You are here

Cybersecurity

CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – November 5, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:

ICS Advisories:

  • There are no new ICS advisories to report

Additional Alerts, Updates, and Bulletins:

Threat Awareness – Compromised U.S. and Foreign Government Emails Used to Conduct Fraudulent Emergency Data Requests

Yesterday, The FBI released a Private Industry Notification (PIN) to warn of a trend of compromised U.S. and Foreign government email addresses used to conduct fraudulent emergency data requests to U.S.-based organizations. The PIN notes that an increase of activity on criminal forums regarding the process of emergency data requests and sale of compromised credentials has led to an increased use of this threat. WaterISAC recommends members review the PIN and implement the recommended mitigations listed.

Threat Awareness – APT Conducts Large-Scale Spear-Phishing Campaign with RDP Attachments

Last week, Microsoft warned of a spear-phishing threat by the Russian state-backed threat group known as Midnight Blizzard or APT29. “Since October 22, 2024, Microsoft Threat Intelligence has observed Russian threat actor Midnight Blizzard sending a series of highly targeted spear-phishing emails to individuals in government, academia, defense, non-governmental organizations, and other sectors” reads Microsoft’s threat blog.

Report – Sophos Unveils Evolving Tactics of China-based Cyber Threats to Critical Infrastructure

Following a 5-year investigation into China-based cyber threats targeting critical infrastructure, Sophos researchers have attributed specific observed activity to Volt Typhoon, highlighting key behaviors in its Pacific Rim report. The report includes a summary of the adversary’s activity and key takeaways for defenders.

EPA Factsheet – Cyber Insurance for Drinking Water and Wastewater Systems

The EPA Water Infrastructure & Cyber Resilience Division (WICRD) recently produced a factsheet entitled “Cyber Insurance for Drinking Water and Wastewater Systems.” The factsheet provides water systems with a simplified guide to assist in the selection of cyber insurance to protect them against computer-related crimes and losses.

Pages

Subscribe to Cybersecurity