You are here

Cybersecurity

Microsoft Ending Support for Windows 7 and Windows Server 2008 R2

The DHS Cybersecurity and Infrastructure Security Agency have released an alert noting that Microsoft will end extended support for their Windows 7 and Windows Server 2008 R2 operating systems on January 14, 2020. After this date, these products will no longer receive free technical support, or software and security updates. CISA offers a list of steps organizations can take to mitigate the effects of end-of-support. Read the alert at CISA.

National Cybersecurity Awareness Month Continues – Cybersecurity Involves Every Person

What do people have to do with cybersecurity? In a word, everything. Reports consistently cite over 90% of cyber attack exploits target humans over system vulnerabilities. As stated by one of the world’s most notorious hackers, Kevin Mitnick (now Chief Hacking Officer at KnowBe4), it is easier to get someone to “reveal” something than it is to “hack” into their system.

Multiple Vulnerabilities in Pulse Secure VPN

The CERT Coordination Center (CERT/CC) has released information on multiple vulnerabilities affecting Pulse Secure Virtual Private Network (VPN). An attacker could exploit these vulnerabilities to take control of an affected system. These vulnerabilities have been targeted by advanced persistent threat (APT) actors. The DHS Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the resources for more information and to apply the necessary updates.

Oracle Releases October 2019 Security Bulletin

Oracle has released its Critical Patch Update for October 2019 to address 219 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. The DHS Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Oracle October 2019 Critical Patch Update and apply the necessary updates.

Still Struggling with Passwords – SecureIT. with Stronger Passwords

It is no secret that passwords alone are not the best method to safeguard our digital assets, especially weak passwords. Password hygiene is a leading topic any time of year, but as NCSAM continues it is a good time for another reminder for organizations to do better to protect data they are entrusted. Password security firm LastPass recently published its’ 3rd Annual Global Password Security Report which highlights how employees’ continued poor password habits weaken the overall organizational security posture.

Siemens SIMATIC WinCC and PCS7 (Update C) (ICSA-19-192-02) – Product Used in the Water and Wastewater and Energy Sectors

October 10, 2019

CISA has updated this advisory with additional information on affected products and mitigation measures. Read the update at CISA.

September 10, 2019

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at CISA.

August 13, 2019

Siemens SIMATIC PCS 7, WinCC, TIA Portal (Update D) (ICSA-19-134-08) – Products Used in the Water and Wastewater and Energy Sectors

October 10, 2019

CISA has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at CISA.

September 10, 2019

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at CISA.

August 13, 2019

Make the Most Out of National Cybersecurity Awareness Month with Free Resources from DHS

As part of National Cybersecurity Awareness Month (NCSAM), the U.S. Department of Homeland Security has recently released a variety of new resources to raise awareness and provide partners with the information and tools to enhance cybersecurity at the home and in the workplace. These resources include guides that pertain to this year’s NCSAM theme of “Own IT. Secure IT.

ACSC Releases Small Business Cybersecurity Guide

The Australian Cyber Security Centre (ACSC) has released a cybersecurity guide for small businesses. The guide provides checklists to help small business protect themselves against common cybersecurity incidents. The ACSC also has a suite of other resources for small businesses, including “step-by-step” guides for backing up and restoring a computer and turning on automatic updates and “quick wins” documents for portable device and website security. For these resources, refer to the Small Business Cyber Security suite at cyber.gov.au. 

Pages

Subscribe to Cybersecurity