#cisa

[ follow ]
#cybersecurity

The Royal ransomware group has rebranded - 'BlackSuit' has already made $500 million in ransom demands and has the FBI on red alert

The Royal ransomware operation has rebranded to BlackSuit, demanding large ransoms. Trend Micro identifies it as one of the most prolific digital extortion groups.

FBI and CISA Warn of BlackSuit Ransomware That Demands Up to $500 Million

Ransomware strain BlackSuit demands up to $500 million in ransoms, with individual demands reaching $60 million.

CISA breached a federal agency as part of its red team program - and nobody noticed for five months

A red team exercise by CISA exposed major security weaknesses in an unnamed federal agency's critical assets in 2023.

US updates telco security guidance after mass Chinese hack | Computer Weekly

CISA and allied agencies have issued a guide to strengthen cybersecurity measures for communications providers against advanced persistent threats from cyber actors.

CISA warns of hackers exploiting bug for end-of-life Ivanti product

The Ivanti Cloud Service Appliance 4.6 and below has a significant vulnerability that is actively exploited, necessitating urgent updates to CSA 5.0.

CISA names Lisa Einstein as its first chief AI officer

Lisa Einstein appointed as CISA's first Chief AI Officer to enhance cybersecurity with AI technologies.

The Royal ransomware group has rebranded - 'BlackSuit' has already made $500 million in ransom demands and has the FBI on red alert

The Royal ransomware operation has rebranded to BlackSuit, demanding large ransoms. Trend Micro identifies it as one of the most prolific digital extortion groups.

FBI and CISA Warn of BlackSuit Ransomware That Demands Up to $500 Million

Ransomware strain BlackSuit demands up to $500 million in ransoms, with individual demands reaching $60 million.

CISA breached a federal agency as part of its red team program - and nobody noticed for five months

A red team exercise by CISA exposed major security weaknesses in an unnamed federal agency's critical assets in 2023.

US updates telco security guidance after mass Chinese hack | Computer Weekly

CISA and allied agencies have issued a guide to strengthen cybersecurity measures for communications providers against advanced persistent threats from cyber actors.

CISA warns of hackers exploiting bug for end-of-life Ivanti product

The Ivanti Cloud Service Appliance 4.6 and below has a significant vulnerability that is actively exploited, necessitating urgent updates to CSA 5.0.

CISA names Lisa Einstein as its first chief AI officer

Lisa Einstein appointed as CISA's first Chief AI Officer to enhance cybersecurity with AI technologies.
morecybersecurity
#cyber-security

Microsoft calls on Trump to 'push harder' on cyber threats | Computer Weekly

Brad Smith urges the Trump administration to continue strong cyber security measures against state-sponsored threats from nations like Russia, China, and Iran.

Defaulting to open: Decoding the (very public) CrowdStrike event | Computer Weekly

The CrowdStrike IT outage raises questions about our dependence on certain organizations and their role in maintaining cyber security.

Microsoft calls on Trump to 'push harder' on cyber threats | Computer Weekly

Brad Smith urges the Trump administration to continue strong cyber security measures against state-sponsored threats from nations like Russia, China, and Iran.

Defaulting to open: Decoding the (very public) CrowdStrike event | Computer Weekly

The CrowdStrike IT outage raises questions about our dependence on certain organizations and their role in maintaining cyber security.
morecyber-security
#election-security

CISA Director releases statement on the security of the 2024 elections

The integrity of the 2024 elections has been affirmed as secure with no evidence of malicious activity impacting it.

OIG audit calls for more clarity from CISA, DHS on disinformation mission

CISA receives positive audit ratings for election security but has decreased disinformation efforts.

Forget AI: Physical threats are biggest risk facing the 2024 election

Physical threats to election administrators are a major concern overshadowing AI-related worries at the RSA Conference.

CISA moves away from trying to influence content moderation decisions on election disinformation

CISA is confident in the protection of U.S. election infrastructure for 2024, with improved security measures.

CISA has not clocked any 'national-level significant incidents' impacting the election, official says

CISA reports no significant threats to the security of today's presidential election.

CISA Director releases statement on the security of the 2024 elections

The integrity of the 2024 elections has been affirmed as secure with no evidence of malicious activity impacting it.

OIG audit calls for more clarity from CISA, DHS on disinformation mission

CISA receives positive audit ratings for election security but has decreased disinformation efforts.

Forget AI: Physical threats are biggest risk facing the 2024 election

Physical threats to election administrators are a major concern overshadowing AI-related worries at the RSA Conference.

