You are here

Cybersecurity

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – January 25, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Two Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Incident Awareness – Major North American Water Utility Experiences Ransomware Incident

Water utility giant, Veolia North America, is the latest victim of a ransomware attack adding to the recent spate of cyber attacks impacting entities across the water and wastewater systems sector. As the investigation ensues, it appears the attack was limited to the company’s internal back-end servers and affected its bill payment systems. While Veolia has stated that there is “no evidence to suggest it affected our water or wastewater treatment operations,” experts and investigators are still assessing the full extent of the attack’s impact.

It’s Data Privacy Week 2024 – Take Control of your Data

The third annual Data Privacy Week began January 21, and continues through Saturday, January 27, 2024, as announced by the National Cybersecurity Alliance (NCA). While Data Privacy Day began in the United States in 2008, this year marks the third annual Data Privacy Week – two years ago, the National Cybersecurity Alliance (NCA) expanded Data Privacy Day into Data Privacy Week. NCA’s goal is to spread awareness about online privacy and help consumers understand that we do have the right and ability to manage our own data.

Threat Awareness – Outlook Calendar Invite Vulnerability Can Steal Passwords with One Click

Outlook is a near ubiquitous communications application. Additionally, with so many social engineering/phishing tactics targeting users through their inboxes, vulnerabilities left unpatched often become an attractive threat vector. One of three Microsoft vulnerabilities recently disclosed by Varonis has the ability to steal hashed passwords through Outlook’s calendar invitation with just one click. This vulnerability was assigned CVE-2023-35636 and Microsoft distributed the patch on December 12, 2023.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – January 23, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Six Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Pages

Subscribe to Cybersecurity