CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing the 10 most recent of 176 total events on this topic. apply a date range to scope the list.

range
iso 8601 utc
iso 8601 utc
01CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCsCISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastr{"url":"https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-…
EVENT. cms80kf0ID. cms80kf0fb27tkh0cblye5gacSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs",
  "cves": [],
  "slug": "cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs",
  "title": "CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs",
  "source": "cisa.gov",
  "excerpt": "CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.  These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems ",
  "cve_count": 0,
  "categories": [],
  "word_count": 500,
  "mentions_ics": false,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html",
    "https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology",
    "https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity",
    "https://www.epa.gov/cyberwater/forms/cybersecurity-technical-assistance-program-water-sector",
    "https://www.cisa.gov/about/regions"
  ],
  "mentions_ransomware": false
}
02o6 Automation open62541View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The foll{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08","cves":[…
EVENT. cms7u5hrID. cms7u5hrlb0atkh0czimu8pegSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
  "cves": [
    "CVE-2026-63362",
    "CVE-2026-65423",
    "CVE-2026-63035",
    "CVE-2026-63559"
  ],
  "slug": "icsa-26-211-08",
  "title": "o6 Automation open62541",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of o6 Automation open62541 are affected: open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.4.0|<=1.4.16 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux >=from_1.5.0|<=1.5.4 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) open62541 on Windows and Linux master (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559) CVSS Vendor Equipment Vulnerabilities v3 8.8 o6 Automation GmbH o6 Aut",
  "cve_count": 4,
  "categories": [],
  "word_count": 1101,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-63362",
    "https://www.o6-automation.com/contact",
    "https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f",
    "https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60"
  ],
  "mentions_ransomware": false
}
03Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications ModuleView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlL{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05","cves":[…
EVENT. cms7u5h8ID. cms7u5h81b0arkh0co106ti2cSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05",
  "cves": [
    "CVE-2026-9636"
  ],
  "slug": "icsa-26-211-05",
  "title": "Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected: ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636) CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636) GuardLogix 5580 >=V36|<=V37 (CVE-2026-9636) Compact GuardLogix 5380 >=V36|<=V37 (CVE-2026-9636) 1756-EN4TR V6.001 (CVE-2026-9636) 1756-EN4TR V7.001 (CVE-2026-9636) CVSS Vendor Equipment Vulnerabilities v3 5.9 Rockwell Automation Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module Improper Check for Certificate Revocation Background Critical Infrastructure Sectors: Critical Manufactur",
  "cve_count": 1,
  "categories": [],
  "word_count": 620,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-05.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-9636",
    "https://cwe.mitre.org/data/definitions/299.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
04MZ Automation lib60870View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893,{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11","cves":[…
EVENT. cms7u5gpID. cms7u5gpab0apkh0cim1binvuSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
  "cves": [
    "CVE-2026-61893",
    "CVE-2026-63033"
  ],
  "slug": "icsa-26-211-11",
  "title": "MZ Automation lib60870",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. View CVE Details Affected Products MZ Automation lib60870 V",
  "cve_count": 2,
  "categories": [],
  "word_count": 541,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-61893",
    "https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm",
    "https://cwe.mitre.org/data/definitions/125.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
  ],
  "mentions_ransomware": false
}
05MZ Automation GmbH libiec61850View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec6185{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10","cves":[…
EVENT. cms7u5g5ID. cms7u5g5rb0ankh0cedfr3l66SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
  "cves": [
    "CVE-2026-66720",
    "CVE-2026-66369",
    "CVE-2026-63550",
    "CVE-2026-65421",
    "CVE-2026-66364",
    "CVE-2026-66349",
    "CVE-2026-56758",
    "CVE-2026-66360"
  ],
  "slug": "icsa-26-211-10",
  "title": "MZ Automation GmbH libiec61850",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360) CVSS Vendor Equipment Vulnerabilities v3 7.5 MZ Automation GmbH MZ Automation GmbH libiec61850 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast m",
  "cve_count": 8,
  "categories": [],
