National Grid latest UK org to zap Chinese kit from critical infrastructure

December 18, 2023 at 07:41AM The National Grid terminated its contract with China’s NR Electric UK over cybersecurity concerns, removing China-manufactured equipment from its network. Similar actions have been taken in the UK’s critical infrastructure network, like the ban on Huawei’s 5G equipment. Concerns center around potential data security risks due to China’s influence in … Read more

Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally

December 13, 2023 at 11:59AM Summary: The FBI, CISA, NSA, SKW, CERT Polska, and NCSC released a report assessing Russian SVR cyber actors exploiting CVE-2023-42793 to target servers hosting JetBrains TeamCity software globally. The report provides IOCs and mitigations to assist organizations in detecting and countering these malicious actions. SVR cyber activity poses a persistent … Read more

CISA, NCSC Offer a Road Map, Not Rules, in New Secure AI Guidelines

November 28, 2023 at 05:40AM The US Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre have released new guidelines for secure AI system development. The guidelines focus on building security into AI systems but do not impose any rules or regulations on the industry. The guidelines cover secure design, development, … Read more

CISA, NCSC Offer a Road Map, Not Rules, in New Secure AI Guidelines

November 27, 2023 at 06:02PM The US Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre have released Guidelines for Secure AI System Development. The guidelines provide an outline for building security into AI systems but do not impose regulations on the industry. The guidelines cover secure design, development, deployment, and … Read more

Hackers exploit MagicLine4NX zero-day in supply-chain attack

November 24, 2023 at 01:20PM The National Cyber Security Centre (NCSC) and Korea’s National Intelligence Service (NIS) have warned that the North Korean Lazarus hacking group has been breaching companies using a zero-day vulnerability in the MagicLine4NX software. The group primarily targets South Korean institutions and is known for utilizing supply-chain attacks and zero-day vulnerabilities … Read more