You are here

Cybersecurity

Cyber Resilience - WaterISAC’s Monthly Cyber Threat Briefing Gets New Name to Better Reflect Mission

‘Tis the season for fresh starts. To that end, WaterISAC is announcing the rebranding of its monthly Cyber Threat Briefing. While it will certainly continue to offer briefings on active threats and vulnerabilities or relevant incidents as appropriate, the slight name change will more closely embody the varied cyber resilience content this monthly webinar has been providing.

Ransomware Resilience – Don’t Wait ‘til it’s Too Late

Ransomware attacks used to be a fairly noisy and obvious attack as malware executed and countless files and their backups were rendered inaccessible either through encryption or deletion. This activity would light up alerts and security solutions like a Christmas tree or New Year’s fireworks. However, during 2023 many ransomware groups have been forgoing the file encryption and deletion phases while they tip-toe around our networks, silently lurking and establishing a foothold.

CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – December 21, 2023

The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS vulnerability advisories, as well as alerts, updates, and bulletins:

ICS Vulnerability Advisories:

CISA Releases Two Industrial Control Systems Advisories

Products are used across multiple sectors, please check these latest advisories for specific equipment used across your ICS environments and address accordingly.

War Fallout: Ukrainians Steal Data from Russian Water Supply Company

According to reports, Ukraine allegedly compromised Rosvodokanal, one of Russia’s largest private companies, and seized 1.5TB of data. The operation is believed to be carried out by the Ukrainian attack group Blackjack and part of continued cyberwarfare between Ukraine and Russia. The Interfax-Ukraine news agency stated that the Ukrainian attackers encrypted 6,000 computers and deleted more than 50TB of data, including internal document management system, corporate emails, cyber protection services, and backups.

Microsoft Outlook Zero-Click Security Flaws Triggered by Sound File

Researchers disclosed details on two security vulnerabilities in Microsoft Outlook this week, which, when chained together, provide attackers a means to run any code or command on a computer system without restrictions. The vulnerabilities mentioned in the article can be exploited when a victim simply clicks on or opens a file, such as a sound file.

Pages

Subscribe to Cybersecurity