Volt Typhoon targets US critical infrastructure with living-off-the-land techniques

Microsoft has uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States. The attack is carried out by Volt Typhoon, a state-sponsored actor based in China Read More …

Cyber Chiefs Forge Partnerships With Physical Security Units As Combined Threats Grow

Cyberattacks are blurring the lines between physical and digital risks, forcing cybersecurity and physical security chiefs to work closely together to combat threats, executives say. Cyber-physical threats, where an attack on computer systems might cause damage to property or people, Read More …

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe

The X_Trader software supply chain attack affected more organizations than 3CX. Initial investigation by Symantec’s Threat Hunter Team has, to date, found that among the victims are two critical infrastructure organizations in the energy sector, one in the U.S. and Read More …

Growth of ‘hackers for hire’ will lead to more attacks and unpredictable threats, UK cyber security agency warns

The number of “hackers for hire” is set to grow over the next five years, leading to more cyber attacks and increasingly unpredictable threats, the UK’s cyber security agency has warned. A rise in spyware is also anticipated and other Read More …

Critical infrastructure gear is full of flaws, but hey, at least it’s certified

Devices used in critical infrastructure are riddled with vulnerabilities that can cause denial of service, allow configuration manipulation, and achieve remote code execution, according to security researchers. And most of these operational technology (OT) products – which include industrial control Read More …

UK Government sets out strategy to protect NHS from cyber attacks

The government will provide a plan to promote cyber resilience across the health and care sectors by 2030, protecting both services and patients. New strategy sets out 5 key ways to build cyber resilience in health and care by 2030 Read More …

Understanding Cyber Threats in Transport

This new report maps and analyses cyber incidents in relation to aviation, maritime, railway and road transport covering the period of January 2021 to October 2022. The report brings new insights into the cyber threats of the transport sector. In Read More …

NATO and European Union launch task force on resilience of critical infrastructure

First announced by NATO Secretary General Jens Stoltenberg and European Commission President Ursula von der Leyen in January, the initiative brings together officials from both organisations to share best practices, share situational awareness, and develop principles to improve resilience. The Read More …

ECB: The Quick and the Dead – building up cyber resilience in the financial sector

The proliferation of cyber threat actors combined with an increase in remote working and greater digital interconnectedness is raising the risk, frequency and severity of cyberattacks.[1] Increasingly, cyber criminals are launching ransomware attacks and demanding payment in crypto. Cyberattacks related to Read More …

TSA issues new cybersecurity requirements for airport and aircraft operators

Today, the Transportation Security Administration (TSA) issued a new cybersecurity amendment on an emergency basis to the security programs of certain TSA-regulated airport and aircraft operators, following similar measures announced in October 2022 for passenger and freight railroad carriers. This is part of the Read More …