against data source permissions and creates cloud-specific tokens converted from cloud-neutral tokens, establishing temporary IAM roles and policies with automatic expiration.

Routine Rule Intellectual Property
Favicon for changeflow.com

Atlassian patent, access controls for authenticated and public users

The USPTO granted Patent US12598189B2 to Atlassian Pty Ltd covering a content collaboration system that manages dual access controls for authenticated users and unauthenticated public users. The system provides synchronized content caching and hierarchical visibility controls for publicly accessible digital content across enterprise environments.

Routine Notice Intellectual Property
Favicon for changeflow.com

Privileged account security system and method for managing access

USPTO granted patent US12598187B2 to Saudi Arabian Oil Company for a system and method managing privileged account access. The technology disables privileged accounts upon creation and enables them only after user authentication for elevated rights requests, reducing the likelihood of system compromise. This is a routine IP event establishing enforceable patent rights for the assignee.

Routine Notice Intellectual Property
Favicon for changeflow.com

Network access using hardware-based security

USPTO granted patent US12598078B2 to Sophos Limited covering hardware-based security for network authentication. The patent describes endpoint devices using hardware-bound security systems to authenticate to enterprise networks, with cryptographically validated challenge-response protocols. The patent was applied for on February 15, 2023, under application number 18110051, with 20 claims granted.

Routine Notice Intellectual Property
Favicon for changeflow.com

BOE Technology info security issuing system patent, Apr

BOE Technology info security issuing system patent, Apr

Routine Notice

Showing 321–330 of 1,347 changes

1 31 32 33 34 35 135
RSS

Get daily alerts for cybersecurity

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

Filters

41 official sources tracked

CERT-Bund Security Advisories

Updated 4m ago

USPTO Patent Applications - Networking (H04L)

Updated 9h ago

USPTO Patent Applications - AI & Computing (G06N)

Updated 5m ago

CERT-FR Security Advisories

Updated 32m ago

USPTO Patent Grants - Networking (H04L)

Updated 7d ago

DHS Press Releases

Updated 19m ago

CISA ICS-CERT Advisories

Updated 2d ago

CSA Alerts & Advisories (Singapore)

Updated 4m ago

CISA Known Exploited Vulnerabilities (KEV)

Updated 4h ago

NIST Publications

Updated 19d ago

EDGAR: Cybersecurity Incidents (8-K 1.05)

Updated 4d ago

DHS News

Updated 9d ago

NIST AI News & Updates

Updated 12d ago

JD Supra Technology & Cyber

Updated 18d ago

UK NCSC Alerts & Advisories

Updated 8d ago

DHS OIG Reports

Updated 18d ago

NIST News

Updated 18d ago

FFIEC IT Examination Handbook Updates

Updated 26d ago

CISA Cybersecurity Advisories

Updated 2m ago

IEEE Standards News

Updated 20d ago

EU AI Act Updates

Updated 4d ago

EPO Patent Bulletin - Networking (H04L)

Updated 17m ago

TSA Press Releases

Updated 15d ago

Regs.gov: Office of the National Cyber Director

Updated 14d ago

NCSC UK News

Updated 21d ago

FR: Office of the National Cyber Director

Updated 15d ago

NSA Cybersecurity Advisories

Updated 6d ago

ENISA News

Updated 12d ago

NIST Cybersecurity Framework Updates

Updated 22d ago

NCSC UK Threat Reports

Updated 1mo ago

USPTO Patent Grants - AI & Computing (G06N)

Updated --

EPO Patent Bulletin - AI & Computing (G06N)

Updated --

HITRUST News & Advisories

Updated 1mo ago

PCI SSC Press Releases

Updated 1mo ago

FR: Information Security Oversight Office

Updated 1mo ago

FR: National Crime Prevention and Privacy Compact Council

Updated 1mo ago

FedRAMP Changelog

Updated 1mo ago

Regs.gov: Cybersecurity and Infrastructure Security Agency

Updated 1mo ago

Regs.gov: First Responder Network Authority

Updated 1mo ago

Regs.gov: Privacy and Civil Liberties Oversight Board

Updated 1mo ago

Regs.gov: Information Security Oversight Office

Updated 1mo ago

Frequently asked questions

What does this feed cover?

CISA Known Exploited Vulnerabilities catalog, ICS-CERT industrial control system advisories, NSA/CISA joint alerts, NIST Cybersecurity Framework updates, FedRAMP authorization changes, and ENISA EU guidance.

Who is this for?

CISOs, SOC teams, and security compliance officers who need to track government cybersecurity directives and mandatory patching deadlines.

How often is this updated?

GovPing checks source pages multiple times daily. CISA KEV catalog additions are flagged as urgent.

Does this cover NIST framework updates?

Yes. We monitor NIST CSF, 800-series publications, and FedRAMP authorization pages.

Why are KEV additions flagged as urgent?

CISA's Known Exploited Vulnerabilities catalog carries binding operational directives for federal agencies, and most organizations treat it as a mandatory patch list. A new addition means active exploitation in the wild.

Is GovPing free?

Yes. GovPing is free, and always will be. We believe government regulatory data should be accessible to everyone. For custom monitoring of pages we don't cover yet, Changeflow starts at $99/mo.

Need to monitor something else?

GovPing covers the common sources. For niche pages specific to your team, add custom URL monitoring with Changeflow.

Get Cybersecurity alerts

Daily digest of cybersecurity regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.