DHS has published a security advisory that confirms a ransomware attack on critical infrastructure and provides recommendations for other operators to take precautions.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Data breach of U.S. Customs and Border Protection agency’s subcontractor has exposed around 100,000 travelers’ images which further highlight the importance of vendor security compliance.
Joint federal cybersecurity advisory warns of a tenacious cyber espionage campaign by Russian hackers against U.S. and allied networks using evolving TTPs of varying sophistication.
A joint advisory by U.S. federal agencies warns of Iranian-affiliated cyber attacks on critical infrastructure, including energy, water, and government sectors.
The U.S. Federal Government is a behemoth that touches every aspect of American life – and today the services and information needed by U.S. citizens are increasingly found online. However, the latest report on the state of U.S. federal websites indicates that they fail on some key indicators regarding web security.
The U.S. government reveals the Vulnerabilities Equities Process which decides if vulnerability data is released or gets stockpiled as cyber weapons.
In a move that was widely expected, U.S. lawmakers have proposed a DeepSeek ban on any and all federal government devices. The move may have been prompted by analysis of DeepSeek code that seems to show a direct connection to the Chinese Communist Party (CCP).
Growing number of Americans now feel that state and local governments should increase their cybersecurity spending and do more to protect data from cyberattacks, similar to that which crippled the city of Atlanta in March 2018.
Anonymous officials from the Biden administration have told the New York Times that Chinese malware has been planted in the networks that control the critical infrastructure of military bases. The "ticking time bomb" could potentially cripple military systems in the event of a conflict between the two countries.
The National Guard is serving as something of a stopgap to defend against cyber attacks for state and local governments that are running behind the curve in terms of cyber capabilities.










