CISA: China’s Volt Typhoon Hackers Planning Critical Infrastructure Disruption

New CISA alert includes technical mitigations to harden attack surfaces and instructions to hunt for the Chinese government-backed hackers.
The post CISA: China’s Volt Typhoon Hackers Planning Critical Infrastructure Disruption appeared first on … Continue reading CISA: China’s Volt Typhoon Hackers Planning Critical Infrastructure Disruption

US Slaps Sanctions on ‘Dangerous’ Iranian Hackers Linked to Water Utility Hacks 

The US government slaps sanctions against six Iranian government officials linked to cyberattacks against Israeli PLC vendor Unitronics.
The post US Slaps Sanctions on ‘Dangerous’ Iranian Hackers Linked to Water Utility Hacks  appeared first on Securit… Continue reading US Slaps Sanctions on ‘Dangerous’ Iranian Hackers Linked to Water Utility Hacks 

CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products

In an unprecedented move, CISA is demanding that federal agencies disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure products within 48 hours.
The post CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products appeared … Continue reading CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products

US Gov Disrupts SOHO Router Botnet Used by Chinese APT Volt Typhoon

The US government neutralizes a botnet full of end-of-life Cisco and Netgear routers being by a notorious Chinese APT group.
The post US Gov Disrupts SOHO Router Botnet Used by Chinese APT Volt Typhoon appeared first on SecurityWeek.
Continue reading US Gov Disrupts SOHO Router Botnet Used by Chinese APT Volt Typhoon

After Delays, Ivanti Patches Zero-Days and Confirms New Exploit

Ivanti documents a brand-new zero-day and belatedly ships patches; Mandiant is reporting “broad exploitation activity.”
The post After Delays, Ivanti Patches Zero-Days and Confirms New Exploit appeared first on SecurityWeek.
Continue reading After Delays, Ivanti Patches Zero-Days and Confirms New Exploit

Ivanti Struggling to Hit Zero-Day Patch Release Schedule

Ivanti is struggling to hit its own timeline for the delivery of patches for critical — and already exploited — flaws in its flagship VPN appliances.
The post Ivanti Struggling to Hit Zero-Day Patch Release Schedule appeared first on SecurityWeek.
Continue reading Ivanti Struggling to Hit Zero-Day Patch Release Schedule

Identity Security Firm Silverfort Lands $116 Million Investment

Israeli late-stage startup Silverfort raises a whopping $116 million in new financing to scale its ambitions in the identity security space.
The post Identity Security Firm Silverfort Lands $116 Million Investment appeared first on SecurityWeek.
Continue reading Identity Security Firm Silverfort Lands $116 Million Investment