You are here

Cybersecurity

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – July 25, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Four Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Threat Awareness – Impacts of Stolen Microsoft Encryption Key Potentially Extend to Other Microsoft Platforms

Wiz has posted a blog discussing the implications of the recently announced security incident affecting Microsoft where a Chinese-attributed threat actor stole a private encryption key to forge access tokens for various Outlook products. After conducting further technical analysis, researchers believe that this stolen key could also impact users of Azure Active Directory, SharePoint, Teams, and OneDrive.

Security Awareness – Higher than Average Critical Infrastructure Employees Correctly Report Phishing Attempts

Hoxhunt has released its Human Cyber-Risk Report: Critical Infrastructure, with a key finding that 66% of critical infrastructure employees have correctly reported at least one malicious phishing attempt. Hoxhunt’s researchers state that this statistic is 20% higher than the averages for other industries they’ve done phishing studies for.

Cyber Resilience – CISA and Microsoft Partnership Expands Access to Logging Capabilities Broadly

Based on a collaborative partnership between CISA and Microsoft, many Microsoft customers will now have access to expanded cloud logging capabilities at no additional charge, which will enhance cyber defense and incident response. The expanded access comes in response to a cyber incident in June involving a government agency where advanced persistent threat (APT) actors accessed and exfiltrated unclassified Exchange Online Outlook data.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – July 20, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases One Industrial Control Systems Advisory

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

Pages

Subscribe to Cybersecurity