Siemens Patches Improper Access Vulnerability in Ruggedcom Protocol

Industrial manufacturer Siemens is encouraging users running devices that use its Ruggedcom protocol to apply firmware updates this week. The updates resolve a serious and remotely exploitable vulnerability that could let an attacker carry out administ… Continue reading Siemens Patches Improper Access Vulnerability in Ruggedcom Protocol

DHS promotes from within to fill cyber deputy assistant secretary role

Rick Driggers, one of two deputy directors at the Department of Homeland Security’s 24-hour watch operation, the National Cybersecurity and Communications Integration Center, has been promoted to be DHS deputy assistant secretary for cybersecurity and communications, a DHS official confirmed Monday. Driggers is taking over the post vacated by DHS veteran Danny Toler, and once held by former Federal CISO Greg Touhill.  The official told CyberScoop Driggers “will gradually assume the responsibilities of his new position over the next few weeks.” In his new position, Driggers reports to Assistant Secretary for Cybersecurity and Communications Jeannette Manfra. In a brief statement emailed to reporters, Manfra said she was “extremely grateful” to Toler. “He has done a great job keeping the ship afloat as the acting assistant secretary.  His contributions to the organization over the past five years will endure.  I believe the department is in a better place as a result of his work, […]

The post DHS promotes from within to fill cyber deputy assistant secretary role appeared first on Cyberscoop.

Continue reading DHS promotes from within to fill cyber deputy assistant secretary role

Privilege Escalation Flaw Patched in Schneider Wonderware

Schneider Electric patched a vulnerability in the Tableau Server running in its Wonderware analytics and visualization platform that could allow an attacker to elevate privileges. Continue reading Privilege Escalation Flaw Patched in Schneider Wonderware

U.S. oil and gas companies are ‘still trying to catch up’ on cybersecurity, experts say

Digital systems and internet networks belonging to U.S. oil and gas companies have increasingly come under attack from hackers in recent years, experts tell CyberScoop. The Homeland Security Department received — between 2011 and 2015 — roughly 350 reports from domestic energy companies who were concerned about hackers probing or breaking into their systems, according to the Houston Chronicle, which cited data from the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT). In this context, the term “incidents” refers to times people called the agency rather than actual breaches. Nearly 900 “security flaws” were discovered by DHS during that timeframe — a figure which some private sector cybersecurity experts claim appears low. Making sure that industrial control systems, or ICS, are secure has become an especially important mission for Gulf Coast oil, gas and petrochemical companies in addition to the local Coast Guard, the newspaper reported. Industrial equipment often used […]

The post U.S. oil and gas companies are ‘still trying to catch up’ on cybersecurity, experts say appeared first on Cyberscoop.

Continue reading U.S. oil and gas companies are ‘still trying to catch up’ on cybersecurity, experts say