  "word_count": 1339,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-66720",
    "https://cwe.mitre.org/data/definitions/125.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
06Johnson Controls OpenBlue EmployeeView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02","cves":[…
EVENT. cms7u5fnID. cms7u5fn1b0alkh0cu5dos5hdSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02",
  "cves": [
    "CVE-2026-21662",
    "CVE-2026-34495",
    "CVE-2026-34497"
  ],
  "slug": "icsa-26-211-02",
  "title": "Johnson Controls OpenBlue Employee",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and F",
  "cve_count": 3,
  "categories": [],
  "word_count": 1214,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-02.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-21662",
    "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
    "https://cwe.mitre.org/data/definitions/434.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
  ],
  "mentions_ransomware": false
}
07Watchfire Controller SoftwareView CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The foll{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09","cves":[…
EVENT. cms7u5f4ID. cms7u5f40b0ajkh0cw1cfsvi2SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09",
  "cves": [
    "CVE-2026-5846"
  ],
  "slug": "icsa-26-211-09",
  "title": "Watchfire Controller Software",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of Watchfire Controller Software are affected: BC550 12.30 (CVE-2026-5846) BC750 11.33|12.35 (CVE-2026-5846) BC760 12.38|13.00 (CVE-2026-5846) BC760DC 12.39 (CVE-2026-5846) CVSS Vendor Equipment Vulnerabilities v3 5.7 Watchfire Watchfire Controller Software Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador Company Headquarters Location: United States Vulnerabilities Exp",
  "cve_count": 1,
  "categories": [],
  "word_count": 625,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-5846",
    "https://cwe.mitre.org/data/definitions/321.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
    "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
  ],
  "mentions_ransomware": false
}
08Toptech Systems RCU II+ and Multiload II+View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The followin{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03","cves":[…
EVENT. cms7u5elID. cms7u5el2b0ahkh0cfoz9juyaSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03",
  "cves": [
    "CVE-2026-12562"
  ],
  "slug": "icsa-26-211-03",
  "title": "Toptech Systems RCU II+ and Multiload II+",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptech Systems RCU II+ and Multiload II+ are affected: RCU II+ <2025-11-24 (CVE-2026-12562) Multiload II+ <2025-11-24 (CVE-2026-12562) CVSS Vendor Equipment Vulnerabilities v3 8.8 Toptech Systems Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12562 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full ",
  "cve_count": 1,
  "categories": [],
  "word_count": 726,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12562",
    "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip",
    "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz",
    "https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/"
  ],
  "mentions_ransomware": false
}
09MikroTik RouterOSView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VP{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01","cves":[…
EVENT. cms7u5e2ID. cms7u5e2bb0afkh0ccyk0o5j1SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01",
  "cves": [
    "CVE-2026-14227"
  ],
  "slug": "icsa-26-211-01",
  "title": "MikroTik RouterOS",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic. The following versions of MikroTik RouterOS are affected: RouterOS vers:all/* (CVE-2026-14227) CVSS Vendor Equipment Vulnerabilities v3 4.9 MikroTik MikroTik RouterOS Insufficient Session Expiration Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia Vulnerabilities Expand All + CVE-2026-14227 An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This coul",
  "cve_count": 1,
  "categories": [],
  "word_count": 536,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-01.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-14227",
    "https://mikrotik.com/support",
    "https://cwe.mitre.org/data/definitions/613.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
  ],
  "mentions_ransomware": false
}
10Schneider Electric IGSSView CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","cves":[…
EVENT. cms7u5diID. cms7u5diqb0adkh0cctxev7hsSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04",
  "cves": [
    "CVE-2026-12927"
  ],
  "slug": "icsa-26-211-04",
  "title": "Schneider Electric IGSS",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system. The following versions of Schneider Electric IGSS are affected: IGSS () IGSS Definition (Def.exe) module vers:intdot/<=18.0.0.26124, 18.0.0.26125 () CVSS V",
  "cve_count": 1,
  "categories": [],
  "word_count": 1282,
  "mentions_ics": true,
  "published_at": "2026-07-30T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-04.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-12927",
    "https://igss.schneider-electric.com/igss/igssupdates/v180/IGSSUPDATE.ZIP",
    "https://cwe.mitre.org/data/definitions/787.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 176older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above