The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian agencies meet the logging requir

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance, the Logging Reference Architecture (LRA), to help federal agencies improve their logging strategies. While primarily intended for federal civilian agencies to meet the requirements of OMB Memorandum M-26-14, CISA explicitly encourages critical infrastructure operators and other government organizations to adopt the LRA as a benchmark for their own logging and monitoring plans. The guidance, published in August 2026, emphasizes the practical usability of logs for detecting attacks and reconstructing incidents.
The LRA framework is structured around two key operational objectives: Continuous Event Monitoring (CEM) for near-real-time detection and response, and Threat Hunting, Investigation, Response, and Forensics (THIRF) for post-compromise analysis. CISA stresses that simply collecting logs is insufficient; the data must be timely, complete, reliable, and detailed enough to be useful during an actual incident. The LRA includes appendices that function as assessment tools, allowing organizations to evaluate the architectural soundness and practical effectiveness of their logging plans.
A significant aspect of the LRA is its guidance on log storage, which directly impacts cost and accessibility. It differentiates between data that needs to be immediately searchable for monitoring and hunting, data that can be moved to cheaper tiers while remaining retrievable for reconstruction, and data requiring immutable, evidentiary handling. The federal baseline suggests keeping data actively searchable for six months and retrievable for one year. The document cautions against making the Security Information and Event Management (SIEM) system the sole system of record, noting that ingesting all data into a single analytics platform can become costly and lead to data fidelity issues. Instead, it advocates for source-specific collection feeding into shared downstream processing.
The LRA also highlights the importance of treating logging infrastructure as a security-critical capability, as its compromise could blind detection, corrupt evidence, or undermine incident response. While acknowledging the benefits of centralized log storage for consistency and visibility, the guidance warns against designs that introduce delays, strip context, or create fragile chokepoints, suggesting that a more federated design with strong governance might be superior in such cases.
Regarding the use of artificial intelligence (AI) and machine learning (ML) in security operations, the LRA provides important guardrails. It stipulates that AI outputs should be considered derived data, not authoritative event records. Any actions with significant operational, legal, or privacy implications should remain subject to human review. The guidance advises agencies to maintain the relationship between original records and derived outputs, and to record sufficient metadata to support review, reproduction, and challenges of AI-generated results.
Federal agencies subject to OMB Memorandum M-26-14 are required to submit an Agency Logging Plan to the Office of Management and Budget and CISA within 90 days of the LRA's publication. This plan must detail how the agency will meet baseline requirements and identify areas where it intends to log beyond them. Agencies will then progress through a maturity model, aiming to reach an "Advanced" level within 320 days. CISA has committed to reviewing and updating the LRA at least annually to adapt to evolving threats and technologies.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed