#CISA

[ follow ]
critical-infrastructure
Theregister
4 days ago
Information security

CISA's ransomware warnings helped critical orgs fix 852 bugs

US government's CISA is actively assisting critical infrastructure organizations in addressing vulnerabilities exploited by ransomware gangs to prevent attacks. [ more ]
Theregister
3 days ago
Information security

CISA boss: Secure software needed to stop ransomware

Make software secure by design to combat ransomware attacks and enhance cybersecurity measures. [ more ]
ComputerWeekly.com
1 week ago
Information security

NCSC updates warning over hacktivist threat to CNI | Computer Weekly

Russia-backed hacktivist groups targeting critical infrastructure with unsophisticated attacks.
NCSC and CISA warning about evolving threats from hacktivist groups not officially backed by the Kremlin. [ more ]
CyberScoop
1 week ago
Information security

CISA's incident reporting requirements go too far, trade groups and lawmakers say

The draft rule for cyber incident reporting may be too burdensome for critical infrastructure entities and for the agency itself. [ more ]
CyberScoop
2 months ago
Privacy professionals

CISA releases 2024 priorities for the Joint Cyber Defense Collaborative

The Cybersecurity and Infrastructure Security Agency (CISA) has released the 2024 priorities for the Joint Cyber Defense Collaborative (JCDC).
The JCDC will focus on defending against advanced persistent threat (APT) operations, raising baseline protections for critical infrastructure, and anticipating emerging technology and risks. [ more ]
CyberScoop
3 months ago
Privacy professionals

CISA, FBI warns of Chinese-manufactured drones

The Cybersecurity and Infrastructure Security Agency and the FBI warn about potential threats from Chinese-made drones on critical infrastructure.
The guidance advises critical infrastructure owners and operators to reduce risk by purchasing drones from U.S. companies. [ more ]
morecritical-infrastructure
gitlab
ITPro
1 week ago
Information security

Hackers are exploiting critical GitLab password reset vulnerability - here's what you need to know

CISA warns of actively exploited GitLab vulnerability CVE-2023-7028, urging swift remediation to prevent potential account hijacking. [ more ]
Ars Technica
1 week ago
Information security

0-click GitLab hijacking flaw under active exploit, with thousands still unpatched

A maximum severity vulnerability in GitLab allows account hijacking without user interaction. [ more ]
moregitlab
vulnerabilities
Theregister
1 week ago
Information security

Federal frenzy to patch gaping security hole in GitLab

CISA mandates federal agencies to patch critical GitLab vulnerability under active exploitation. [ more ]
Therecord
2 months ago
Privacy professionals

CISA forced to take two systems offline last month after Ivanti compromise

Hackers breached CISA systems through Ivanti product vulnerabilities
CISA recommended incident response plans and system upgrades for resilience [ more ]
Nextgov.com
3 months ago
Information security

Agencies must disconnect all exposed Ivanti products by Friday, CISA says

CISA has directed federal agencies to disconnect from Ivanti products due to new security vulnerabilities.
China-linked hackers have attempted to exploit these vulnerabilities since at least December. [ more ]
CyberScoop
3 months ago
Information security

CISA issues emergency directive for federal agencies to patch Ivanti VPN vulnerabilities

The Cybersecurity and Infrastructure Security Agency issued an emergency directive for federal agencies to patch their systems against a zero-day exploit in a VPN software.
The vulnerabilities in the software were publicly released by the software company on Jan. 10, and so far, the campaign has impacted at least 2,100 devices worldwide. [ more ]
Databreaches
3 months ago
Information security

CISA pushes federal agencies to patch Citrix RCE within a week

CISA ordered US federal agencies to secure their systems against recently patched Citrix NetScaler and Google Chrome zero-days.
Citrix urged customers to immediately patch vulnerable systems against code injection and buffer overflow vulnerabilities. [ more ]
Dark Reading
5 months ago
Information security

Exploited Vulnerabilities Can Take Months to Make KEV List

CISA added known software flaws to its KEV catalog months after they were disclosed and exploited.
The delayed updates to the KEV catalog can hinder security teams' patching efforts and put organizations at risk.
The examples of Adobe, Juniper, and Veeam demonstrate the long lead time for vulnerabilities to be included in the KEV catalog. [ more ]
morevulnerabilities
ransomware
Databreaches
2 months ago
Privacy technologies

CISA Alert CodeAA23-353A: ALPHV BlackCat

#StopRansomware advisories provide TTPs and IOCs to help organizations protect against ransomware.
ALPHV Blackcat ransomware targeting healthcare sector since mid-December 2023. [ more ]
Theregister
5 months ago
Privacy professionals

Royal ransomware may soon rebrand, BlackSuit links confirmed

The FBI and CISA have released guidance on the Royal ransomware operation, suggesting it may undergo a rebrand.
Rebranding in the ransomware industry is common as groups try to evade law enforcement attention.
There are similarities between Royal and BlackSuit ransomware, indicating a potential rebrand or spinoff variant. [ more ]
moreransomware
fbi
BleepingComputer
3 months ago
Information security

