(Pixabay) CISA’s secure-software buying tool had a simple XSS vulnerability of its own A researcher who discovered the vulnerability said it was fixed in December, after he first reported it to the agency in September. 24 hours ago By Tim Starks