You are here

Cybersecurity

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – November 02, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Six Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

MuddyWater eN-Able Spear-Phishing with New TTPs

Cybersecurity firm Deep Instinct recently observed a new spear-phishing campaign from the Iranian state-sponsored group “Muddy Water” targeting two entities in Israel using updated TTPs. In the past, Muddy Water has used PDF, RTF, and HTML attachments containing links to archives hosted on various file-sharing platforms. These archives contain installers for various remote administration tools including ScreenConnect, RemoteUtilities, Syncro, etc.

White House Issues Executive Order on Safe and Responsible Use of AI, including for Critical Infrastructure

President Biden has signed an executive order (EO) aimed at regulating generative AI systems, recognizing their transformative potential and potential risks. The order focuses on ensuring the safe and responsible use of AI, including with respect to critical infrastructure.

FBI PSA – Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers

The FBI’s Internet Crime Complaint Center (IC3) is issuing an updated Public Service Announcement (PSA) to help organizations better understand and guard against the inadvertent recruitment, hiring, and facilitation of Democratic People's Republic of Korea (DPRK, a.k.a. North Korea) information technology (IT) workers.

Pages

Subscribe to Cybersecurity