You are here

Cybersecurity

Water Sector, Federal Partners Launch Effort on ICS Monitoring

Today, the water sector, EPA and the White House National Security Council announced the launch of the Industrial Control Systems Cybersecurity Initiative – Water and Wastewater Sector Action Plan - a 100-day “surge” to investigate the pros and cons of utilities implementing industrial control system (ICS) monitoring and sharing monitoring results with the Cybersecurity and Infrastructure Security Agency (CISA).

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins - January 27, 2022

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

Alerts, Updates, and Bulletins:

FBI PIN: Context and Recommendations to Protect Against Malicious Activity by Iranian Cyber Group Emennet Pasargad

The FBI has published a TLP:WHITE Private Industry Notification (PIN) providing context and recommendations to protect against malicious activity by Iranian cyber group Emennet Pasargad. While some of the Emennet’s  most notable cyber activities have involved information operations, particularly election interference activities, it has also conducted traditional cyber exploitation activity targeting several sectors, including oil and petrochemical, financial, and telecommunications, in the U.S., Europe, and the Middle East.

Security Awareness – Data Compromises Increasing

A new report by the Identify Theft Resource Center (ITRC) reveals that data compromises are greatly increasing. The report recorded 1,862 data compromises in 2021, up more than 68 percent compared to 2020. Utilities and manufacturers witnessed a 217 percent increase in data compromise in 2021 compared to the previous year. While phishing was the number one cause of data compromises, ransomware related data breaches have doubled every year for the past two years.

Threat Actors Continue Abusing Microsoft Office Products in Phishing Campaigns

Threat actors continue abusing Microsoft Office products to fool unsuspecting individuals and to inject malware onto victims’ devices. Since December, threat actors have been sending mass phishing attacks with Excel files that deceive victims into downloading Emotet onto their systems. After victims open the Excel file, it prompts them to enable macros which subsequently downloads Emotet and enables other malicious activity.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins - January 25, 2022

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

Alerts, Updates, and Bulletins:

Pages

Subscribe to Cybersecurity