You are here

Cybersecurity

Vulnerability Awareness – Joint Advisory on Ivanti Exploit Chains by Suspected Chinese Threat Actors

Yesterday, CISA and the FBI released a joint advisory that included technical details of at least two exploit chains used by threat actors to break into Ivanti Cloud Service Appliances (CSA). The advisory comes in response to active exploitation in Ivanti CSA of the following vulnerabilities:

Secure by Design – CISA and FBI Release Updated Guidance on Product Security Bad Practices

Last week, CISA released an update to the joint guidance “Product Security Bad Practices,” originally released in October last year. This guidance gives an overview of exceptionally risky product security practices for software manufacturers who produce software in support of critical infrastructure or national critical functions.

The bad practices are divided into three categories:

Report – KnowBe4 Research Indicates Effective Security Awareness Training Reduces Likelihood of Breaches

A recent report from Cybersecurity firm KnowBe4 indicates the effectiveness of security awareness training (SAT) on overall organizational security. The report, titled “Effective Security Awareness Training Really Does Reduce Breaches,” notes that organizations who implement effective SAT programs are 8.3 times less likely to appear on public data breach lists annually compared to general statistics.

CISA Releases the JCDC AI Cybersecurity Collaboration Playbook and Fact Sheet

Yesterday, CISA released the “JCDC AI Cybersecurity Collaboration Playbook and Fact Sheet” to enhance information sharing between the public and private sectors in response to AI-related cyber threats. Developed in conjunction with the FBI, NSA's AI Security Center, and various industry partners including Google, IBM, and Microsoft, the playbook aims to create a “unified approach” to managing these threats.

Pages

Subscribe to Cybersecurity