Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA BOD 22-01 iOS KEV patch order

Public Sector Action
First reported
Last updated
Happening score
H score 35
1 unique sources, 2 articles

Summary

Hide ▲

CISA ordered Federal Civilian Executive Branch agencies to secure affected iOS devices by March 26 after adding three Coruna vulnerabilities to its Known Exploited Vulnerabilities catalog. The directive matters because the flaws were linked to cyberespionage and crypto-theft activity, raising immediate federal remediation pressure. CISA also urged all organizations to patch the issues or stop using the product if fixes are unavailable.

Related Happenings

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

CISA zero-trust SASE guidance for TIC 3.0

Public Sector Action
H score30 First: 25.06.2026 14:30 Last: 25.06.2026 14:30 Sources 1

About this happening: CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...

CISA BOD 26-04 three-day remediation directive

Public Sector Action
H score36 First: 24.06.2026 17:35 Last: 24.06.2026 17:35 Sources 1

About this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...

Timeline

  1. 06.03.2026 17:57 2 articles · 4mo ago

    CISA adds three Coruna iOS flaws to KEV and orders federal patching

    Legal Policy Action Update

    CISA added three of the 23 Coruna iOS vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected devices by March 26 under Binding Operational Directive (BOD) 22-01. The directive followed reporting that the flaws were exploited in spyware and crypto-theft attacks using the Coruna exploit kit, and CISA urged all organizations to apply vendor mitigations or discontinue use if fixes are unavailable.

    Show sources