Top

Category: Cybersecurity


Cybersecurity

US Environmental Protection Agency hack exposes data of 8.5 million users

April 8, 2024

Via: CSO Online

The US federal arm tasked with environmental protection matters, the Environmental Protection Agency (EPA), is allegedly experiencing a data breach affecting over 8.5 million users. The breach, which has reportedly exposed personal and sensitive information belonging to EPA’s customers and […]


Cybersecurity

General Data Protection Regulation (GDPR): What you need to know to stay compliant

April 4, 2024

Via: CSO Online

Companies that collect data on citizens in European Union (EU) countries need to comply with strict rules around protecting customer data. The General Data Protection Regulation (GDPR) sets a standard for consumer rights regarding their data, but companies will be […]


Cybersecurity

US government blames 2023 Exchange breach on ‘preventable’ security failures by Microsoft

April 3, 2024

Via: CSO Online

The US Department of Homeland Security (DHS) has issued a critical assessment of Microsoft’s security protocols in the wake of the summer 2023 Exchange Online breach, concluding that security failures within Microsoft created the conditions that allowed Chinese state-backed hacking […]


Cybersecurity

Missouri county declares state of emergency amid suspected ransomware attack

April 3, 2024

Via: ArsTechnica

Jackson County, Missouri, has declared a state of emergency and closed key offices indefinitely as it responds to what officials believe is a ransomware attack that has made some of its IT systems inoperable. “Jackson County has identified significant disruptions […]


Cybersecurity

The Pentagon wants to help boost cybersecurity for small contractors

April 2, 2024

Via: Government Executive

The Pentagon is working on a shared virtual cloud-based workspace for contractors as a way to boost their cybersecurity and part of a larger strategic effort to make defense companies more secure. “There are some things that we’re working on […]


Cybersecurity

Robust remote access security for the utilities sector advances with Zero Trust

March 28, 2024

Via: CIO

Cyberattacks on utilities more than doubled from 2020 to 2022. It’s likely the case that the rapid growth of connected assets is outstripping security capabilities. One analyst firm predicts that by 2026, industrial organizations will have more than 15 billion […]


Cybersecurity

New Russian cyberespionage group APT29 campaign targets politicians

March 26, 2024

Via: CSO Online

Researchers warn that a cyberespionage group linked to Russia’s foreign intelligence service, the SVR, has recently launched a spear-phishing campaign targeting one of Germany’s major political parties. This is a departure from the group’s typical targeting of government agencies and […]


Cybersecurity

New phishing campaign targets US organizations with NetSupport RAT

March 21, 2024

Via: CSO Online

Hundreds of US employees have been targeted in a new email attack that uses accounting lures to distribute malicious documents that deploy a malicious remote access tool known as NetSupport RAT. The attackers use a combination of detection evasion techniques […]


Cybersecurity

“Disabling cyberattacks” are hitting critical US water systems, White House warns

March 20, 2024

Via: ArsTechnica

The Biden administration on Tuesday warned the nation’s governors that drinking water and wastewater utilities in their states are facing “disabling cyberattacks” by hostile foreign nations that are targeting mission-critical plant operations. “Disabling cyberattacks are striking water and wastewater systems […]


Cybersecurity

Alabama Under DDoS Cyberattack by Russian-Backed Hacktivists

March 14, 2024

Via: Dark Reading

Alabama has been grappling with network disruptions, following cyber incidents targeting both state and city governments, and days later, they still appear to be struggling to recover. Alabama’s governor, Kay Ivey, confirmed that a cyberattack on state systems began March […]


Cybersecurity, IT Policy, Tech

FCC Approves Voluntary Cyber Trust Labels for Consumer IoT Products

March 14, 2024

Via: Dark Reading

The Federal Communications Commission (FCC) will be rolling out a voluntary cybersecurity labeling program for Internet of Things (IoT) products for consumers At its public meeting today, the Commission unanimously voted to approve the program, which will allow IoT manufacturers […]


Cybersecurity

Russian hackers target vulnerable webmail servers in Europe for espionage

February 19, 2024

Via: CSO Online

A Russian advanced persistent threat (APT) actor has been using the cross-site scripting (XSS) vulnerabilities in Roundcube webmail servers to target critical government infrastructures in Europe, according to a research by Recorded Future. The threat group, known as Winter Vivern, […]


Cybersecurity, IT Policy, Tech

Biden to veto any efforts to shutter SEC cyber disclosure rules

January 31, 2024

Via: Nextgov

The White House on Wednesday affirmed its commitment to a Securities and Exchange Commission rule that would require publicly traded firms to disclose cybersecurity incidents, declaring that President Joe Biden will veto any legislative efforts to shutter the agency regulation. […]


Cybersecurity

Cyberattacks on state and local governments rose in 2023, says CIS report

January 30, 2024

Via: StateScoop

The Center for Internet Security, the Upstate New York nonprofit that runs information sharing and analysis operations to support government agencies, found in a study announced Tuesday that cyberattacks on state and local governments increased from 2022 to 2023. That’s […]


Cybersecurity

White House: Developers of ‘powerful AI systems’ now have to report safety test results to government

January 29, 2024

Via: Fox News

The White House says “developers of the most powerful AI systems” will now have to report AI safety test results to the Department of Commerce in the wake of an executive order issued by President Biden aimed at “managing the […]


Cybersecurity

Civilian cyber reserves gaining steam at the US federal and state levels

January 24, 2024

Via: CSO Online

Volunteer cybersecurity reserve workforces are growing in the face of infosec worker shortages, with US CyberCommand recently authorized in the 2024 NDAA to create its own civilian cybersecurity reserve corps. The creation of civilian cyber reserves has gained traction over […]


Cybersecurity

Healthcare experienced more cyberattacks than any other sector in 2023

January 18, 2024

Via: TechSpot

According to technology research provider Omdia, the healthcare sector suffered 241 cyberattacks during the first nine months of 2023. That’s over 100 more than the government (147) and almost three times more than software, hardware, and IT services (91). The […]


Cloud Computing, Cybersecurity, Tech

FBI warns against cloud credential-stealing Androxgh0st botnet

January 17, 2024

Via: CSO Online

The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency (CISA) have published an urgent advisory about the Androxgh0st botnet, which is being used to steal cloud credentials from major platforms, including AWS, SendGrid, and Microsoft Office 365. […]


Cybersecurity

Turkish ransomware campaign hacks into weak MSSQL servers: report

January 10, 2024

Via: CSO Online

Poorly secured Microsoft SQL servers in the US, EU, and LATAM are being attacked by financially motivated Turkish threat actors in an ongoing campaign to deliver MIMIC ransomware payloads, according to a Securonix research. The financial cyberthreat campaign named RE#TURGENCE […]


Cybersecurity

Stronger together: Creating a cyber-secure community

January 4, 2024

Via: CSO Online

Ransomware activity continues to threaten organizations and people while breach attempts are becoming more sophisticated and targeted – due largely to an increase in Ransomware-as-a-Service (RaaS) operations. The reality is that in an interconnected world, organizations can’t fully protect their […]