we_are_coded.by CODE · The world, decoded
БГ
Who's who

CISA

The BasicsUpdated on 16 August 2026we are coded

CISA is the US agency that keeps an official list of software holes with proof that someone is already using them to attack people and companies. See that abbreviation under a story, and you know we're not talking theory, but something happening right now, somewhere.

Checked on16 August 2026
In short: CISA is a US government agency for cybersecurity. It tracks which holes in computer programs are already being used by attackers, not in theory but in practice, and puts them on a public list. If something makes that list, it means not "maybe dangerous" but "someone is doing it right now". So when you see CISA cited under a story, know this: it's an official source, not a forum rumor.

The full name is the Cybersecurity and Infrastructure Security Agency. It's part of the US Department of Homeland Security.

Imagine you're a doctor and you get two kinds of bulletin from the health authorities. One says: "this disease theoretically exists somewhere in the world." The other says: "this disease already has confirmed cases in your neighborhood, here are the addresses." The second bulletin is the one you actually drop everything else to read. CISA does exactly this, but for software. Their list is called KEV. That's short for Known Exploited Vulnerabilities catalog, literally: a catalog of holes already in use. Only cases with proven attacks make it in, not hypotheses.

The difference matters. Every year, researchers around the world painstakingly find and document thousands of holes in software. Almost nobody but their author pays attention to most of them. CISA doesn't report on all that noise. Only the case where it's already proven that someone specific went through exactly this hole makes it in. So the list isn't reading material for the curious. It's a list of the doors currently actually being kicked.

The difference between "theoretically dangerous" and "CISA said it's already under attack" is the difference between suspecting an illness and a confirmed diagnosis.

Look at it the other way

CISA is more like a doctor declaring an epidemic than a weatherman making a forecast. It's not "you might get sick" here, it's "there are already confirmed cases, here are the addresses". So when we cite CISA under a breach story here at we are coded, we're not doing it for weight of prose. We're doing it because it means someone specific, proven, has already caught the infection through exactly this gap. But software has no borders. The agency is American, but the infection it flags is the same in software used by a Bulgarian company or shop. If your neighborhood drinks from the same tap, the infection is already yours too.

The visual is generated code art. No third-party images.
Official primary sources
→CISA: About CISA (official page)

Everything we have written

39 stories

October 20263 stories

September 202618 stories

August 20268 stories

July 20268 stories

June 20262 stories