Microsoft Warns Threat Actors Continue to Exploit Zerologon Bug

Tech giant and feds this week renewed their urge to organizations to update Active Directory domain controllers. Continue reading Microsoft Warns Threat Actors Continue to Exploit Zerologon Bug

FBI, DHS, HHS Warn of Imminent, Credible Ransomware Threat Against U.S. Hospitals

On Monday, Oct. 27, KrebsOnSecurity began following up on a tip from a reliable source that an aggressive Russian cybercriminal gang known for deploying ransomware was preparing to disrupt information technology systems at hundreds of hospitals, clinics and medical care facilities across the United States. Today, officials from the FBI and the U.S. Department of Homeland Security hastily assembled a conference call with healthcare industry executives warning about an “imminent cybercrime threat to U.S. hospitals and healthcare providers.” Continue reading FBI, DHS, HHS Warn of Imminent, Credible Ransomware Threat Against U.S. Hospitals

Feds Sound Alarm Over Emotet Attacks on State, Local Govs

CISA warned already-strained public-sector entities about disturbing spikes in Emotet phishing attacks aimed at municipalities. Continue reading Feds Sound Alarm Over Emotet Attacks on State, Local Govs

Department of Homeland Security Cybersecurity: Top 10 Vulnerabilities Still Being Exploited

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (DHS CISA) recently released a list of the top 10 most commonly exploited software vulnerabilities across the last four years.
Apache Struts was the second most a… Continue reading Department of Homeland Security Cybersecurity: Top 10 Vulnerabilities Still Being Exploited

Homeland Security sued over secretive use of face recognition

As of June 2019, CBP had processed more than 20 million travelers using facial recognition, civil rights group ACLU says. Continue reading Homeland Security sued over secretive use of face recognition

Ex-Inspector General indicted for stealing data on 250k govt colleagues

Crime doesn’t pay, even if you have the audacity to try to sell your employer its own, free software and personal data on your own colleagues. Continue reading Ex-Inspector General indicted for stealing data on 250k govt colleagues

Now you need a notarized document to get a .gov domain

The US government is tightening its rules around the registration of government web domains to stop fraudsters impersonating government sites. Continue reading Now you need a notarized document to get a .gov domain

Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work

The Department of Homeland Security and two U.S. military branches already had discontinued use of the app based on concerns over Chinese data-security and censorship practices. Continue reading Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work

Ransomware attack forces 2-day shutdown of natural gas pipeline

The attacker(s) infected both IT and operational networks with an unspecified ransomware strain, though the facility never lost control. Continue reading Ransomware attack forces 2-day shutdown of natural gas pipeline