News and analysis for the well-informed compliance or audit exec.
Annual Membership best value
Subscribe now for $365
Our lowest price ($1 per day) for one year.
Register for free
Receive the CW newsletter and access CPE webcasts.
- Chief Compliance Officer and VP of Legal Affairs, Arrow Electronics
By Jeff Dale2023-03-15T19:54:00
The Cybersecurity and Infrastructure Security Agency (CISA) announced Monday a pilot program designed to help critical infrastructure entities vulnerable to cyberattacks mitigate a ransomware incident before it occurs.
The Ransomware Vulnerability Warning Pilot will allow CISA to “determine vulnerabilities commonly associated with known ransomware exploitation and warn critical infrastructure entities,” the agency said in a press release announcing the program.
CISA said it will use its cyber hygiene scanning service to identify to organizations internet-accessible vulnerabilities commonly exploited by ransomware actors. The agency said it already alerted 93 organizations running an outdated Microsoft Exchange Service vulnerability called “ProxyNoShell.” Threat actors have exploited the vulnerability to access “emails on an organization’s server and … plant malware on an Exchange server,” according to Kroll’s “Q4 2022 Threat Landscape Report.”
THIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.
News and analysis for the well-informed compliance or audit exec.
Annual Membership best value
Subscribe now for $365
Our lowest price ($1 per day) for one year.
Register for free
Receive the CW newsletter and access CPE webcasts.
2023-11-20T19:26:00Z By Kyle Brasseur
New guidance released by the Cybersecurity and Infrastructure Security Agency offers best practices for organizations in the healthcare and public health sector to adopt to combat rising cyber threats.
2023-03-10T19:32:00Z By Aaron Nicodemus
Software company Blackbaud agreed to pay $3 million to the Securities and Exchange Commission to settle claims it violated securities law by failing to disclose the true scope of a ransomware attack that affected 13,000 users.
2023-02-24T20:10:00Z By Adrianne Appel
Securing your organization’s private data when vendors have access to it means managing relationships from beginning to end, panelists at CW’s virtual Cyber Risk and Data Privacy Summit agreed.
2024-06-27T16:37:00Z By Aaron Nicodemus
The U.S. Department of Energy released supply chain cybersecurity principles meant to help strengthen key technologies used to manage and operate electricity, oil, and natural gas systems.
2024-05-21T19:27:00Z By Adrianne Appel
The Environmental Protection Agency is increasing its inspections of public drinking water systems after finding a majority of those reviewed were vulnerable to cyberattacks and related threats.
2024-05-07T21:21:00Z By Adrianne Appel
Verizon’s annual data breach report shows trends in cybersecurity incidents, including more ransomware and extortion attacks last year.
Site powered by Webvision Cloud