CVE-2021-37708
CVE-2021-37708
The United States is launching three new research programs designed to protect America’s critical energy infrastructure systems. The Department of Energy released information on the projects earlier this week, which will be spearheaded by the department’s Office of Cybersecurity, Energy Security, and Emergency Response. The programs will aim to protect the US energy system from…
A group of threat actors maintains an active attack targeting GitHub Actions systems with the intention of extracting cryptocurrency in a hacking variant known as cryptojacking. As you may remember, GitHub Actions is a CI/CD solution that makes it easier to automate particular resource flows, as well as allow for periodic task configuration. Apparently, this…
A Didi logo is seen at the headquarters of Didi Chuxing in Beijing on November 20, 2020. REUTERS/Florence Lo/File Photo/File Photo Chinese regulators said they will tighten control of domestic firms listed overseas. The move came after the Beijing-led cybersecurity probe against Didi, Reuters reported. On Sunday, China said Didi “has serious violations of laws…
The bipartisan leaders of two Senate committees on Thursday introduced legislation to shore up the cybersecurity of critical infrastructure after months of crippling cyberattacks. The Department of Homeland Security (DHS) Industrial Control Systems Capabilities Enhancement Act would direct the Cybersecurity and Infrastructure Security Agency (CISA) to lead efforts to understand threats against industrial control systems. The…
3rd Party Risk Management , Governance & Risk Management , IT Risk Management NIST, CISA Highlight Key Steps to Take Akshaya Asokan (asokan_akshaya) • April 28, 2021 The U.S. Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology have released a report providing insights on how to enhance supply…
3rd Party Risk Management , Breach Notification , Cybercrime Flaw in Network Traffic Security Management Platform Ranked as Highly Critical Akshaya Asokan (asokan_akshaya) • March 21, 2021 Attackers are exploiting a critical remote code vulnerability in F5 Networks’ BIG-IP platform, tracked as CVE-2021-22986, for which the company released patches on March 10. See…