You are here

Cybersecurity

Security Awareness – AI Makes Difficult to Detect Emails Even More Challenging

In a report by Egress, researchers found that human-generated phishing campaigns are getting harder to detect, with a 24.4% increase in obfuscation techniques integrated into over half (55%) of phishing emails in 2023. These techniques have also grown in sophistication, with almost half (47%) of phishing threat actors deploying two obfuscation layers, while less than one-third (31%) use only one technique.

Cyber Resilience – Impact on National Security in the Face of Government Shutdowns

In a recent report from Forbes, the nation's cybersecurity was in a tight spot when Congress passed a bill to keep the government running for the next 45 days. A government shutdown could have caused problems for many government functions, including those responsible for protecting the country from cyberattacks. Depending on how long the shutdown lasted, it could have led to a crisis for companies and organizations across the country.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – October 3, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

  • n/a

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

​Alerts, Updates, and Bulletins:

NSA Releases Guidance on Acceptance Testing for Supply Chain Risk Management

The National Security Agency (NSA) has released the Cybersecurity Information Sheet (CSI) “Procurement and Acceptance Testing Guide for Servers, Laptops, and Desktop Computers,” encouraging U.S. government departments and agencies operating National Security Systems (NSS) to implement a robust supply chain risk management strategy.

Joint Cybersecurity Advisory – People's Republic of China-Linked Cyber Actors Hide in Router Firmware

WaterISAC regularly provides awareness of recent CISA reporting. While direct relevance to your utility/organization on the details of each report may vary, activity alerts like this are practical for general awareness and greater understanding of active threats and adversary capabilities.

Pages

Subscribe to Cybersecurity