WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Supplemental Cyber Highlights – November 9, 2023
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Supplemental Cyber Highlights – November 9, 2023

Author: April Zupan

Created: Thursday, November 9, 2023 - 16:06

Categories: Cybersecurity

The following posts are useful for general awareness of current threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure Resilience

  • SBOMs’ Role in Helping to Protect ICS (ISS Source)
  • Machine Learning Aids Water Treatment Monitoring (ISS Source)
  • Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology (Mandiant)

IT Vulnerabilities, Malware & Threats

  • Atlassian Bug Escalated to 10, All Unpatched Instances Vulnerable (Dark Reading)
  • New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers (The Hacker News)
  • A Hole in the (fire) Wall: Check Point Research reveals technique allowing attackers to bypass Firewall rules designed to stop NTLM credential thefts, and provides protection methods (Check Point)
  • October 2023’s Most Wanted Malware: NJRat Jumps to Second Place while AgentTesla Spreads through new File Sharing Mal-Spam Campaign (Check Point)
  • Quishing Campaigns Spike 50% in September (Infosecurity Magazine)
  • The Truth Crisis | The Rising Threat of Online Misinformation and Disinformation (Sentinel One)

Ransomware

  • Dallas County reviewing data leaked by ransomware gang (The Record)

Cyber Resilience

  • Zero Day Threat Protection for Your Network (Trend Micro)
  • When Email Security Meets SaaS Security: Uncovering Risky Auto-Forwarding Rules (The Hacker News)
  • Key questions to ask when evaluating an identity and access security vendor (SC Magazine)

General Awareness

  • 3 Things to Know about Vishing (Cofense)
  • Microsoft Authenticator now blocks suspicious MFA alerts by default (Bleeping Computer)
  • Sumo Logic discloses security breach, advises API key resets (Bleeping Computer)

Technical Posts (for security analysts, sysadmins, and other nerds)

  • Threat Actors Leverage File-Sharing Service and Reverse Proxies for Credential Harvesting (Trend Micro)

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Zero-Day Vulnerability in Microsoft Exchange Under Active Exploitation, CVE-2026-42897

May 19, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability Affecting Cisco Catalyst SD-WAN, CVE-2026-20182

May 19, 2026 in Cybersecurity, Security Preparedness

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar