You are here

Cybersecurity

Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization

Today, CISA released an advisory detailing the results of a red team assessment (RTA) conducted at the request of an unnamed critical infrastructure organization. The assessment and resulting advisory include the red team’s activity, tactics, techniques, and procedures (TTPs), and network defense activity, as well as lessons learned and key findings.

2024 CWE Top 25 Most Dangerous Software Weaknesses

The Homeland Security Systems Engineering and Development Institute, sponsored by CISA and operated by MITRE, has released the 2024 CWE Top 25 Most Dangerous Software Weaknesses list. The Top 25 uses data from the National Vulnerability Database (NVD) to compile the most frequent and critical errors that can lead to serious vulnerabilities in software. CISA encourages users and administrators to review the Top 25 list and evaluate recommended mitigations to determine those most suitable to adopt. 

DHS Unveils Framework for the Safe and Secure Deployment of AI in Critical Infrastructure

Last week, DHS released a framework that outlines how to securely develop and deploy artificial intelligence (AI) in critical infrastructure titled “Roles and Responsibilities Framework for Artificial Intelligence in Critical Infrastructure.” The recommendations apply to all entities at each layer of the AI supply chain, including cloud and compute providers, AI developers, and critical infrastructure owners and operators.

EPA Report: Cybersecurity Concerns Related to Drinking Water Systems

The EPA Office of Inspector General (OIG) has released a report titled “Management Implication Report: Cybersecurity Concerns Related to Drinking Water Systems.” A passive assessment of cybersecurity vulnerabilities was conducted on drinking water systems that serve over 50,000 people or more. This included 1,062 drinking water systems across the U.S. that serve more than 193 million people.

Pages

Subscribe to Cybersecurity