"NSA Joins FBI and Others to Warn of North Korea Cyber Espionage Campaign"

"NSA Joins FBI and Others to Warn of North Korea Cyber Espionage Campaign"

The National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and others have released a joint Cybersecurity Advisory (CSA) titled "North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs." The CSA includes methods for detecting and mitigating the malicious activities of the Democratic People's Republic of Korea (DPRK) Reconnaissance General Bureau (RGB) 3rd Bureau.

Submitted by Gregory Rigby on

"'Stargazer Goblin' Amasses Rogue GitHub Accounts to Spread Malware"

"'Stargazer Goblin' Amasses Rogue GitHub Accounts to Spread Malware"

The threat actor "Stargazer Goblin" has found a new way to use GitHub to spread malware and malicious links. Instead of hosting malware on GitHub and luring users to download an infected code package by clicking on a malicious link in a phishing email, the new tactic involves tricking victims into thinking that malicious repositories are legitimate through an operation involving thousands of fake accounts.

Submitted by Gregory Rigby on

"Most IT Leaders Say Severity of Cyber-Attacks has Increased"

"Most IT Leaders Say Severity of Cyber-Attacks has Increased"

According to security researchers at CTS, Nine in 10 IT leaders have said that the risk and severity of cyberattacks has increased over the past year, while 61% believe the attack surface is now "impossible to control."
Submitted by Adam Ekwall on

"Ransomware and BEC Make Up 60% of Cyber Incidents"

"Ransomware and BEC Make Up 60% of Cyber Incidents"

According to security researchers at Cisco Talos, ransomware and business email compromise (BEC) attacks accounted for 60% of all incidents in the second quarter of 2024.  Technology was the most targeted sector in this period, making up 24% of incidents, a 30% rise from the previous quarter.  The researchers noted that adversaries may view technology firms as a gateway into other industries and organizations, given their role in servicing various industries, including critical infrastructure.

Submitted by Adam Ekwall on

"BIND Updates Resolve High-Severity DoS Vulnerabilities"

"BIND Updates Resolve High-Severity DoS Vulnerabilities"

The Internet Systems Consortium (ISC) recently announced BIND security updates that contain patches for several remotely exploitable denial-of-service (DoS) vulnerabilities in the DNS software suite.  The ISC said that the updates resolve a total of four high-severity bugs, tracked as CVE-2024-0760, CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076, all of which have a CVSS score of 7.5.  The first security defect would result in the server becoming unstable when receiving a flood of DNS messages over TCP.

Submitted by Adam Ekwall on

Salt Lake City Cybersecurity Conference

"Join Us in Salt Lake City for the Futurecon Cybersecurity Event!  Hear from our esteemed speakers while gaining up to 10 CPE credits. Immerse yourself in the latest cybersecurity developments to gain valuable insights in today’s dynamic threat landscape. Learn how to effectively manage risk, demo the newest technologies from an array of different sponsors, and network with your local community.  Don’t miss our special ceremony recognizing our honorary attendees receiving an Award of Excellence!

Advancing Construction Cybersecurity Summit

"The inaugural Advancing Construction Cybersecurity Summit is uniting CISOs, CIOs, cybersecurity, information security, legal and GRC experts across the AEC community to tackle shared challenges surrounding the enterprise-wide protection and security of valuable personnel, project and financial data. Unearth lessons learned from ransomware attacks, discover how others are ensuring CMMC compliance, develop robust security protocols for you and your partners across all project sites and many more security strategies all available to you in just 3 days.

Subscribe to