CISA warns about the fast flux DNS evasion technique used by ransomware gangs and state-sponsored threat actors to shield cybercrime infrastructure, threatening national security.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Hackers exploited Pulse Connect Secure VPN vulnerabilities to collect passwords, install web shells, and bypass multi-factor authentication on victims’ networks, including federal agencies.
The new guidance actually focuses on three main areas of AI data security: data drift and potentially poisoned data, and also risks in the data supply chain. The guidance builds upon the NSA’s existing Deploying AI Systems Securely publication, but adds much more detail specific to addressing potential vulnerabilities.
Hot on the heels of the U.S. bombing of Iranian nuclear facilities, a joint cybersecurity advisory has warned critical infrastructure organizations of cyber threats stemming from Iranian-backed malicious actors.
CISA has disclosed that more than 100 water systems across multiple U.S. states were affected by a coordinated cyber attack unofficially attributed to Iranian hackers.
CISA: Admin Credentials of a Former Employee Leveraged to Compromise a State Government Organization
The Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC) discovered that a threat actor compromised a state government organization using a former employee’s leaked admin credentials.
CISA has released a new cybersecurity checklist as a primer for an expected uptick in hacking ahead of the 2024 presidential election, composed of just four pages of information that does not pack any surprises.
CISA directs federal agencies to adhere to the vulnerability management catalog and patch 300 exploited vulnerabilities assigned CVE IDs in 2021 within 2 weeks and 6 months for previous ones.
CISA/NSA Identity and Access Management Guidelines Provide Cybersecurity Guidance for Administrators
CISA and the NSA note that identity and access management vulnerabilities are a particular recent focus for certain state-backed threat groups, and that 40% of data breaches not involving user error or an insider are now facilitated by stolen credentials.
Cisco has launched a data breach investigation and pulled its development portal offline after a hacker listed the company’s infrastructure information on a hacking forum.










