You are here

Cybersecurity

House Committee Hearing – Unconstrained Actors: Assessing Global Cyber Threats to the Homeland

During the House Committee Hearing held yesterday, four witnesses addressed the escalating threats posed by nation-state actors, particularly from the People’s Republic of China (PRC). They highlighted the increased sophistication and operational capabilities of these threat actors and noted a rise in cyber intrusions targeting U.S. critical infrastructure. Witnesses also cited recent incidents at water utilities.

Cyber Resilience – Tenable Analysis of Salt Typhoon and Exploited Vulnerabilities

Cybersecurity firm Tenable recently released an analysis of People’s Republic of China’s (PRC)-affiliated threat actor Salt Typhoon and examines the vulnerabilities and tactics employed by the group. Salt Typhoon has infiltrated at least nine U.S.-based telecommunications companies and has utilized various tactics, primarily exploiting vulnerabilities, to gain access.

Vulnerability Awareness – Joint Advisory on Ivanti Exploit Chains by Suspected Chinese Threat Actors

Yesterday, CISA and the FBI released a joint advisory that included technical details of at least two exploit chains used by threat actors to break into Ivanti Cloud Service Appliances (CSA). The advisory comes in response to active exploitation in Ivanti CSA of the following vulnerabilities:

Secure by Design – CISA and FBI Release Updated Guidance on Product Security Bad Practices

Last week, CISA released an update to the joint guidance “Product Security Bad Practices,” originally released in October last year. This guidance gives an overview of exceptionally risky product security practices for software manufacturers who produce software in support of critical infrastructure or national critical functions.

The bad practices are divided into three categories:

Report – KnowBe4 Research Indicates Effective Security Awareness Training Reduces Likelihood of Breaches

A recent report from Cybersecurity firm KnowBe4 indicates the effectiveness of security awareness training (SAT) on overall organizational security. The report, titled “Effective Security Awareness Training Really Does Reduce Breaches,” notes that organizations who implement effective SAT programs are 8.3 times less likely to appear on public data breach lists annually compared to general statistics.

Pages

Subscribe to Cybersecurity