hrbrmstr, to random
@hrbrmstr@mastodon.social avatar

Well, good to know the dashboard automation is working https://kev.hrbrmstr.app/

mattodon, to NixOS

I wrote an answer from the perspective of a user to a recent request for comments by about software identifiers.

It's now published here: https://tweag.io/blog/2024-03-12-nix-as-software-identifier/

br00t4c, to random
@br00t4c@mastodon.social avatar

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

#cisa #cybercrime

https://go.theregister.com/feed/www.theregister.com/2024/03/08/magnet_goblin_ivanti/

br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

LockBit's contested claim of fresh ransom payment suggests it's been well hobbled

#cisa

https://go.theregister.com/feed/www.theregister.com/2024/03/04/in_brief/

governa, to microsoft
@governa@fosstodon.org avatar
itnewsbot, to ProgrammingLanguages

The NSA list of memory-safe programming languages has been updated - The US government says it would be better for them if you ceased using C or C++ wh... - https://readwrite.com/the-nsa-list-of-memory-safe-programming-languages-has-been-updated/ #nsarecommendsprogrammingtools #programminglanguages #memory-safety #whitehouse #readwrite #cisa #nsa

majorlinux, to random
@majorlinux@toot.majorshouse.com avatar

Somebody at Ma Bell wasn't having a great day.

AT&T outage reportedly caused by update but US gov't investigating - Desk Chair Analysts

https://dcanalysts.net/att-outage-reportedly-caused-by-update-by-us-govt-investigating/

#ATT #CISA #DHS #FBI #Outage

RedPacketSecurity, to OSINT
governa, to random
@governa@fosstodon.org avatar

#CISA Warning: Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability

https://thehackernews.com/2024/02/cisa-warning-akira-ransomware.html

YourAnonRiots, to Cybersecurity Japanese

Think twice before leaving old employee accounts active!

#CISA reports a major cyber attack on a state government organization. Attackers used leaked credentials from a former employee's administrator account to breach the network.

https://thehackernews.com/2024/02/us-state-government-network-breached.html

#cybersecurity

YourAnonRiots, to cisco Japanese

⚠️ warns of hackers exploiting a security flaw (CVE-2020-3259) in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software in attacks.

https://thehackernews.com/2024/02/cisa-warning-akira-ransomware.html

cybernews, to Cybersecurity
governa, to random
@governa@fosstodon.org avatar
YourAnonRiots, to Cybersecurity Japanese

🔒 #CISA teams up with #OpenSSF to introduce a framework called "Principles for Package Repository Security," aimed at fortifying open-source software ecosystems against cyber threats.

https://thehackernews.com/2024/02/cisa-and-openssf-release-framework-for.html

#cybersecurity #hacking

simontsui, to random

Hot off the press! CISA adds CVE-2023-43770 (6.1 medium) Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
🔗 (to be replaced later) https://www.cisa.gov/known-exploited-vulnerabilities-catalog

#CISA #KEV #KnownExploitedVulnerabilitiesCatalog #vulnerability #eitw #Roundcube #XSS #activeexploitation #CVE_2023_43770

simontsui,

Why you should care about CVE-2023-43770:
ESET Research previously reported on 25 October 2023 that the Winter Vivern APT was exploiting a similar RoundCube cross-site scripting vulnerability CVE-2023-5631 as a zero-day against European overnmental entities and a think tank.

#CISA #KEV #KnownExploitedVulnerabilitiesCatalog #vulnerability #eitw #Roundcube #XSS #activeexploitation #CVE_2023_43770 #WinterVivern #APT #cyberespionage

simontsui, to Cybersecurity

CISA, on behalf of the collective group of industry and government partners that comprise the Joint Cyber Defense Collaborative (JCDC), released JCDC’s 2024 Priorities. Similar to the 2023 JCDC Planning Agenda, JCDC’s 2024 Priorities will help focus the collective group on developing high-impact and collaborative solutions to the most pressing cybersecurity challenges.

