US federal government security, live

The current federal picture in one place: CISA cybersecurity advisories as they publish, the Known Exploited Vulnerabilities that carry BOD 22-01 remediation due dates for federal civilian agencies, and how a Microsoft 365 tenant proves it meets the CISA SCuBA secure configuration baselines. Data refreshes twice a day from the primary sources.

SenservaSenserva Watch is free: alerts on the CVEs and patches you follow, and Three Free Unlimited Audits of every tenant you manage.Join Senserva Watch

Live government advisories

Pulled from the official feeds; refreshed twice a day.

Loading the live feed. If nothing appears, the feed updates on the next refresh; the official source links below always work.

What this means for a Microsoft 365 tenant

KEV due dates are patch deadlines

Under BOD 22-01, federal civilian agencies must remediate every CISA KEV entry by its due date. Our Microsoft patch tracker and non-Microsoft exploited CVE tracker carry those KEV flags and due dates on every row, and every tracked CVE has its own page.

SCuBA is the federal M365 baseline

CISA's Secure Cloud Business Applications (SCuBA) project defines the secure configuration baseline for federal Microsoft 365. Siemserva by Senserva maps its checks to every SCuBA policy, with a page per control in the control reference, so a scan doubles as baseline evidence.

CMMC and GCC for the defense industrial base

Federal contractors carry their own bar: CMMC 2.0 assessments and GCC / GCC High tenancy questions. See Senserva for federal: CMMC and GCC and the CMMC 2.0 guide. Every finding maps to the frameworks assessors ask about, with audit-ready evidence attached.