You are here

Cybersecurity

CISA and OMB Release Guidance on Vulnerability Management for Federal Government Agencies

Yesterday the U.S. Department of Homeland Security Cybersecurity Agency (CISA) and the Office of Management and Budget released three documents providing guidance for how federal government agencies should manage vulnerabilities. The CISA guidance consists of a binding operational directive (BOD) that requires each federal agency to publish a vulnerability disclosure program (VDP) as well as implementation guidance.

Malicious Domain Blocking and Reporting – Newest Service from MS-ISAC for SLTTs

What do you get when you combine the influence of the Cybersecurity and Infrastructure Security Agency (CISA) with the resources of the Multi-State Information Sharing and Analysis Center (MS-ISAC) and a global internet edge technology provider with an unprecedented view of the threat landscape? In short, MDBR – Malicious Domain Blocking and Reporting. The Center for Internet Security (CIS) has partnered through MS-ISAC and EI-ISAC with CISA and Akamai to make MDBR available at no cost to the members of the MS-ISAC and EI-ISAC.

Mitsubishi Electric Multiple Products (ICSA-20-245-01)

CISA has published an advisory on predictable exact value from previous values vulnerability in multiple products from Mitsubishi Electric. Successful exploitation of this vulnerability could be used to hijack TCP sessions and allow remote command execution. Mitsubishi Electric recommends that users take a series of mitigation measures to minimize the risk of exploiting this vulnerability. CISA recommends a series of measures to mitigate the vulnerability.

Emotet Makes You See Red

When Emotet is active there is no shortage of discoveries of additional behaviors designed to trick users and expand its infections. Last week, researchers discovered a new template that Emotet is using in its attachments. When a user clicks on an Emotet-laden attachment, they are presented with a red accent colored prompt to 'Enable Editing' and 'Enable Content' to view the document. This template has been named ‘Red Dawn’ due to the red accent colors.

Pages

Subscribe to Cybersecurity