🔗 https://www.cisa.gov/topics/partnerships-and-collaboration/joint-cyber-defense-collaborative/2024-jcdc-priorities

#CISA #JCDC #cybersecurity #APT

simontsui,

See related CISA blog: Extending the Breadth and Depth of our Partnerships - JCDC 2024 Priorities

2024 priorities are defined around three focus areas. The first focus area, Defend Against Advanced Persistent Threat (APT) Operations, aligns JCDC strategic and operational efforts to counter known and suspected APT campaigns that target critical infrastructure sectors with the potential to impact National Critical Functions. The second focus area, Raise the Baseline, encompasses JCDC efforts to improve the cybersecurity posture of critical infrastructure entities to reduce the frequency and impact of cyber incidents. The third focus area, Anticipate Emerging Technology and Risks, seeks to decrease the likelihood and impact of AI-related threats and vulnerabilities to critical infrastructure providers.

#CISA #JCDC #cybersecurity #APT

GottaLaff, to random
@GottaLaff@mastodon.social avatar

You wouldn't believe the stuff I'm NOT posting here.

Via Spiro’s Ghost:

WHAT THE FUCK?! He got destroyed there. He is INSANE.

Trump: We have to run the whole East Coast like I did twice. I did twice. I did better the second time, But we have to run the East Coast.

Beachbum,
@Beachbum@mastodon.sdf.org avatar

@GottaLaff @JaneDoeTheFirst 1) I really don’t like to hear people talk at all about rigging or stealing the elections. That constant mantra that tfg, bannon, stone, started with ‘stop the steal’ in ‘16 & ‘20 played a big part in the insurrection because people listen to pundits and not the 65 cases that were brought by attorneys and denied by judges, indicating that the election was free, fair legitimate. They didn’t listen to Chris Krebs with #CISA

YourAnonRiots, to infosec Japanese

⚠️ Attention FCEB agencies: #CISA confirms active exploitation of CVE-2024-21762, the latest critical security flaw in FortiOS SSL VPN.

https://thehackernews.com/2024/02/fortinet-warns-of-critical-fortios-ssl.html

Apply fixes by February 16, 2024, to mitigate threats and secure networks. #infosec

researchbuzz, to politics
@researchbuzz@researchbuzz.masto.host avatar

#politics #elections #cybersecurity #CISA

'As part of the #Protect2024 initiative, CISA developed a webpage to serve as a central point for consolidated critical resources, training lists and security service offerings to support the over 8,000 election jurisdictions for the 2024 election cycle. '

https://www.cisa.gov/news-events/news/cisa-launches-protect2024-resources-webpage-state-and-local-election-officials

ppatel, to Cybersecurity
@ppatel@mstdn.social avatar

This is why we can't have nice things. Businesses should be pissed about this. But why bother when you can have tax breaks.

Some top #cybersecurity experts are retreating from a #CISA program that enlists outside professionals, citing growing conservative backlash and management gripes.

https://www.politico.com/news/2024/02/06/far-right-washington-private-hackers-00139413

#security

riskybusiness, to random

This week's feature guest is CISA's assistant director for cybersecurity Eric Goldstein. He'll talk about CISA ordering USG agencies to disconnect their Ivanti equipment, the Volt Typhoon campaign and a Politico report into CISA's Joint Cyber Defense Collaborative. Up later today

simontsui,

HOT OFF THE PRESS: CISA: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
🔗 https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

#China #cyberespionage #CISA #PRC #IOC #threatintel

simontsui, to news

Politico: Five external computer security professionals involved in CISA's Joint Cyber Defense Collaborative (JCDC) told POLITICO they and many colleagues have stopped contributing or have significantly pared back their involvement. While many of their complaints stem from how the program is organized, the discontent also represents another indirect impact of Donald Trump’s 2020 election fraud claims, now threatening to hamper largely apolitical cybersecurity work: CISA’s efforts to combat disinformation ahead of the 2020 election has made it a favorite target of conservatives, who accuse it of trying to censor their views online.
🔗 https://www.politico.com/news/2024/02/06/far-right-washington-private-hackers-00139413

#News #CISA #JCDC #politics

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • khanakhh
  • GTA5RPClips
  • osvaldo12
  • magazineikmin
  • mdbf
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • everett
  • Durango
  • JUstTest
  • ngwrru68w68
  • modclub
  • tester
  • tacticalgear
  • cubers
  • thenastyranch
  • cisconetworking
  • ethstaker
  • Leos
  • provamag3
  • normalnudes
  • anitta
  • lostlight
  • All magazines