DHS, CISA, and FEMA announce over $100 million in funding for cybersecurity infrastructure improvements.

DHS, CISA, and FEMA announce over $100 million in funding for cybersecurity infrastructure improvements.

he United States Department of Homeland Security (DHS), in partnership with the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Emergency Management Agency (FEMA), has announced more than $100 million in new funding dedicated to strengthening the cybersecurity infrastructure of state, local, and tribal governments.
CISA releases Sandia Lab’s Thorium malware analysis and digital forensics platform as open source.

CISA releases Sandia Lab’s Thorium malware analysis and digital forensics platform as open source.

The Cybersecurity and Infrastructure Security Agency (CISA) has recently taken a significant step forward in the fight against digital threats by open-sourcing the Thorium platform. Developed in collaboration with Sandia National Laboratories, Thorium is designed to automate and streamline the process of malware analysis and digital forensics, providing cybersecurity teams with a powerful, scalable solution for modern threat detection and response.
CISA adds four known exploited vulnerabilities to the KEV catalog.

CISA adds four known exploited vulnerabilities to the KEV catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four additional security vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, following evidence of active exploitation in the wild. The inclusion of these vulnerabilities underscores the urgent need for all organizations—particularly federal agencies—to assess exposure and apply necessary mitigations or patches.
CISA Advisory – Ransomware actors exploiting unpatched SimpleHelp Remote Monitoring and Management software.

CISA Advisory – Ransomware actors exploiting unpatched SimpleHelp Remote Monitoring and Management software.

CISA Cybersecurity Advisory AA25-163A, released on June 12, 2025, addresses a significant ransomware threat exploiting unpatched vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) software. The advisory was prompted by incidents in which ransomware actors compromised customers of a utility billing software provider by leveraging these vulnerabilities.