Last week CISA took a major step in the fight against ransomware and state-sponsored attacks by issuing Binding Operational Directive 23-02. This directive directly calls out an area where threat actors are the most active and successful in the wild—the exploitation of network infrastructure appliances such as VPNs, switches, routers, and firewalls as well as […]| Eclypsium | Supply Chain Security for the Modern Enterprise
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread| hackread.com
Learn how Volt Typhoon exploits VPN zero-day flaws in Fortinet, Ivanti & others, and how Versa protects enterprises with Zero Trust & NGFW.| The Versa Networks Blog - The Versa Networks Blog
The EPA issued an enforcement alert Monday detailing "urgent cybersecurity threats and vulnerabilities" to community drinking water systems.| USA TODAY
Understand how this small and home office router botnet can impact your business and how to combat the threat.| Lumen Blog
US government agencies took down the botnet of Chinese APT Volt Typhoon, used to target critical infrastructure for nation-state espionage| Infosecurity Magazine
On December 13, 2023, Lumen’s Black Lotus Labs reported our findings on the KV-botnet, a covert data transfer network used by state-sponsored actors based in China to conduct espionage and intelligence activities targeting U.S. critical infrastructure.| Lumen Blog
Black Lotus Labs uncovered a zero-day exploit in Versa Director servers. Learn its impact on SD-WAN security and how to mitigate threats.| Lumen Blog
CISA Director Jen Easterly says the CrowdStrike-linked outage serves as a “dress rehearsal” for what China may have planned for U.S. critical infrastructure.| CyberScoop
Insecure by design, VPNs are no longer Virtual Private Networks, but rather, on occasion, Virtual| zeronetworks.com
SUMMARY| Cybersecurity and Infrastructure Security Agency CISA
In recent months, we’ve concluded within Microsoft that the increasing speed, scale, and sophistication of cyberattacks call for a new response. Therefore, we’re launching today across the company a new initiative to pursue our next generation of cybersecurity protection – what we’re calling our Secure Future Initiative (SFI).| Microsoft On the Issues
Summary| Cybersecurity and Infrastructure Security Agency CISA