CISA: Vendors must secure SOHO routers against Volt Typhoon attacks

CISA and the FBI are urging manufacturers of small office/home office (SOHO) routers to enhance their security against attacks by state-backed hacking groups like Volt Typhoon.
The agencies are advising vendors to eliminate vulnerabilities in router web management interfaces during the design and development stages. [ more ]
TechRepublic
3 months ago
Privacy professionals

Androxgh0st Malware Botnet Steals AWS, Microsoft Credentials and More

The Androxgh0st malware is a botnet that collects cloud credentials and abuses the Simple Mail Transfer Protocol.
The malware targets websites using the Laravel web application framework to steal credentials and other sensitive data. [ more ]
morefbi
Theregister
5 days ago
Information security

CISA expects devs to squash old directory traversal bugs

CISA urges software industry to address directory traversal vulnerabilities. [ more ]
Theregister
2 days ago
Information security

68 tech companies sign CISA's secure by design pledge

Tech giants sign CISA's Secure by Design pledge to enhance product security by committing to specific actions within a year. [ more ]
Theregister
4 days ago
Information security

CISA's KEV list improving private and public-sector patching

CISA's Known Exploited Vulnerabilities catalog deadlines are positively affecting private organizations' vulnerability remediation timeline. [ more ]
CyberScoop
4 days ago
Information security

Krebs, Luber added to Cyber Safety Review Board

Chris Krebs and David Luber are among four new additions to the Cyber Safety Review Board, contributing their cybersecurity expertise. [ more ]
Above the Law
4 days ago
Information security

Cloud Security Advice For Law Firms

Law firms are adopting a cloud-first mentality, but often overlook the importance of securing their cloud environment, leaving room for vulnerabilities. [ more ]
CyberScoop
1 day ago
Information security

Forget AI: Physical threats are biggest risk facing the 2024 election

Physical threats to election administrators are a major concern overshadowing AI-related worries at the RSA Conference. [ more ]
Axios
1 day ago
Artificial intelligence

How AI is turbocharging security issues

AI is empowering cybercriminals and making cybersecurity threats more sophisticated and widespread. [ more ]
www.securityweek.com
5 months ago
Artificial intelligence

CISA Outlines AI-Related Cybersecurity Efforts

CISA has published a roadmap to promote the use of AI in cybersecurity and support critical infrastructure organizations.
The roadmap emphasizes the need for security practices in AI systems and encourages AI system makers to follow secure-by-design principles.
CISA plans to integrate AI across its systems to defend against cyber threats and protect critical infrastructure. [ more ]
Nextgov.com
5 months ago
Artificial intelligence

CISA releases roadmap to guide its AI efforts

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a Roadmap for Artificial Intelligence (AI) to establish levels of regulation within machine learning technologies.
The roadmap focuses on five lines of effort: responsibly using AI to support missions, assuring the safety of AI systems, protecting critical infrastructure from malicious use of AI, collaborating with partners, and expanding AI expertise within the agency's workforce.
CISA plans to assess the state of AI adoption, establish AI policy positions, and improve its workforce through recruitment and training. [ more ]
CyberScoop
1 week ago
Information security

How to fine-tune the White House's new critical infrastructure directive

Biden administration updated federal infrastructure protection policy via NSM-22, linking it to modern cyber threat landscape, but fell short by not including space and cloud industries. [ more ]
Nextgov.com
1 week ago
Information security

House cyber chairman tries again to undo SEC cyber disclosure rules

Rep. Andrew Garbarino aims to dissolve SEC cybersecurity incident disclosure rule, favoring Cybersecurity and Infrastructure Security Agency for handling such disclosures. [ more ]
CyberScoop
1 week ago
Information security

Easterly appeals to Congress on CISA funding, citing Chinese threats to critical infrastructure

More funding is crucial for CISA to enhance cybersecurity defense, particularly against Chinese hackers in critical infrastructure. [ more ]
WIRED
1 week ago
Information security

The US Government Is Asking Big Tech to Promise Better Cybersecurity

The pledge offers flexibility to companies in meeting goals but emphasizes public progress and sharing techniques. [ more ]
CyberScoop
2 weeks ago
Information security

CISA ransomware warning program set to fully launch by end of 2024

CISA plans to launch automated vulnerability warning program to reduce ransomware attacks through patching vulnerabilities. [ more ]
Theregister
4 weeks ago
Deliverability

Microsoft breach allowed Russia to steal Feds' emails

CISA warns Russian spies stole sensitive data from Microsoft's email system; agencies need immediate remedial action. [ more ]
The Verge
1 month ago
Privacy professionals

Cyberattacks are targeting US water systems, warns EPA and White House

Water and wastewater systems are vulnerable to cyberattacks due to lack of resources for cybersecurity practices.
Biden administration urges states to enhance security measures for critical water infrastructure against disabling cyberattacks. [ more ]
Theregister
1 month ago
Privacy professionals

