You are here

Cybersecurity

Microsoft Reports Highly Targeted Attacks from Nobelium

Microsoft has detected recent limited activity emanating from the threat tracked as Nobelium which was originally responsible for the compromise of SolarWinds Orion in December. According to Microsoft, this recent activity was targeted at specific customers, primarily IT companies (57%), followed by government (20%). Microsoft is contacting all customers that were compromised or targeted through its nation-state notification process.

FBI Tech Tuesday on Protecting from Spoofing and Phishing Scams

As part of the FBI’s Tech Tuesday series, the Phoenix, Arizona office has published an article warning of phishing and spoofing scams by criminal actors and actions to take to help prevent becoming a victim. It notes that phishing scams reported the most victims nationally in 2020, with more than 240,000 victims reporting about $50 million in losses. Meanwhile, spoofing scams saw significantly less victims, about 28,000, but victims reported a much higher money loss of more than $215 million.

More Cyber Resources from MITRE!

So much from MITRE, so little time!! The NSA has announced plans to fund the development of a new MITRE project called D3FEND. The goal of D3FEND is to provide a knowledge base of defensive countermeasures and their relationships to offensive/adversary techniques. D3FEND has a similar look and feel, and is a complement to the MITRE ATT&CK® Framework knowledgebase of cyber adversary behavior.

Security Awareness – Now’s a Good Time to Review your Phishing Defenses

With all of the attention on ransomware lately, we can’t forget about phishing. Given the propensity for phishing to be the leading attack vector resulting in compromises – including ransomware – organizations need to continuously review their defense in depth strategies to combat phishing. Perry Carpenter, Chief Evangelist and Strategy Officer at KnowBe4, reviews three key elements of a good phishing defense approach that includes: policies, procedures and documentation; technical defenses; and security awareness training.

Chris Inglis Confirmed as First U.S. National Cyber Director

Last week the Senate confirmed Chris Inglis as the first-ever national cyber director, a role in which he is tasked with coordinating the government’s response to major cybersecurity incidents and threats. He will also coordinate cooperation between the government and the private sector on critical cybersecurity issues. Inglis will be expected to work closely with the National Security Council, as well as the Cybersecurity and Infrastructure Security Agency. Inglis spent nearly three decades at the NSA.

NSA Releases Guidance on Deploying Secure UC and VVoIP Communications Systems

The National Security Agency (NSA) has released guidance to help organizations secure their communication systems, specifically Unified Communications (UC) and Voice and Video over IP (VVoIP). UC and VVoIP are call-processing systems that are used for communications and collaboration by many enterprises. The NSA warns that if these systems are not properly secured, they are exposed to the same risks as IP systems, including software vulnerabilities and various types of malware.

Pages

Subscribe to Cybersecurity