You are here

Cybersecurity

Joint Cybersecurity Advisory – Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server

Yesterday, CISA, the FBI, and MS-ISAC released a joint Cybersecurity Advisory (CSA) concerning the successful exploitation of a .NET deserialization vulnerability in the Progress Telerik user interface (UI) software (CVE-2019-18935). Successful exploitation of the vulnerability provided threat actors with remote code execution capabilities on a federal network.

Cyber Resilience – NSA Urges Organizations to Implement Zero Trust in New Resource Sheet

The NSA has released a Cybersecurity Information Sheet titled “Advancing Zero Trust Maturity throughout the User Pillar” that provides recommendations for maturing identity, credential and access management (ICAM) capabilities. Noting the increased trend in threat actors targeting users and user accounts, the NSA promotes the use of the Zero Trust framework by organizations looking to achieve a more maturity cybersecurity posture.

Advisory: Potential for Mandatory Microsoft DCOM Patch to Disrupt SCADA Communications

Action may be Required: Tomorrow (March 14, 2023), it will no longer be possible to disable the Microsoft DCOM hardening patch. This could result in the disruption of critical communications between ICS/SCADA/OT devices.

In other words, if ICS/OT/SCADA devices suddenly stop communicating after applying the Microsoft DCOM patch from March 14, 2023, it may be practical to consider this as a possible cause during your troubleshooting efforts.

Pages

Subscribe to Cybersecurity