CISA
"When we see a vulnerability or intrusion campaign that could have been reasonably avoided if the software manufacturer had aligned to secure by design principles, we’ll call it out"
CISA has sounded the alarm over a pair of actively targeted vulnerabilities in Ivanti and Veeam software
"We have gotten very smart on how to do business with agencies and build in flexibility into our contracting vehicles. We took an approach early on to divide and conquer..."
Attackers dropped a webshell, collected and exfiltrated Active Directory data, then ran into some healthy obstacles...
Following a major security breach involving US federal agencies, Microsoft refuses to provide details on the incident