You are here

Cybersecurity

(TLP:CLEAR) CISA and Partners Release New Guidance for SIEM and SOAR Implementation

Summary: On Tuesday, CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released new guidance for organizations seeking to procure Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.

(TLP:CLEAR) Threat Actors Target U.S. Critical Infrastructure and Exfiltrate Data with LummaC2 Malware

Summary: Yesterday, CISA and the FBI released a joint Cybersecurity Advisory (CSA) detailing the tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs) linked to threat actors deploying LummaC2 malware. This malware poses a serious threat, capable of infiltrating networks and exfiltrating sensitive information of vulnerable individuals’ and organizations’ computer networks across U.S. critical infrastructure sectors.

(TLP:CLEAR) Russian GRU Targeting Western Logistics Entities and Technology Companies

Summary: A joint Cybersecurity Advisory (CSA) was just released by over 20 federal and international partner agencies to highlight a Russian state-sponsored campaign targeting Western logistics entities and technology companies. The CSA provides an overview of targets, initial access tactics, techniques, and procedures (TTPS), and indicators of compromise (IOCs) that are associated with the campaign.

(TLP:CLEAR) Insights into the Continued Salt Typhoon Telecom Infiltrations

Summary: New insights have been shed into the problems that allowed the Chinese advanced persistent threat group known as Salt Typhoon to infiltrate several telecommunications companies’ networks over the last year. CyberScoop gives a detailed analysis of how telecoms may never fully eradicate the threat actor fromtheir networks.

Pages

Subscribe to Cybersecurity