You are here

Cybersecurity

Threat Awareness – Phishing Campaign Uses REMCOS RAT to Exploit Victims

A phishing campaign has been identified by researchers at Fortinet where threat actors are using a new variant of the REMCOS (Remote Control System) remote access trojan (RAT). The phishing emails intend to trick victims into opening a malicious Excel attachment disguised as an order file. Once opened, the document exploits a vulnerability which sets off an infection chain ultimately leading to the delivery of a fileless variant of REMCOS.

Joint Advisory – 2023 Top Routinely Exploited Vulnerabilities

Today, CISA, the National Security Agency (NSA), the FBI, and international partners published a joint Cybersecurity Advisory (CSA), 2023 Top Routinely Exploited Vulnerabilities. As in prior years, this effort highlights multiple vulnerabilities that threat actors are routinely exploiting on devices and software that remain unpatched or are no longer supported by a vendor.

OT/ICS Cyber Resilience – PLCHound: A Significant Improvement for Identifying Internet-Exposed ICS Systems

Research by a team from Georgia Tech School of Electrical and Computer Engineering has come up with an algorithm that improves upon previous detection methods of identifying internet-exposed ICS devices, in this case PLCs. Dubbed PLCHound, the new algorithm uses advanced language processing and machine learning techniques to identify devices. According to the researchers, PLCHound enabled them to identify 37 times more internet-connected PLCs than were previously estimated.

Cyber Resilience – Eight Cybersecurity Strategies for Small Organizations

Cybersecurity presents a unique set of challenges for small organizations. Due to their limited size and budget, they often cannot afford a dedicated security team, and therefore tend to rely on just one person for their cybersecurity needs. This individual often struggles to manage all the recommended or necessary tasks due to time constraints or resource limitations, which can lead to cascading consequences where security issues are handled as they arise which, more often than not, is too late to prevent severe impacts.

NRWA to Lead Multi-agency Initiative to Bolster Cybersecurity of Rural Water Systems

The National Rural Water Association (NRWA) has partnered with the U.S. Department of Agriculture (USDA) and the White House Office of the National Cyber Director (ONCD) to launch a one-year program study to enhance cybersecurity for rural water systems. The Oregon Association of Water Utilities and Vermont Rural Water Association will help NRWA administer the one-year study.

Pages

Subscribe to Cybersecurity