CISA Shifting Einstein Detection System Deeper Into Networks

CISA Shifting Einstein Detection System Deeper Into Networks

Fraud Management & Cybercrime , Fraud Risk Management , Governance & Risk Management Move Away From Perimeter Designed to Help Agencies Battle Supply Chain Attacks Scott Ferguson (Ferguson_Writes) • June 22, 2021     Acting CISA Director Brandon Wales The U.S. Cybersecurity and Infrastructure Agency is moving its Einstein intrusion detection system deeper into federal…

CVE-2021-20734 – Alert Detail – Security Database

CVE-2021-20734 – Alert Detail – Security Database

Executive Summary Informations Name CVE-2021-20734 First vendor Publication 2021-06-22 Vendor Cve Last vendor Modification 2021-06-22 Security-Database Scoring CVSS v3 Cvss vector : N/A Overall CVSS Score NA Base Score NA Environmental Score NA impact SubScore NA Temporal Score NA Exploitabality Sub Score NA   Calculate full CVSS 3.0 Vectors scores Security-Database Scoring CVSS v2 Cvss…

The Changing Nature of the Insider Threat

The Changing Nature of the Insider Threat

Fraud Management & Cybercrime , Fraud Risk Management , Governance & Risk Management Joseph Blankenship of Forrester Describes Efforts to Enlist Insiders for Fraud Anna Delaney (annamadeline) • June 22, 2021     Joseph Blankenship, vice president, research director, Forrester Cybercriminals and nation-states are attempting to recruit insiders at companies around…

Using a Medical Device Cybersecurity Bill of Materials

Using a Medical Device Cybersecurity Bill of Materials

When medical device makers provide a software bill of materials for components contained in their products, it’s critical to make that voluminous security information actionable for healthcare customers, says Rob Suárez, CISO at medical device maker Becton Dickinson and Co., or BD. The Food and Drug Administration in draft guidance released in 2018 – which…

Wormable DarkRadiation Ransomware Targets Linux and Docker Instances

Wormable DarkRadiation Ransomware Targets Linux and Docker Instances

Cybersecurity researchers have disclosed a new ransomware strain called “DarkRadiation” that’s implemented entirely in Bash and targets Linux and Docker cloud containers, while banking on messaging service Telegram for command-and-control (C2) communications. “The ransomware is written in Bash script and targets Red Hat/CentOS and Debian Linux distributions,” researchers from Trend Micro said in a report…

CVE-2021-32698 – Alert Detail – Security Database

CVE-2021-32698 – Alert Detail – Security Database

Executive Summary Informations Name CVE-2021-32698 First vendor Publication 2021-06-21 Vendor Cve Last vendor Modification 2021-06-21 Security-Database Scoring CVSS v3 Cvss vector : N/A Overall CVSS Score NA Base Score NA Environmental Score NA impact SubScore NA Temporal Score NA Exploitabality Sub Score NA   Calculate full CVSS 3.0 Vectors scores Security-Database Scoring CVSS v2 Cvss…

Firewall Rules Could Have Blunted SolarWinds Malware

Firewall Rules Could Have Blunted SolarWinds Malware

Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime , Fraud Risk Management Agency Says Blocking Outgoing Connections From Orion Would Have Stopped Malware Jeremy Kirk (jeremy_kirk) • June 22, 2021     Federal agencies could have prevented follow-on attacks after the SolarWinds supply chain attack by using recommended firewall configurations, but this step isn’t…

Hacker ‘Tried to Poison’ Water Treatment Plan That Serves San Francisco Bay Area in US: Report

Hacker ‘Tried to Poison’ Water Treatment Plan That Serves San Francisco Bay Area in US: Report

A hacker had accessed a water treatment plant in the San Francisco Bay Area in January and deleted programs that were used to treat drinking water, the US media reported. In the latest cyberattack to come to light on an American facility, the hacker used the username and password of a former employee to log…