You are here

Cybersecurity

Cyber Resilience – CISA Announces Effort to Create Sector-Specific Cybersecurity Performance Goals

CISA is working with Sector Risk Management Agencies (SRMAs) to directly engage with each critical infrastructure sector to develop Sector-Specific Goals (SSGs). In most instances, these goals will likely consist of either new, unique goals with direct applicability to a given sector, or materials to assist sector constituents with effective implementation of the existing cross-sector CPGs.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – July 25, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Four Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Threat Awareness – Impacts of Stolen Microsoft Encryption Key Potentially Extend to Other Microsoft Platforms

Wiz has posted a blog discussing the implications of the recently announced security incident affecting Microsoft where a Chinese-attributed threat actor stole a private encryption key to forge access tokens for various Outlook products. After conducting further technical analysis, researchers believe that this stolen key could also impact users of Azure Active Directory, SharePoint, Teams, and OneDrive.

Security Awareness – Higher than Average Critical Infrastructure Employees Correctly Report Phishing Attempts

Hoxhunt has released its Human Cyber-Risk Report: Critical Infrastructure, with a key finding that 66% of critical infrastructure employees have correctly reported at least one malicious phishing attempt. Hoxhunt’s researchers state that this statistic is 20% higher than the averages for other industries they’ve done phishing studies for.

Pages

Subscribe to Cybersecurity