"SDSU Researchers Working to Protect Power Grids Against Natural Disasters and Cyberattacks"

"SDSU Researchers Working to Protect Power Grids Against Natural Disasters and Cyberattacks"

Researchers at San Diego State University (SDSU) are developing methods to protect power grids from the effects of cyberattacks and natural disasters. They will explore "energy space" to better understand power grid dynamics. In researching energy space, the team is developing a sensing and control system to monitor power distribution grids that host energy storage structures, renewables, and electric vehicles. Power grid blackouts have occurred because of cyberattacks and natural disasters.

Submitted by grigby1 CPVI on

"Department of Energy CyberForce Competition 2023: Cultivating Tomorrow's Cybersecurity Leaders Today"

"Department of Energy CyberForce Competition 2023: Cultivating Tomorrow's Cybersecurity Leaders Today"

The US Department of Energy (DOE) is boosting its efforts to cultivate a well-equipped energy cybersecurity workforce through a hands-on Operational Technology (OT) cybersecurity competition involving real-world challenges. The DOE invites teams of college and university students to participate in the in-person ninth edition of its CyberForce Competition on November 4. It is sponsored by the DOE's Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and led by the DOE's Argonne National Laboratory (ANL).

Submitted by grigby1 CPVI on

"Trucking Faces Increasing Threat of Cyberattacks"

"Trucking Faces Increasing Threat of Cyberattacks"

There has been an increase in cyber threats faced by the trucking industry as the problem spreads throughout the economy. The National Motor Freight Traffic Association (NMFTA) recently hosted the discussion at its Digital Solutions Conference. Experts in transportation and cybersecurity gathered for the two-day conference to highlight issues and discuss best practices. Debbie Sparks, executive director of the NMFTA, emphasized the importance of industry stakeholders collaborating to solve the cybersecurity issues facing the transportation industry.

Submitted by grigby1 CPVI on

"Kansas Court System Down Nearly 2 Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware"

"Kansas Court System Down Nearly 2 Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware"

Kansas officials are calling a massive computer outage that’s kept most of the state’s courts offline for two weeks a “security incident” and have not provided an explanation.  Experts say it has all the hallmarks of a ransomware attack.  The disruption has left attorneys unable to search online records and forced them to file motions the old-fashioned way on paper.  Security researcher Allan Liska stated that, since 2019, ransomware groups have targeted 18 state, city, or municipal court systems.  In Kansas, the first sign of trouble came on Oct.

Submitted by Adam Ekwall on

"Chrome Update Spreads Trojan Malware"

"Chrome Update Spreads Trojan Malware"

There has been an increase in fake Chrome update websites that could grant unauthorized access to user devices via Remote Access Trojans (RATs). Researchers at the cybersecurity company Sucuri observed an increase in websites infected with "FakeUpdateRU" malware. The fraudulent websites deceive users into believing they are downloading a legitimate Chrome browser update when they are installing a RAT.

Submitted by grigby1 CPVI on

"Roundcube 0-Day Used To Steal European Government Emails"

"Roundcube 0-Day Used To Steal European Government Emails"

The cyber espionage group Winter Vivern exploited a now-patched zero-day vulnerability in the open-source webmail service Roundcube to steal emails from European government entities and think tanks. It is believed that the Russia- and Belarus-aligned Winter Vivern, also known as TA473, has been active since 2020. The group has a history of spying on European and Central Asian governments. Winter Vivern has exploited vulnerabilities in the Zimbra and Roundcube email servers. Researchers from ESET observed the group using a cross-site scripting (XSS) vulnerability in its most recent attacks.

Submitted by grigby1 CPVI on

"The Danger of Forgotten Pixels on Websites: A New Case Study"

"The Danger of Forgotten Pixels on Websites: A New Case Study"

Reflectiz, an advanced website security solution provider, has released a case study highlighting a scenario involving forgotten pixels on websites that could have impacted any industry. The case study focuses on an overlooked and misconfigured pixel associated with a top global healthcare provider. This forgotten piece of code collected private user information without user consent, potentially exposing the company to significant fines and reputational damage. This article continues to discuss the case study on the risks of forgotten pixels on websites.

Submitted by grigby1 CPVI on

Pub Crawl - November 2023

Pub Crawl - November 2023

Selections by dgoff

Pub Crawl summarizes, by hard problems, sets of publications that have been peer-reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers. Select the topic name to view the corresponding list of publications. Submissions and suggestions are welcome.

Submitted by grigby1 CPVI on

"Google Announces Bug Bounty Program and Other Initiatives to Secure AI"

"Google Announces Bug Bounty Program and Other Initiatives to Secure AI"

Google recently announced several initiatives meant to improve the safety and security of AI, including a bug bounty program and a $10 million fund.  Google noted that the new vulnerability reporting program (VRP) will reward researchers for finding vulnerabilities in generative AI to address concerns such as the potential for unfair bias, hallucinations, and model manipulation.

Submitted by Adam Ekwall on

"Cloudflare Sees Surge in Hyper-Volumetric HTTP DDoS Attacks"

"Cloudflare Sees Surge in Hyper-Volumetric HTTP DDoS Attacks"

Cloudflare reports that the number of hyper-volumetric HTTP Distributed Denial-of-Service (DDoS) attacks recorded in the third quarter of 2023 exceeds all previous years. A report from Cloudflare reveals that during the third quarter of 2023, the Internet company mitigated thousands of hyper-volumetric HTTP DDoS attacks. More than 89 of these attacks surpassed 100 million requests per second (rps). The largest attack peaked at 201 million rps, three times larger than the previous record in February 2023.

Submitted by grigby1 CPVI on
Subscribe to