You are here

Cybersecurity

Ransomware Preparedness – Two Years After Colonial Pipeline Attack, U.S. Critical Infrastructure Still Not Prepared for Ransomware

It’s been two years since the ransomware attack on the Colonial Pipeline, which many observers view as a watershed moment in cybersecurity. While many positive strides have been made since the attack, which CISA details in a recent blog post, other analysts argue the threat from ransomware is still growing and impacting critical infrastructure organizations.

Ransomware Resilience – Federal Government: Low Victim Reporting Hampers Ransomware Response Efforts

CyberScoop has written an article discussing federal concerns over victims’ reluctance to report ransomware attacks to the broader community, as outlined in the Institute for Security and Technology’s  Ransomware Task Force May 2023 Progress Report. The FBI and Justice Department have stated that only 20% of victims report if they’ve been infected.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – May 9, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

Alerts, Updates, and Bulletins:

Threat Awareness – IcedID and QBot Malware Continue to Propagate with Various Techniques to Compromise more Victims

Commodity malware continues to plague businesses and the threat actors employing them are utilizing a diverse toolset of tactics, techniques, and procedures in order to proliferate the malware, such as IcedID and Qbot/Qakbot, and compromise more victims.

Courts Rule in Favor of Merck in Major Cyber Insurance Claim Case

Security Week has written an article covering the Superior Court of New Jersey Appellate Division’s ruling in favor of Merck in the company’s $1.4 billion claim against insurers for the fallout of the NotPetya attack it suffered in 2017. Insurers argued that the property insurance offered to Merck had a war exclusion clause that was “clear and unambiguous, and it plainly applies to the NotPetya attack.”

Pages

Subscribe to Cybersecurity