Biden's budget proposal boosts CISA's funding to $3b

Biden proposes $103 million extra for CISA
Budget focuses on cybersecurity enhancements and resources for federal agencies [ more ]
ComputerWeekly.com
2 months ago
Privacy professionals

New version of ALPHV/BlackCat ransomware hits victims | Computer Weekly

CISA issued advisory on ALPHV/BlackCat ransomware targeting US healthcare sector
New ALPHV/BlackCat version with advanced capabilities like targeting VMware environments [ more ]
Nextgov.com
3 months ago
Privacy professionals

Contracts featuring automation, built-in security can boost agencies' cyber defenses, VA officials say

Automating legacy systems and prioritizing built-in security in contracts can enhance cyber resilience at federal agencies.
The Department of Veterans Affairs oversees a significant portion of IT assets in the federal civilian space and relies on CISA for cybersecurity implementation. [ more ]
CyberScoop
3 months ago
Privacy professionals

CISA orders Ivanti devices targeted by Chinese hackers be disconnected

Federal agencies running Ivanti Connect Secure or Ivanti Policy Secure devices must disconnect them due to cyber espionage linked to China.
CISA has issued instructions for updating and bringing the devices back online. [ more ]
Nextgov.com
3 months ago
Privacy professionals

Biden to veto any efforts to shutter SEC cyber disclosure rules

The White House reaffirmed its commitment to a SEC rule on cybersecurity disclosures and stated that President Biden would veto any efforts to eliminate the regulation.
Lawmakers both in the Senate and the House have proposed measures to nullify the SEC rule, arguing that disclosing cyber incidents could compromise businesses and national security. [ more ]
Databreaches
5 months ago
Information security

Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors.
The vulnerability (CVE-2023-26360) allows for arbitrary code execution and affects ColdFusion 2018 and ColdFusion 2021 versions. [ more ]
Theregister
5 months ago
Information security

CISA finally removes dud vulnerability from must-patch list

CISA has removed a security vulnerability (CVE-2022-28958) from its Known Exploited Vulnerability catalog after it was found to be a fake vulnerability.
The vulnerability was thought to be a critical remote code execution flaw but had no impact on the systems it targeted. [ more ]
Theregister
5 months ago
Information security

CISA reveals how fed agency succumbed to ColdFusion attacks

A federal agency had at least two public-facing servers compromised by attackers exploiting a critical Adobe ColdFusion vulnerability.
The agency failed to patch the vulnerability for more than three months after the deadline set by CISA. [ more ]
Dark Reading
5 months ago
DevOps

CISA Launches Pilot Program to Address Critical Infrastructure Threats

CISA is launching a pilot program to provide cybersecurity services to critical infrastructure entities in need.
The pilot program is a response to the increasing volume and impact of cyberattacks on critical infrastructure organizations.
CISA plans to expand the pilot program to include 100 different entities across sectors this year. [ more ]
Dark Reading
5 months ago
Privacy professionals

Scattered Spider Casino Hackers Evade Arrest in Plain Sight

The cybercrime group known as Scattered Spider is still operating and attacking US organizations despite being known to law enforcement for over six months.
Law enforcement's failure to make arrests or disrupt the group's activities is seen as a failure in cybersecurity law enforcement.
The FBI and CISA have released an advisory on Scattered Spider, providing recommendations for organizations to improve their cybersecurity posture. [ more ]
www.databreaches.net
5 months ago
Public health

CISA Releases The Mitigation Guide: Healthcare and Public Health (HPH) Sector

CISA has released a mitigation guide for the Healthcare and Public Health sector to combat cyber threats.
The guide provides defensive mitigation strategy recommendations and identifies known vulnerabilities for organizations to assess their networks.
HPH entities are encouraged to visit CISA's Healthcare and Public Health Cybersecurity Toolkit and Sector webpages for more information. [ more ]
SecurityWeek
5 months ago
Information security

CISA Warns of Attacks Exploiting Sophos Web Appliance Vulnerability

CISA added Sophos, Oracle, and Microsoft product flaws to its Known Exploited Vulnerabilities catalog.
The Sophos flaw CVE-2023-1671 is a critical vulnerability that can be exploited for arbitrary code execution.
CVE-2020-2551 is an Oracle WebLogic Server flaw targeted by a Chinese threat actor in attacks on government and critical infrastructure organizations in Taiwan. [ more ]
Nextgov.com
5 months ago
Privacy professionals

CISA, FBI warn of social engineering-based ransomware

Scattered Spider, a cybercriminal group, is targeting large U.S. corporations with ransomware exploits.
The FBI and CISA have issued a joint advisory warning organizations not to pay the ransom.
Paying a ransom following a data breach is contrary to law enforcement guidance and could incentivize hackers to target the same victims. [ more ]
Nextgov.com
5 months ago
Privacy professionals

CISA turns 5 and looks to the future

The Cybersecurity and Infrastructure Security Agency (CISA) was launched as the federal government's go-to cyber policy and incident response shop.
CISA was formed from the old National Protection and Programs Directorate at the Department of Homeland Security.
CISA has experienced significant growth in staff and funding in recent years. [ more ]
[ Load more ]