Iranian hackers are going after critical infrastructure sector passwords, agencies caution

An international advisory says that the purpose of the “brute force” attacks is to sell the info to cybercrime forums.

The post Iranian hackers are going after critical infrastructure sector passwords, agencies caution appeared first on CyberScoop.

Continue reading Iranian hackers are going after critical infrastructure sector passwords, agencies caution

Organizations can substantially lower vulnerabilities with secure-by-design practices, report finds

Ex-National Cyber Director Inglis says “quantitative data” in Secure Code Warrior’s report shows the importance of the cybersecurity practice.

The post Organizations can substantially lower vulnerabilities with secure-by-design practices, report finds appeared first on CyberScoop.

Continue reading Organizations can substantially lower vulnerabilities with secure-by-design practices, report finds

Tens of thousands of IPs vulnerable to Fortinet flaw dubbed ‘must patch’ by feds

The Shadowserver Foundation put the figure at around 87,000 for a vulnerability rated as critical and first discovered in February.

The post Tens of thousands of IPs vulnerable to Fortinet flaw dubbed ‘must patch’ by feds appeared first on CyberScoop.

Continue reading Tens of thousands of IPs vulnerable to Fortinet flaw dubbed ‘must patch’ by feds

CISA advisory committee approves four draft reports on critical infrastructure resilience

Each report includes recommendations for the cyber agency to tackle, with the overarching goal of combating threats from China.

The post CISA advisory committee approves four draft reports on critical infrastructure resilience appeared first on CyberScoop.

Continue reading CISA advisory committee approves four draft reports on critical infrastructure resilience

What’s new from this year’s Counter Ransomware Initiative summit, and what’s next

Action plans, different kinds of meetings and more have all been in the mix, top administration officials told CyberScoop.

The post What’s new from this year’s Counter Ransomware Initiative summit, and what’s next appeared first on CyberScoop.

Continue reading What’s new from this year’s Counter Ransomware Initiative summit, and what’s next

Automatic tank gauge vendors alerted of software vulnerabilities in their products

If exploited, the vulnerabilities could give hackers full administrative access to critical networks found in the management systems for large fuel storage.

The post Automatic tank gauge vendors alerted of software vulnerabilities in their products appeared first on CyberScoop.

Continue reading Automatic tank gauge vendors alerted of software vulnerabilities in their products

Exclusive: House Homeland Security chair releases, pushes forth cyber workforce bill

CyberScoop has the full details of the legislation, under which Rep. Mark Green wants to establish an ROTC-like program and more.

The post Exclusive: House Homeland Security chair releases, pushes forth cyber workforce bill appeared first on CyberScoop.

Continue reading Exclusive: House Homeland Security chair releases, pushes forth cyber workforce bill

U.S. agencies say Iranian hackers tried to pass ‘non-public’ Trump campaign docs to Biden’s campaign

According to a joint statement from CISA, ODNI and the FBI, there is no evidence that anyone from Biden’s campaign responded to the offer.

The post U.S. agencies say Iranian hackers tried to pass ‘non-public’ Trump campaign docs to Biden’s campaign appeared first on CyberScoop.

Continue reading U.S. agencies say Iranian hackers tried to pass ‘non-public’ Trump campaign docs to Biden’s campaign

Newmark initiative will bring online a network of civil defense hackers

A new initiative links together volunteer cyber programs with those most needing help.

The post Newmark initiative will bring online a network of civil defense hackers appeared first on CyberScoop.

Continue reading Newmark initiative will bring online a network of civil defense hackers

CISA warns of hackers exploiting bug for end-of-life Ivanti product

Ivanti’s Cloud Service Appliance has a “high severity vulnerability” being exploited in the wild.

The post CISA warns of hackers exploiting bug for end-of-life Ivanti product appeared first on CyberScoop.

Continue reading CISA warns of hackers exploiting bug for end-of-life Ivanti product