You are here

Cybersecurity

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – February 13, 2024

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – February 13, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases One Industrial Control Systems Advisory

Passthrough: Joint Cyber Defense Collaborative (JCDC) Priorities for 2024

Yesterday, CISA—on behalf of the collective group of industry and government partners that comprise the Joint Cyber Defense Collaborative (JCDC)—released JCDC’s 2024 Priorities. Similar to the 2023 JCDC Planning Agenda, JCDC’s 2024 Priorities will help focus the group on developing high-impact and collaborative solutions to the most pressing cybersecurity challenges.

The focused goals of the 2024 priorities are to:

WaterISAC and NRWA Announce Collaborative Effort to Better Serve the Underserved

WaterISAC and the National Rural Water Association (NRWA) recently announced a formal collaboration effort intended to educate rural utilities across the country about both cyber and physical security threats. The collaboration comes in hopes to increase resilience efforts among some of the country’s smallest and often overlooked utilities, including 25,000 NRWA members that serve populations of 3,300 or fewer.

Cyber Resilience – Recap of Tuesday’s Hearing on Securing Operational Technology in the Water Sector

Similar to the subcommittee hearing last week, another one was held Tuesday that focused on the water sector, titled “Securing Operational Technology: A Deep Dive into the Water Sector.” The witnesses included top water trade officials as well as leaders from Dragos and MITRE. Much of what was explored centered around the need for more cybersecurity technical resources, specifically for OT systems.

(TLP:CLEAR) WaterISAC Advisory – PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance

Yesterday, WaterISAC sent an advisory to members regarding the joint Cybersecurity Advisory (CSA) and guidance related to Volt Typhoon. The CSA confirms that these state-sponsored affiliated actors have an interest in and have compromised water and wastewater systems sector assets. Specifically, the U.S.

(TLP:CLEAR) Public Safety ISAO Vulnerability Advisory – Exploitation of ESXi Vulnerabilities Disrupted Emergency Services

WaterISAC is sharing this for broader awareness of the threat against out-of-date VMware ESXi servers, on the impact such incidents can have on mission critical resources, and most importantly how this incident enabled adversaries to access and encrypt a broadband radio network.

Pages

Subscribe to Cybersecurity