WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Supplemental Cyber Highlights – December 10, 2024
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Supplemental Cyber Highlights – December 10, 2024

Author: Chase Snow

Created: Tuesday, December 10, 2024 - 14:03

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

The following posts are useful for general awareness of current cyber threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience & OT Vulnerability Management

  • Bipartisan senators push for investigation into Pentagon’s cybersecurity failures after Chinese telecom networks hack | Industrial Cyber
  • November 2024’s Most Wanted Malware: Androxgh0st Leads the Pack, Targeting IoT Devices and Critical Infrastructure | Check Point
  • Cisco Says Flaws in Industrial Routers, BGP Tool Remain Unpatched 8 Months After Disclosure | SecurityWeek
  • Public and private sectors must partner to address generative AI’s interdependent energy and security requirements | Cyberscoop

IT Vulnerability Security Updates

  • Microsoft NTLM Zero-Day to Remain Unpatched Until April | Dark Reading
  • Critical OpenWrt Flaw Exposes Firmware Update Server to Exploitation | SecurityWeek
  • SAP Patches Critical Vulnerability in NetWeaver | SecurityWeek
  • MC LR Router and GoCast unpatched vulnerabilities | Cisco Talos

IT Malware, Threats & Risks

  • Chinese hackers use Visual Studio Code tunnels for remote access | Bleeping Computer
  • Ongoing Phishing and Malware Campaigns in December 2024 | The Hacker News

Ransomware

  • Unmasking Termite, the Ransomware Gang Claiming the Blue Yonder Attack | Infosecurity Magazine
  • Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering | The Hacker News

Cyber Resilience & General Awareness

  • Microsoft 365 outage takes down Office web apps, admin center | Bleeping Computer  
  • Microsoft Rolls Out Default NTLM Relay Attack Mitigations | SecurityWeek
  • Strengthening security posture with comprehensive cybersecurity assessments | Help Net Security

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar