CISA
CISA has posted a new directive for US government agencies regarding targeted attacks by the Midnight Blizzard hacking team that also hit Microsoft
CISA is moving into what it hopes is the home stretch for drafting and enforcing stricter reporting rules for cybersecurity incidents
CISA has just two federal staff and five contractor staff working on its OT-specific threat hunting and/or incident response services...
As CISA reportedly admits two of its systems were breached in February due to Ivanti flaws
"Package managers are at a critical point in the open source ecosystem and have the capability to scale security improvements across open source ecosystems"
"This actor is not doing the quiet intelligence collection and theft of secrets... they can disrupt major services if, and when, the order comes down,"
"When we see a vulnerability or intrusion campaign that could have been reasonably avoided if the software manufacturer had aligned to secure by design principles, we’ll call it out"
CISA has sounded the alarm over a pair of actively targeted vulnerabilities in Ivanti and Veeam software