LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
securitycritical

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian agencies meet the logging requir

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance, the Logging Reference Architecture (LRA), to help federal agencies improve their logging strategies. While primarily intended for federal civilian agencies to meet the requirements of OMB Memorandum M-26-14, CISA explicitly encourages critical infrastructure operators and other government organizations to adopt the LRA as a benchmark for their own logging and monitoring plans. The guidance, published in August 2026, emphasizes the practical usability of logs for detecting attacks and reconstructing incidents.

The LRA framework is structured around two key operational objectives: Continuous Event Monitoring (CEM) for near-real-time detection and response, and Threat Hunting, Investigation, Response, and Forensics (THIRF) for post-compromise analysis. CISA stresses that simply collecting logs is insufficient; the data must be timely, complete, reliable, and detailed enough to be useful during an actual incident. The LRA includes appendices that function as assessment tools, allowing organizations to evaluate the architectural soundness and practical effectiveness of their logging plans.

A significant aspect of the LRA is its guidance on log storage, which directly impacts cost and accessibility. It differentiates between data that needs to be immediately searchable for monitoring and hunting, data that can be moved to cheaper tiers while remaining retrievable for reconstruction, and data requiring immutable, evidentiary handling. The federal baseline suggests keeping data actively searchable for six months and retrievable for one year. The document cautions against making the Security Information and Event Management (SIEM) system the sole system of record, noting that ingesting all data into a single analytics platform can become costly and lead to data fidelity issues. Instead, it advocates for source-specific collection feeding into shared downstream processing.

The LRA also highlights the importance of treating logging infrastructure as a security-critical capability, as its compromise could blind detection, corrupt evidence, or undermine incident response. While acknowledging the benefits of centralized log storage for consistency and visibility, the guidance warns against designs that introduce delays, strip context, or create fragile chokepoints, suggesting that a more federated design with strong governance might be superior in such cases.

Regarding the use of artificial intelligence (AI) and machine learning (ML) in security operations, the LRA provides important guardrails. It stipulates that AI outputs should be considered derived data, not authoritative event records. Any actions with significant operational, legal, or privacy implications should remain subject to human review. The guidance advises agencies to maintain the relationship between original records and derived outputs, and to record sufficient metadata to support review, reproduction, and challenges of AI-generated results.

Federal agencies subject to OMB Memorandum M-26-14 are required to submit an Agency Logging Plan to the Office of Management and Budget and CISA within 90 days of the LRA's publication. This plan must detail how the agency will meet baseline requirements and identify areas where it intends to log beyond them. Agencies will then progress through a maturity model, aiming to reach an "Advanced" level within 320 days. CISA has committed to reviewing and updating the LRA at least annually to adapt to evolving threats and technologies.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.

vulnerabilityhigh

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

nation-state

Criminal Deception in Silicon Valley

Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En

security

Security vets rally around $4 paper password books for sale in Australia

Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026

breach

Personal Information Exposed in Apollo Global Data Breach

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek.

vulnerability

Rethinking Application Security for the AI Era

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek.