Tag: cisa
-
CISA Released A Free Guide to Enhance OT Product Security
To address rising cyber threats targeting critical infrastructure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new step-by-step guide designed to help organizations select and deploy secure operational technology (OT) products. The guide, titled “Secure by Demand: Priority Considerations for OT Owners and Operators when Selecting Digital Products,” highlights key security features…
-
Mit welchen Gefahren die Betriebstechnik 2025 rechnen muss
Für 2025 erwarten Experten verstärkte Cyberangriffe auf kritische Infrastrukturen, besonders in der Industrie, im Gesundheitswesen sowie im Transport- und Energiesektor. Schwachstellen sind ungesicherte OT- und IoT-Geräte. Laut US-Sicherheitsbehörde CISA zielen Bedrohungsgruppen zunehmend auf SCADA-Systeme, Sensoren und ältere Steuergeräte. First seen on itsicherheit-online.com Jump to article: www.itsicherheit-online.com/news/cybersecurity/mit-welchen-gefahren-die-betriebstechnik-2025-rechnen-muss/
-
Biden’s final push: Using AI to bolster cybersecurity standards
Tags: access, ai, attack, china, cisa, compliance, cyber, cyberattack, cybersecurity, data, defense, detection, email, exploit, finance, framework, government, hacker, incident, infrastructure, intelligence, office, privacy, programming, resilience, risk, software, strategy, technology, threat, vulnerabilityIn a decisive move to strengthen national cybersecurity, President Joe Biden is poised to sign an executive order imposing stringent security standards for federal agencies and contractors. Scheduled for publication in the coming days, the directive will emphasize integrating artificial intelligence (AI) into cyber defense strategies while addressing systemic vulnerabilities in software security, reported Reuters.This…
-
CISA director reiterates prior calls for C-suites, boards to take cyber risk ownership
Jen Easterly said companies need to consider cybersecurity threats as core risks that need to be fully incorporated into corporate business strategy. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-director-boards-cyber-risk/737042/
-
CISA report touts cyber hygiene enrollment surge for critical infrastructure orgs
The cyber agency said that surge has fueled “a moderate impact” in CI sectors meeting its cybersecurity performance goals. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisa-cyber-hygiene-critical-infrastructure-report/
-
CISA Adds Mitel, Oracle, flaws to the KEV list
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-adds-mitel-oracle-flaws-to-the-kev-list
-
The Future of CISA in Healthcare in the New Administration
Many important efforts by the Cybersecurity Infrastructure and Security Agency to help the healthcare sector and other critical infrastructure sectors bolster their cybersecurity are likely to continue under the incoming Trump administration, predicted CISA Deputy Director Nitin Natarajan. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/interviews/future-cisa-in-healthcare-in-new-administration-i-5437
-
CISA adds Mitel and Oracle bugs to exploited vulnerabilities list
First seen on scworld.com Jump to article: www.scworld.com/news/cisa-adds-mitel-and-oracle-bugs-to-exploited-vulnerabilities-list
-
Exit Interview: CISA’s Nitin Natarajan on Threats to Watch
Deputy Director Reflects on Term and Offers Advice to Successors. From application security to zero trust, it’s been a busy four years for the current leaders of the U.S. Cybersecurity and Infrastructure Security Agency. Deputy Director Nitin Natarajan discusses the agency’s accomplishments and the threats that await the next administration’s cyber leaders. First seen on…
-
U.S. CISA adds Ivanti Connect Secure, Policy Secure, and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Connect Secure, Policy Secure, and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Ivanti Connect Secure Vulnerability, tracked as CVE-2025-0282 (CVSS score: 9.0) to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability Ivanti impacted Ivanti Connect…
-
Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
3 CVEs added to CISA’s catalog First seen on theregister.com Jump to article: www.theregister.com/2025/01/08/mitel_0_day_oracle_rce_under_exploit/
-
BeyondTrust breach affected Treasury Department only
The government cybersecurity agency says fallout from a breach against BeyondTrust last month has not affected other federal agencies, although the investigation is ongoing. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366617777/CISA-BeyondTrust-breach-impacted-Treasury-Department-only
-
Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackers
CISA has added Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic Server (CVE-2020-2883) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/01/08/mitel-micollab-oracle-weblogic-server-vulnerabilities-exploited-by-attackers/
-
CISA Warns of Mitel MiCollab Vulnerabilities Exploited in Attacks
CISA says two recently disclosed path traversal vulnerabilities in the Mitel MiCollab collaboration platform have been exploited in attacks. The post CISA Warns of Mitel MiCollab Vulnerabilities Exploited in Attacks appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/cisa-warns-of-mitel-micollab-vulnerabilities-exploited-in-attacks/
-
U.S. CISA adds Oracle WebLogic Server and Mitel MiCollab flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle WebLogic Server and Mitel MiCollab flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle WebLogic Server and Mitel MiCollab vulnerabilities, to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for the vulnerabilities added to the catalog:…
-
Oracle WebLogic Vulnerability Actively Exploited in Cyber Attacks CISA
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of critical vulnerabilities in various software, particularly spotlighting an unspecified vulnerability in Oracle WebLogic Server. This announcement comes as part of CISA’s efforts to enhance cybersecurity across federal agencies and beyond, with three new vulnerabilities added to their Known Exploited…
-
Oracle WebLogic Vulneraiblity Actively Exploited in Cyber Attacks CISA
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of critical vulnerabilities in various software, particularly spotlighting an unspecified vulnerability in Oracle WebLogic Server. This announcement comes as part of CISA’s efforts to enhance cybersecurity across federal agencies and beyond, with three new vulnerabilities added to their Known Exploited…
-
CISA Flags Critical Flaws in Mitel and Oracle Systems Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three flaws impacting Mitel MiCollab and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The list of vulnerabilities is as follows -CVE-2024-41713 (CVSS score: 9.1) – A path traversal vulnerability in Mitel MiCollab that could allow an attacker…
-
CISA Issues New Goals to Strengthen IT Cybersecurity
CISA Urges IT and Design Sector Software Developers to Improve Cyber Hygiene. The Cybersecurity and Infrastructure Security Agency is urging the information technology and design sector to strengthen foundational cybersecurity practices throughout the software development lifecycle by aiming to achieve a series of new sector-specific goals released Tuesday. First seen on govinfosecurity.com Jump to article:…
-
Chinese hack only impacted Treasury Department
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-chinese-hack-only-impacted-treasury-department
-
Third-Party Data Breach Limited to Treasury Dept.
The breach was carried out by exploiting CVE-2024-12356 in BeyondTrust cybersecurity company, just last week. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cisa-third-party-data-breach-limited-treasury-dept
-
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/
-
CISA says hack targeting Treasury Department did not impact other federal agencies
BeyondTrust says an investigation of a December attack spree is nearing completion and SaaS instances are fully patched. Hackers used a stolen key to attack Treasury workstations. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-hack-treasury-federal-agencies/736654/
-
Prognosen für die OT-Sicherheit in 2025
Für das Jahr 2025 erwarten die ThreatLabZ-Researcher von Zscaler eine wachsende Angriffswelle auf kritische Infrastrukturen, Produktionsanlagen und Cloud-native Anwendungen. Gerade die Bereiche der Fertigungsindustrie, Krankenhäuser, Transport- oder Energienetze waren schon immer schwer gegen Angriffe von außen abzusichern, da diese Branchen mit ungeschützten OT-/IoT-Endpunkten agieren, die keine Sicherheitsagenten hosten können. Die CISA hat einen massiven Anstieg…
-
CISA says Treasury was the only US agency breached via BeyondTrust
The US Cybersecurity and Infrastructure Security Agency (CISA) has shared on Monday that the Treasury Department was the only US federal agency affected by the recent … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/01/07/cisa-says-treasury-was-the-only-us-agency-breached-via-compromised-beyondtrust-instances/
-
No Federal Agency Beyond Treasury Impacted by BeyondTrust Incident
CISA says no federal agencies other than Treasury were impacted by the recent compromise of a BeyondTrust cloud-based service. The post CISA: No Federal Agency Beyond Treasury Impacted by BeyondTrust Incident appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/cisa-no-federal-agency-beyond-treasury-impacted-by-beyondtrust-incident/
-
CISA Claims Treasury Breach Did Not Impact Other Agencies
The US Cybersecurity and Infrastructure Security Agency claims a recent China-linked breach was confined to the Treasury First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-treasury-breach-not-impact/
-
No Wider Federal Impact from Treasury Cyber Attack, Investigation Ongoing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday said there are no indications that the cyber attack targeting the Treasury Department impacted other federal agencies.The agency said it’s working closely with the Treasury Department and BeyondTrust to get a better understanding of the breach and mitigate its impacts.”The security of federal systems and…
-
Treasury was only federal agency impacted by recent China breach
The Cybersecurity and Infrastructure Security Agency said in a short statement that there is “no indication that any other federal agencies” have been impacted by a breach of Treasury Department systems attributed to state-sponsored hackers from China.]]> First seen on therecord.media Jump to article: therecord.media/cisa-treasury-only-agency-affected-recent-china-breach

