You are here

Cybersecurity

Microsoft Uncovers Diamond Sleet's Supply Chain Attack with LambLoad Malware

According to a new blog post by Microsoft, a North Korean-based threat actor dubbed Diamond Sleet has been observed distributing a malicious variant of a legitimate application installer developed by CyberLink Corp. to target customers in a supply chain attack. For its part, the trojanized file, which is hosted on CyberLink’s update infrastructure, includes malicious code that is designed to download, decrypt, and load a second-stage payload.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – November 28, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Four Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

CISA Launches Targeted Pilot Program for Critical Infrastructure, including Water and Wastewater Sector

In response to cyber attacks that have intensified in both volume and impact and the vulnerabilities within the nation’s critical infrastructure, CISA has announced the beginning a new pilot program that is focused on certain sectors. The water and wastewater sector is among them and can expect to be offered “cutting-edge” cybersecurity services, such as CISA’s Protective Domain Name System (DNS) Resolver.

Pages

Subscribe to Cybersecurity