Reducing the Attack Surface for End-of-Support Edge Devices


The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors.

Nation-state threat actors exploit end-of-support (EOS) edge devices—including, but not limited to, load balancers, firewalls, routers, and virtual private network (VPN) gateways—to gain network access, maintain presence, and compromise sensitive data. Organizations using EOS devices are particularly vulnerable to compromise, especially if they are using EOS devices exposed to the public internet or external systems at the network’s “edge.”

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Uncovering and Defending Systems Against Attacks With Layers of Remote Control

    January 10, 2022

    As organizations brace themselves for the year ahead, now is an opportune time to take stock of how they can strengthen their security posture and shore up their defenses. While organizations may have the power of leading-edge cybersecurity solutions on their side, malicious actors continue to work diligently to refine their methods and take advantage ...

  • TSA to impose cybersecurity mandates on railroad and aviation industries

    January 6, 2022

    The Transportation Security Administration will impose new cybersecurity mandates on the railroad and airline industries, including reporting requirements as part of a department effort to force compliance in the wake of high-profile cyberattacks on critical industries, Homeland Security Secretary Alejandro Mayorkas announced Wednesday. DHS is moving to require more companies in critical transportation industries to meet ...

  • FTC warns companies to remediate Log4j security vulnerability

    January 4, 2022

    Log4j is a ubiquitous piece of software used to record activities in a wide range of systems found in consumer-facing products and services. Recently, a serious vulnerability in the popular Java logging package, Log4j (CVE-2021-44228) was disclosed, posing a severe risk to millions of consumer products to enterprise software and web applications. This vulnerability is ...

  • What the Rise in Cyber-Recon Means for Your Security Strategy

    December 30, 2021

    As we move into 2022, bad actors are ramping up their reconnaissance efforts to ensure more successful and more impactful cyberattacks. And that means more zero-day exploits are on the horizon. When seen through an attack chain such as the MITRE ATT&CK framework, campaigns are frequently discussed in terms of left-hand and right-hand phases of threats. ...

  • Albanian Army to establish a unit for cyber defense

    December 29, 2021

    The Department of Defense has launched a project in collaboration with US military cyber security partners, creating greater protection against external attacks that may occur in the future. This was announced by the Minister of Defense, Niko Peleshi from Elbasan during the question about the scandal with the publication of salaries and personal data of over ...

  • West Virginia State workers to be paid on time despite ransomware attack

    December 27, 2021

    West Virginia state workers will be paid on schedule this week, despite a ransomware attack that recently crippled a software provider that helps manage time and leave for more than 35,000 state employees. The State Auditor’s Office reassured employees Monday that checks will be deposited on schedule Friday. For additional assurance, officials urged state workers to check ...