Advertisement
UK Cyber Security and Resilience Bill Targets High-Risk Vendors
The UK amends its Cyber Security and Resilience Bill to grant ministers powers to block high-risk technology suppliers from critical infrastructure.
U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure
U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.
Bolstering Municipal Cybersecurity: A Call for Professional Support
Local government agencies face severe cybersecurity resource gaps. This analysis urges cyber professionals to volunteer expertise to defend critical public services.
CISA Warns: Medusa Ransomware Breaches 500+ Critical Infra Orgs
CISA, FBI, and HHS alert on Medusa ransomware, which has impacted over 500 critical infrastructure organizations since June 2021, urging immediate network hardening.
Ransomware Attack Hits Colombian Justice Ministry
A ransomware attack targets the Colombian Justice Ministry days before a presidential transition, highlighting regional risks.
Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA
Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.
Advertisement
Multistate Water System Attacks Target Exposed PLCs
Attacks targeting poorly secured, internet-exposed PLCs in water systems are widening across multiple U.S. states, with Iran suspected.
Hackers Breach Polish CHP Plant via Private APN and Teltonika Router
Attackers breached a Polish combined heat and power plant via a private APN, shutting down a steam turbine and water treatment system.
Private APN Misconfiguration Led to Polish Energy Plant OT Compromise
Hackers compromised a Polish energy plant's OT network by exploiting a private APN misconfiguration, shutting down a steam turbine and water treatment system.
NC Ports Cyberattack Disrupts Operations at Key Facilities
North Carolina Ports confirmed a cyberattack disrupting IT systems and operations across its facilities. Recovery efforts are underway, with expected delays.
Iran-Backed Cyberattacks Target Minnesota Water Utilities
Iran-backed threat actors targeted over 30 Minnesota water utilities, highlighting critical infrastructure vulnerabilities. Learn about TTPs and mitigation strategies.
Coordinated OT Attack Targets 30+ Minnesota Water Utilities
Over 30 Minnesota water utilities were targeted in a coordinated cyberattack on operational technology, prompting a statewide incident response and investigation.
Thousands of Data Center Controllers Exposed: Prevent Server Takeover
Thousands of internet-exposed data center remote management processors are vulnerable to offline password cracking, enabling server takeover and critical infrastructure…
CISA & ACSC Advise Isolating OT Systems During Cyberattacks
CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.
OT Security Startup Frenos Secures $1.52 Million for AI R&D
Frenos raises $1.52 million in seed funding to expand AI research and development focused on securing industrial control systems and operational technology.
Securing Critical Infrastructure: Closing Identity Gaps
Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.
OT Security: Legacy System Vulnerabilities in Critical Infrastructure
Addressing the complex challenges of securing legacy OT systems in critical infrastructure, balancing vulnerability disclosure with operational continuity and safety.
UK and EU Sanction Russian APTs Over Critical Infrastructure Attacks
Recent UK and EU sanctions target Russian intelligence services following persistent cyber operations against government entities and critical infrastructure.
EU Sanctions Russian Intel Officers for APT28 Cyber Operations
The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.
Russian APTs Target Critical Infrastructure via Edge Device Exploits
US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.
France Mandates Quantum-Safe Encryption by 2027
France's ANSSI will stop certifying non-quantum-safe encryption products from 2027, compelling government and critical operators to adopt post-quantum solutions.
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.
CVE-2024-2821: Critical RCE in Daktronics Controllers — Patch Now
Critical vulnerabilities (CVE-2024-2821, CVE-2024-2822, CVE-2024-2823) in Daktronics Venus 1500 and Vanguard controllers allow remote hacking of highway signs and…