Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Iran-Linked Attack on U.S. Water Treatment Station

On November 25, the U.S. municipal water authority in Aliquippa, Pennsylvania confirmed that one of its booster stations had suffered an attack by a threat actor group that supports Iranian geopolitical interests. The attack by a cyber group known as CyberAv3ngers compromised a programmable logic controller (PLC) for a water pressure monitoring and regulation system. Officials, however, have made it clear that the incident did not threaten local drinking water or water supplies.

New SEC Rules Will Do More Than Result in Quick Breach Reporting

On July 26, the U.S. Security & Exchange Commission (SEC) announced several new cybersecurity rules, taking affect mid-December 2023, that will significantly impact all U.S. organizations (and foreign entities doing business in the U.S.) that must follow SEC regulations. Although the announcement did not generate a ton of fanfare off the normal business and cybersecurity sites, the rules will greatly increase resource requirements and actions.

Financial Institutions are the Most Affected by Phishing Attacks and Scams

New data shows how the overwhelming majority of phishing attacks on financial institutions dwarf every other industry sector by as much as a factor of 30-to-1. It’s no secret that banks and other types of financial institutions hold all the money, so it should be no surprise that's where cybercriminals focused their malicious activities last year, according to Group IB’s Digital Risk Trends 2023 report.

PDFs: Friend or Phishing Foe? Don't Get Caught by the Latest Scam Tactic

Researchers at McAfee warn that attackers are increasingly utilizing PDF attachments in email phishing campaigns. “Over the last four months, McAfee Labs has observed a rising trend in the utilization of PDF documents for conducting a succession of phishing campaigns,” the researchers write. “These PDFs were delivered as email attachments. Attackers favor using PDFs for phishing due to the file format’s widespread trustworthiness.".

Friday Flows Episode 15: Automating with Database Integrations

Easily insert data into any database with Tines Data enrichment can come from many different places. Often this information resides inside of internal databases. The process to get this data can be complicated today. You may have to install ODBC connectors and then start writing it out in code. Sometimes you can use a management tool, like SQL Management Studio, which has great displays, but take up a lot of memory on your computer.

CyberArk + Tenable

Discover how the powerful integration between CyberArk and Tenable transforms security protocols for organizations worldwide. This seamless integration empowers teams to perform continuous scans, swiftly identify vulnerabilities, and secure high-risk access points in real-time. By leveraging comprehensive scanning capabilities and advanced risk scoring, security teams can confidently provide conditional access while enhancing the overall security posture. Learn how this collaboration strengthens defenses, mitigates threats, and ensures a proactive approach to safeguarding critical assets.

New York Healthcare Provider Notified 600k Following Network Cyberattack

East River Medical Imaging (ERMI) has three locations in New York City and Westchester County. ERMI is a “multi-modality radiology center,” including patient-centered solutions like MRIs, CTs, ultrasounds, imaging, radiology, fluoroscopy, and x-rays. They have served New York since 1970 and have a long history of high-quality patient care. At the end of August, an unauthorized actor accessed their network—exposing sensitive information from employees and patients.

Forescout Vedere Labs discloses 21 new vulnerabilities affecting OT/IoT routers

Forescout Vedere Labs has identified a total of 21 new vulnerabilities affecting Sierra Wireless AirLink cellular routers and some of its open source components such as TinyXML and OpenNDS, which are used in a variety of other products.

Decoding the SEO Dilemma: Exploring the Divide on AI's Role in Production Environments #podcast

Dive into the heart of the SEO dilemma with me as we unravel the intriguing discussions surrounding the use of AI, particularly in production environments. In this video, I explore the current sentiments and general consensus among CX leaders, shedding light on the varied perspectives within the SEO community. SEO and the AI Frontier: Curious about what the CESOs have been saying? Join me as I dissect the thoughts and opinions circulating within the industry. It's a dynamic landscape with diverse viewpoints on the role of AI, especially in shaping the future workforce.

Maximizing Third-Party Risk Management: A Step-by-Step Guide

In today’s interconnected business environment, third-party partnerships are essential for growth and operational efficiency. However, these collaborations bring inherent risks, especially in the realm of cybersecurity. Effective third-party risk management is crucial for safeguarding sensitive data and maintaining business continuity.