Despite Russia warnings, Western critical infrastructure remains unprepared

September 18, 2024 at 05:23AM Russian special forces are escalating cyber operations targeting Western critical infrastructure. Unit 29155 of Russia’s GRU military intelligence agency is exploiting vulnerabilities, while a secretive military unit is plotting to sabotage submarine cables. Experts warn of the increased risk of destructive hybrid attacks and emphasize the importance of improving cybersecurity … Read more

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA

June 12, 2024 at 05:06AM The June 2024 Patch Tuesday brought advisories from Siemens, Aveva, Schneider Electric, and the US cybersecurity agency CISA. Siemens published 14 new advisories addressing over 120 vulnerabilities, including critical authentication bypass and code execution flaws. Aveva released advisories for high-severity local and remote code execution vulnerabilities. Schneider Electric disclosed 11 … Read more

CISA’s early-warning system helped critical orgs close 852 ransomware holes

May 7, 2024 at 04:11PM CISA is launching a Ransomware Vulnerability Warning Pilot program to help healthcare, schools, and critical infrastructure organizations address security flaws exploited by ransomware groups. The system sent 1,754 notifications in its first year, resulting in 49% of organizations taking action. The program is set to become a fully automated warning … Read more

Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes

November 30, 2023 at 03:48PM Google has released an urgent Chrome update to fix six security vulnerabilities, including an actively exploited zero-day flaw (CVE-2023-6345) relating to the Skia graphics library. Spyware risks are implied. Zyxel also patched critical issues affecting NAS devices. Users are urged to promptly update Chrome to mitigate security threats. Meeting Takeaways: … Read more

CISA Debuts ‘Secure by Design’ Alert Series

November 30, 2023 at 06:06AM The US cybersecurity agency CISA launched Secure by Design (SbD) alerts, encouraging software manufacturers to build products with proactive security measures to mitigate vulnerabilities, particularly in web management interfaces. The new alerts focus on vendor practices that can globally reduce harm, emphasizing the need for default security features, customer security … Read more