Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

First Voyage Raises $2.5M For Its Habit-Building AI Companion

Ford is launching a battery storage business to power data centers and the grid

Lightspeed raises record $9 billion in new capital

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Creative Commons announces trial support for ‘pay-to-crawl’ AI systems.

    15 December 2025

    TIME named “Architects of AI” Person of the Year

    15 December 2025

    Runway releases its first global model, adds native audio to latest video model

    14 December 2025

    OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

    14 December 2025

    Trump’s AI executive order promises ‘a rulebook’ – startups may find legal loophole instead

    13 December 2025
  • Apps

    Google’s ‘dark web reporting’ feature will no longer be available from February

    15 December 2025

    WhatsApp’s biggest market becomes the toughest test

    15 December 2025

    Google debuts ‘Disco’, a Gemini-powered tool for building web apps from browser tabs

    14 December 2025

    Google’s AI testing feature for clothes now only works with a selfie

    14 December 2025

    DoorDash driver faces felony charges after allegedly spraying customers’ food

    13 December 2025
  • Crypto

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025

    Only 5 days until Disrupt 2025 sets the startup world on fire

    22 October 2025
  • Fintech

    Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

    7 December 2025

    Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

    5 December 2025

    Nexus stays out of AI, keeping half of its new $700M fund for India startup

    4 December 2025

    Fintech firm Marquis notifies dozens of US banks and credit unions of data breach after ransomware attack

    3 December 2025

    Revolut hits $75 billion valuation in new capital raise

    24 November 2025
  • Hardware

    Nvidia is reportedly weighing increasing H200 production to meet growing demand in China

    15 December 2025

    Pebble founder unveils $75 AI smart ring to record short notes with the push of a button

    10 December 2025

    Amazon’s Ring launches controversial AI-powered facial recognition feature on video doorbells

    10 December 2025

    Google’s first AI glasses are expected next year

    9 December 2025

    eSIM adoption is on the rise thanks to travel and device compatibility

    6 December 2025
  • Media & Entertainment

    Understanding the Dangerous Netflix-Warner Bros. Deal

    15 December 2025

    Disney signs deal with OpenAI to allow Sora to create AI videos with its characters

    11 December 2025

    YouTube TV will launch genre-based subscription plans in 2026

    11 December 2025

    Founder of AI startup Tavus says users talk to AI Santa ‘for hours’ a day

    10 December 2025

    Spotify releases music videos in the US and Canada for Premium subscribers

    9 December 2025
  • Security

    The flaw in the photo booth manufacturer’s website exposes customers’ photos

    13 December 2025

    Home Depot exposed access to internal systems for a year, researcher says

    13 December 2025

    Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

    11 December 2025

    Petco takes down Vetco website after exposing customers’ personal information

    10 December 2025

    Petco’s security bug affected customers’ SSNs, driver’s licenses and more

    9 December 2025
  • Startups

    First Voyage Raises $2.5M For Its Habit-Building AI Companion

    15 December 2025

    Harness hits $5.5B valuation with $240M raise to automate AI’s ‘post-code’ divide

    15 December 2025

    Mesa shuts down credit card that rewards cardholders for paying their mortgages

    14 December 2025

    Port raises $100M valuation from $800M round to take on Spotify’s Backstage

    14 December 2025

    Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

    13 December 2025
  • Transportation

    Ford is launching a battery storage business to power data centers and the grid

    15 December 2025

    TechCrunch Mobility: Rivian’s survival plan involves more than cars

    14 December 2025

    India’s Spinny lines up $160m funding to acquire GoMechanic, sources say

    14 December 2025

    Inside Rivian’s big bet on self-driving with artificial intelligence

    13 December 2025

    Zevo wants to add robotaxis to its car-sharing fleet, starting with newcomer Tensor

    13 December 2025
  • Venture

    Lightspeed raises record $9 billion in new capital

    15 December 2025

    Runware raises $50 million in Series A to make it easier for developers to create images and videos

    12 December 2025

    Stanford’s star reporter understands Silicon Valley’s startup culture

    12 December 2025

    The market has “changed” and founders now have the power, VCs say

    11 December 2025

    Tiger Global plans cautious business future with new $2.2 billion fund

    8 December 2025
  • Recommended Essentials
TechTost
You are at:Home»Security»CISA says US government agency hacked thanks to ‘end of life’ software.
Security

CISA says US government agency hacked thanks to ‘end of life’ software.

techtost.comBy techtost.com10 December 202302 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Cisa Says Us Government Agency Hacked Thanks To 'end Of
Share
Facebook Twitter LinkedIn Pinterest Email

The US cybersecurity agency CISA has warned that unknown hackers broke into the servers of a federal government agency by exploiting a previously known vulnerability in software that no longer receives updates – meaning the agency could not fix it even if it wanted to.

On Tuesday, CISA has issued an advisory detailing two separate cyber attacks on an unnamed federal government agency. Hackers attacked the service in June and July by targeting publicly accessible servers running outdated or outdated Adobe ColdFusion software, which is used to build web applications.

End-of-life software means that the developer has publicly announced that it will no longer be supported or receive further software or security updates. Running software at end-of-life is by definition risky because it cannot be fixed, exposing the organization running the software to cyber-attacks.

Contact us

Do you have more information about these attacks? Or other attacks targeting government agencies? We would love to hear from you. Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or email at lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

CISA said there was no evidence the attackers planted malware or did more than look around the breached agency’s network.

“The analysis suggests that the malicious activity conducted by the threat actors was a reconnaissance effort to map the wider network,” but CISA admitted it could not confirm whether data from the agency’s network had been infiltrated.

CISA spokesman Antonio Soliz declined to comment when asked by TechCrunch for more information about who the agency believes are the hackers responsible for targeting the agency.

In the advisory, CISA said it did not know whether the two cyberattacks were carried out by the same hackers.

In both cyberattacks, Microsoft Defender for Endpoint, Windows’ native antivirus software, alerted the service to a possible exploit of the Adobe ColdFusion vulnerability and “quarantined” the hackers’ activities.

In March, CISA ordered all federal agencies to patch one of the known vulnerabilities in Adobe ColdFusion used in these attacks. CVE-2023-26360.

UPDATE, Dec. 6, 4:31 p.m. ET: This story was updated to include no comment from the CISA spokesperson.

Adobe agency CISA cyber security government hacked hacker Hacking infosec life software
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWith its second app, Amo wants to make sharing photos as simple as taking a photo
Next Article How to promote PaaS usage beyond 12-factor applications
bhanuprakash.cg
techtost.com
  • Website

Related Posts

The flaw in the photo booth manufacturer’s website exposes customers’ photos

13 December 2025

Interest in Spoor’s AI bird tracking software is soaring

13 December 2025

Home Depot exposed access to internal systems for a year, researcher says

13 December 2025
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

First Voyage Raises $2.5M For Its Habit-Building AI Companion

15 December 2025

Ford is launching a battery storage business to power data centers and the grid

15 December 2025

Lightspeed raises record $9 billion in new capital

15 December 2025
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

7 December 2025

Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

5 December 2025

Nexus stays out of AI, keeping half of its new $700M fund for India startup

4 December 2025
Startups

First Voyage Raises $2.5M For Its Habit-Building AI Companion

Harness hits $5.5B valuation with $240M raise to automate AI’s ‘post-code’ divide

Mesa shuts down credit card that rewards cardholders for paying their mortgages

© 2025 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.