{"id":52543,"date":"2023-06-28T15:54:56","date_gmt":"2023-06-28T15:54:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34761\/Hundreds-Of-Federal-Network-Devices-Fail-New-CISA-Requirements.html"},"modified":"2023-06-28T15:54:56","modified_gmt":"2023-06-28T15:54:56","slug":"hundreds-of-federal-network-devices-fail-new-cisa-requirements","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/","title":{"rendered":"Hundreds Of Federal Network Devices Fail New CISA Requirements"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/security-weakness.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>U.S. federal agencies are running hundreds of remotely accessible management interfaces that don\u2019t meet recently mandated security requirements, according to Censys researchers.<\/p>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) issued a <a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/binding-operational-directive-23-02\" target=\"_blank\" rel=\"noreferrer noopener\">Binding Operational Directive (BOD) 23-02<\/a> &nbsp;on June 13 requiring all federal civilian executive branch (FCEB) agencies to harden their internet-exposed network edge and remote management devices.<\/p>\n<p>\u201cRecent threat campaigns underscore the grave risk to the federal enterprise posed by improperly configured network devices,\u201d <a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/binding-operational-directive-23-02\" target=\"_blank\" rel=\"noreferrer noopener\">the directive states<\/a>.<\/p>\n<p>It requires FCEB agencies to remove from the internet all management interfaces using network protocols \u2013 including HTTP\/ HTTPS, FTP, SSH, Telnet, and others \u2013 so they are only accessible from an internal enterprise network.<\/p>\n<p>Removal must be undertaken within 14 days of the agency identifying a management interface that falls into the category of devices covered by the directive. Agencies also have a fortnight to implement changes if they receive a notification from CISA, which announced in March it was beefing up plans to proactively <a href=\"https:\/\/www.scmagazine.com\/news\/vulnerability-management\/cisa-scans-critical-infrastructure-bugs-ransomware\">alert agencies<\/a> of attack surface vulnerabilities.<\/p>\n<h2>Numerous hosts exposing network appliances<\/h2>\n<p>In a <a href=\"https:\/\/censys.io\/identifying-cisa-bod-23-02-internet-exposed-networked-management-interfaces-with-censys\/\">June 26 blog post<\/a>, Censys said its researchers analyzed the attack surfaces of more than 50 organizations and sub-organizations covered by the directive. They found over 13,000 distinct hosts across more than 100 autonomous systems associated with FCEB agencies.<\/p>\n<p>\u201cExamining the services running on a subset of over 1,300 FCEB hosts accessible via IPv4 address, Censys found hundreds of publicly exposed devices within the scope outlined in the directive,\u201d the post said.<\/p>\n<p>The researchers found almost 250 instances of web interfaces for hosts exposing network appliances, many of which were running remote protocols, including SSH and Telnet.<\/p>\n<p>\u201cAmong these were various Cisco network devices with exposed Adaptive Security Device Manager interfaces, enterprise Cradlepoint router interfaces exposing wireless network details, and many popular firewall solutions such as Fortinet Fortiguard and SonicWall appliances.\u201d<\/p>\n<p>More than 15 instances of other exposed remote access protocols including FTP, SMB, NetBIOS, and SNMP were also found running on FCEB-related hosts.<\/p>\n<p>\u201cThese protocols have a history of security vulnerabilities, and exposing them to the internet raises the risk of being targeted by threat actors trying to gain remote unauthorized access to government infrastructure,\u201d the researchers said.<\/p>\n<p>They also found \u201cmultiple\u201d out-of-band remote server management devices including Lantronix SLC console servers. <a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/binding-operational-directive-23-02-implementation-guidance\" target=\"_blank\" rel=\"noreferrer noopener\">According to CISA<\/a>, such out-of-band interfaces \u201cshould never be directly accessible via the public internet\u201d.<\/p>\n<h2>Other vulnerabilities discovered<\/h2>\n<p>The researchers said they discovered \u201cother noteworthy security concerns\u201d which fell outside the scope of the Binding Operational Directive on the hosts they investigated.<\/p>\n<p>Among the finds were several instances of exposed managed file transfer tools including <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/after-goanywhere-mft-hack-hhs-again-warns-of-clop-ransomware-threat\" target=\"_blank\" rel=\"noreferrer noopener\">MOVEit Transfer<\/a> and <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/after-goanywhere-mft-hack-hhs-again-warns-of-clop-ransomware-threat\" target=\"_blank\" rel=\"noreferrer noopener\">GoAnywhere MFT<\/a>, both of which have been at the center of recent serious breaches.<\/p>\n<p>More than 10 hosts were discovered running HTTP services exposing directory listings of file systems, which Censys said was a common source of sensitive data leakage.<\/p>\n<p>The researchers discovered exposed Nessus vulnerability scanning servers, an attractive target for threat actors because they pinpoint weaknesses in internal networks, providing attackers with useful intelligence and a springboard for future exploitations.<\/p>\n<p>Censys also found exposed <a href=\"https:\/\/www.scmagazine.com\/news\/asset-management\/china-linked-espionage-actor-blamed-for-global-barracuda-esg-attacks\" target=\"_blank\" rel=\"noreferrer noopener\">Barracuda Email Security Gateway<\/a> appliances, the target of another recent spate of high-profile and costly attacks.<\/p>\n<p>Over 150 instances of end-of-life software were discovered, including Microsoft Internet Information Services (IIS), OpenSSL, and Exim. \u201cEnd-of-life software is more susceptible to new vulnerabilities and exploits because it no longer receives security updates, making it an easy target,\u201d the researchers said.<\/p>\n<p>Censys said while CISA\u2019s directive only applied to FCEB agencies, all organizations should harden the interfaces within their networks, given they were often targeted by threat actors.