You are here

Cybersecurity

House Committee Releases Cyber Threat Snapshot - Cites Water Sector Incidents and Rising Nation-State Threats

The House Committee on Homeland Security released a “Cyber Threat Snapshot” examining the growing threats posed by malign nation-states and criminal networks to U.S. critical infrastructure. The snapshot particularly focuses on the threats posed by the Chinese-affiliated threat groups Volt Typhoon and Salt Typhoon, as well as the Iranian Islamic Revolutionary Guard Corps, both of which have been known to target the water sector.

Threat Awareness – Phishing Campaign Uses REMCOS RAT to Exploit Victims

A phishing campaign has been identified by researchers at Fortinet where threat actors are using a new variant of the REMCOS (Remote Control System) remote access trojan (RAT). The phishing emails intend to trick victims into opening a malicious Excel attachment disguised as an order file. Once opened, the document exploits a vulnerability which sets off an infection chain ultimately leading to the delivery of a fileless variant of REMCOS.

Joint Advisory – 2023 Top Routinely Exploited Vulnerabilities

Today, CISA, the National Security Agency (NSA), the FBI, and international partners published a joint Cybersecurity Advisory (CSA), 2023 Top Routinely Exploited Vulnerabilities. As in prior years, this effort highlights multiple vulnerabilities that threat actors are routinely exploiting on devices and software that remain unpatched or are no longer supported by a vendor.

OT/ICS Cyber Resilience – PLCHound: A Significant Improvement for Identifying Internet-Exposed ICS Systems

Research by a team from Georgia Tech School of Electrical and Computer Engineering has come up with an algorithm that improves upon previous detection methods of identifying internet-exposed ICS devices, in this case PLCs. Dubbed PLCHound, the new algorithm uses advanced language processing and machine learning techniques to identify devices. According to the researchers, PLCHound enabled them to identify 37 times more internet-connected PLCs than were previously estimated.

Pages

Subscribe to Cybersecurity