CISA moves away from trying to influence content moderation decisions on election disinformation

CISA is confident in the protection of U.S. election infrastructure for 2024, with improved security measures.

CISA has not clocked any 'national-level significant incidents' impacting the election, official says

CISA reports no significant threats to the security of today's presidential election.
moreelection-security
#software-security

CISA official: AI tools 'need to have a human in the loop'

CISA is developing AI security initiatives, emphasizing the importance of human oversight in cybersecurity processes despite the hype around AI technology.

Software vendors are flocking to CISA's Secure by Design Pledge

More than 180 software companies have committed to CISA's Secure by Design Pledge to enhance product security by integrating security principles into the design and manufacturing process.

CISA official: AI tools 'need to have a human in the loop'

CISA is developing AI security initiatives, emphasizing the importance of human oversight in cybersecurity processes despite the hype around AI technology.

Software vendors are flocking to CISA's Secure by Design Pledge

More than 180 software companies have committed to CISA's Secure by Design Pledge to enhance product security by integrating security principles into the design and manufacturing process.
moresoftware-security

GSA awards contract for $524M CISA headquarters

GSA awarded a $524-million contract for a new CISA headquarters in Washington, D.C., funded in part by the Inflation Reduction Act.
from Theregister
4 months ago

Google gamed into advertising a malicious Authenticator

Scammers used Google ads to distribute fake Google Authenticator software.
AI technology is increasingly being used in cyber fraud, with AI-written emails accounting for 40% of BEC cases.
CISA appointed its first Chief AI Officer, indicating a growing focus on the threats posed by machine learning.

CISA names Lisa Einstein as its first chief AI officer

Lisa Einstein appointed as CISA's first chief AI officer to advance cyber defenses and critical infrastructure support through AI technologies.
#vulnerability

Federal agency warns critical Linux vulnerability being actively exploited

CISA added a critical Linux security bug, CVE-2024-1086, actively exploited, granting privilege escalation through a use-after-free vulnerability in Linux kernel versions 5.14-6.6.

0-click GitLab hijacking flaw under active exploit, with thousands still unpatched

A maximum severity vulnerability in GitLab allows account hijacking without user interaction.

Federal agency warns critical Linux vulnerability being actively exploited

CISA added a critical Linux security bug, CVE-2024-1086, actively exploited, granting privilege escalation through a use-after-free vulnerability in Linux kernel versions 5.14-6.6.

0-click GitLab hijacking flaw under active exploit, with thousands still unpatched

A maximum severity vulnerability in GitLab allows account hijacking without user interaction.
morevulnerability

Departing top CISA official reflects on nearly four years in the cyber hot seat

CISA has made progress in understanding cyber risks and collaborating with industry, but more work remains, including implementing a rule for gathering cyber incident data.
#cybersecurity-threats

How AI is turbocharging security issues

AI is empowering cybercriminals and making cybersecurity threats more sophisticated and widespread.

NCSC updates warning over hacktivist threat to CNI | Computer Weekly

Russia-backed hacktivist groups targeting critical infrastructure with unsophisticated attacks.
NCSC and CISA warning about evolving threats from hacktivist groups not officially backed by the Kremlin.

How AI is turbocharging security issues

AI is empowering cybercriminals and making cybersecurity threats more sophisticated and widespread.

NCSC updates warning over hacktivist threat to CNI | Computer Weekly

Russia-backed hacktivist groups targeting critical infrastructure with unsophisticated attacks.
NCSC and CISA warning about evolving threats from hacktivist groups not officially backed by the Kremlin.
morecybersecurity-threats

68 tech companies sign CISA's secure by design pledge

Tech giants sign CISA's Secure by Design pledge to enhance product security by committing to specific actions within a year.

Cloud Security Advice For Law Firms

Law firms are adopting a cloud-first mentality, but often overlook the importance of securing their cloud environment, leaving room for vulnerabilities.

CISA's KEV list improving private and public-sector patching

CISA's Known Exploited Vulnerabilities catalog deadlines are positively affecting private organizations' vulnerability remediation timeline.

CISA expects devs to squash old directory traversal bugs

CISA urges software industry to address directory traversal vulnerabilities.

House cyber chairman tries again to undo SEC cyber disclosure rules

Rep. Andrew Garbarino aims to dissolve SEC cybersecurity incident disclosure rule, favoring Cybersecurity and Infrastructure Security Agency for handling such disclosures.
[ Load more ]