You are here

Cybersecurity

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – August 15, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Two Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Threat Awareness – Complex Social Engineering Attack Uses Phone Pressure to Get Victims to Click

Sophos has written a blog describing its investigation into a social engineering-based attack chain that used a unique approach to get the victim to click on a malicious payload. This peer-pressure based tactic allowed the attackers to infect the network, despite the victim quickly detecting it.

Don’t Delay! – MITRE’s NO-COST Research Proposal for Water and Wastewater Cyber Resilience

As originally heard during WaterISAC’s July Cyber Threat Briefing, MITRE is extending an offer to 5 water or wastewater utilities to participate in its NO-COST research project that will aid in gaining valuable insights into your OT environment. Don’t delay! MITRE is looking to finalize the participants before the end of August.

The goal of this project is to:

Threat Awareness – EvilProxy Hybrid Phishing Campaign Targeting Executive Accounts at Over 100 Global Organizations

Proofpoint has written a blog discussing its research into an EvilProxy-based campaign targeting high-level business leaders across 100 global organizations. Successful cloud account takeover incidents have increased over 100 percent over the last six months, with the ultimate goal of establishing persistent access to executive’s business accounts.

Pages

Subscribe to Cybersecurity