You are here

Cybersecurity

Siemens SCALANCE W1750D, M800, and S615 (Update C) (ICSA-17-332-01) – Product Used in Water and Wastewater and Energy Sectors

October 13, 2020

CISA has updated this advisory with additional details on the affected products. Read the advisory at CISA.

May 10, 2018

The NCCIC has updated this advisory with additional details on mitigation measures. NCCIC/ICS-CERT.

April 5, 2018

Tags: 
ics-cert siemens

Siemens Industrial Products (Update J) (ICSA-19-253-03) – Products Used in the Water and Wastewater and Energy Sectors

October 13, 2020

CISA has updated this advisory with additional details on the affected products. Read the advisory at CISA.

September 8, 2020

CISA has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at CISA.

'15CFAM' is More than FUN with Consequence-driven Cyber-informed Engineering (CCE)

Welcome to week two of ‘15 Cybersecurity Fundamentals Awareness Month’ (15CFAM), as WaterISAC continues its tribute to National Cybersecurity Awareness Month (NCSAM). Today we briefly touch on less of a fundamental and more of a slightly advanced topic called Consequence-driven Cyber-informed Engineering (CCE), which comes in at #6 (Install Independent Cyber-Physical Safety Systems) in the 15 Cybersecurity Fundamentals for Water and Wastewater Utilities.

CISA Alert: APT Actors Chaining Vulnerabilities against Government Organizations and Critical Infrastructure

The U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) has published an alert on recently-observed activity involving an advanced persistent threat actor exploiting multiple legacy vulnerabilities in combination with a newer privilege escalation vulnerability – CVE-2020-1472 – in Windows Netlogon. CISA explains this is a commonly-used tactic, known as “vulnerability chaining,” in which multiple vulnerabilities are exploited in the course of a single intrusion to compromise a network or application.

WaterISAC’s ‘15 Cybersecurity FUNdamentals Awareness Month’ (15CFAM) Continues – Having More FUN Safeguarding Systems and Administering Access

Welcome back to ‘15 Cybersecurity Fundamentals Awareness Month’ (15CFAM), WaterISAC’s supplement to National Cybersecurity Awareness Month (NCSAM). 15CFAM aims to walk through WaterISAC’s 15 Cybersecurity Fundamentals for Water and Wastewater Utilities. Today we saunter among safeguarding systems from unauthorized access and exposure from cyber and physical threats.

Johnson Controls Sensormatic Electronics American Dynamics Victor Web Client (ICSA-20-282-01)

CISA has published an advisory on an improper authorization vulnerability in Johnson Controls Sensormatic Electronics American Dynamics Victor Web Client. All versions up to and including v5.4.1 are affected. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to delete arbitrary files on the system or render the system unusable through a denial-of-service attack. Johnson Controls recommends users upgrade all versions of victor Web Client to v5.6. CISA also recommends a series of measures to mitigate this vulnerability.

Pages

Subscribe to Cybersecurity