<\/p>\n<p>\u201cThese internet-exposed devices have long been the low-hanging fruit for threat actors to gain unauthorized access to important assets, and it\u2019s encouraging that the federal government is taking this step to proactively improve their overall security posture and those of their adjacent systems.\u201d<\/p>\n<h2>How widespread is the problem and how hard is the fix?<\/h2>\n<p>The BOD more specifically will force Federal agencies to adopt a more comprehensive external attack surface management (EASM) strategy. External attack surfaces are a major source of breaches, exposing insecure or misconfigured APIs, IoT devices and under-patched servers to adversaries.<\/p>\n<p>Rob Gurzeev, CEO and co-founder of attack surface management firm <a rel=\"noreferrer noopener\" href=\"http:\/\/www.cycognito.com\/\" target=\"_blank\">CyCognito<\/a>, points out that the directive will have a far-reaching impact beyond just FCEB agencies. Non-governmental supply chain partners will also be under increased scrutiny for external attack surface weak spots. These third-party risks or subsidiary risks are often the overlooked weakest link in a <a rel=\"noreferrer noopener\" href=\"https:\/\/website-assets.cycognito.com\/cms\/Reports\/CyCognito-Executive-Brief-External-Attack-Surface-Management-solutions-Web.pdf\" target=\"_blank\">tightly managed enterprise network<\/a> (PDF).<\/p>\n<p>\u201cBig companies have tens of thousands of exposed web interfaces&nbsp;today, as every DevOps tool, OpenSource tool, and even hardware assets have web interfaces for management now,\u201d Gurzeev said. \u201cThe shift to the cloud&nbsp;essentially connected millions of \u2018machines\u2019 to the internet &#8211; not behind a firewall.\u201d<\/p>\n<p>Gurzeev said that despite the fact that the bulk of an organization\u2019s network infrastructure is behind a firewall, 80 percent of the network risk is found within the external attack surface, exposed to the public internet. Wors, he said, external surface vulnerabilities can take ten-times longer to detect and mitigate. \u201cAdditionally, dwell time\u2014the period from breach to mitigation\u2014averages three to four months, and can sometimes stretch to six,\u201d he said.<\/p>\n<h2>BOD 23-02: Directive Details<\/h2>\n<p>The directive mandates agencies regularly scan and report the security readiness of internet-facing devices to CISA. It also requires agencies to fix found issues within 14 days of finding or being notified of them. If a patch isn\u2019t immediately available, then CISA requires agencies to isolate or ban outside access to resources.<\/p>\n<div>\n<ul>\n<li>The CISA mandate also includes:<\/li>\n<li>Comprehensive asset inventory<\/li>\n<li>A vulnerability management<\/li>\n<li>Blueprint for incident response<\/li>\n<li>Mitigation based on risk and compliance<\/li>\n<\/ul>\n<\/div>\n<p>Lastly, agencies must layer Zero Trust Architecture technology into managed networks identified by CISA.&nbsp;<\/p>\n<p>\u201cWhile this new mandate impacts agencies directly, it also impacts their supply chain partners as well,\u201d wrote Pablo Quiroga, director of product management, at Qualys in a <a href=\"https:\/\/blog.qualys.com\/qualys-insights\/2023\/06\/14\/qualys-responds-to-cisa-alert-binding-operational-directive-23-02\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a> responding to the directive.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34761\/Hundreds-Of-Federal-Network-Devices-Fail-New-CISA-Requirements.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52544,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[6978],"class_list":["post-52543","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinegovernmentusaflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-28T15:54:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/security-weakness.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hundreds Of Federal Network Devices Fail New CISA Requirements\",\"datePublished\":\"2023-06-28T15:54:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/\"},\"wordCount\":1002,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg\",\"keywords\":[\"headline,government,usa,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/\",\"name\":\"Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg\",\"datePublished\":\"2023-06-28T15:54:56+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg\",\"width\":800,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,government,usa,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinegovernmentusaflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hundreds Of Federal Network Devices Fail New CISA Requirements\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/","og_locale":"en_US","og_type":"article","og_title":"Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-28T15:54:56+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/security-weakness.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hundreds Of Federal Network Devices Fail New CISA Requirements","datePublished":"2023-06-28T15:54:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/"},"wordCount":1002,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg","keywords":["headline,government,usa,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/","url":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/","name":"Hundreds Of Federal Network Devices Fail New CISA Requirements 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg","datePublished":"2023-06-28T15:54:56+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/hundreds-of-federal-network-devices-fail-new-cisa-requirements.jpg","width":800,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hundreds-of-federal-network-devices-fail-new-cisa-requirements\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,government,usa,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinegovernmentusaflaw\/"},{"@type":"ListItem","position":3,"name":"Hundreds Of Federal Network Devices Fail New CISA Requirements"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52543","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52543"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52543\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52544"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}