Energy Provider in Ukraine Targeted With Industroyer2 ICS Malware

energy-provider-in-ukraine-targeted-with-industroyer2-ics-malware

An energy provider in Ukraine was recently targeted with a new piece of malware designed to cause damage by manipulating industrial control systems (ICS).

The attack, which targeted high-voltage electrical substations, has been analyzed by Ukraine’s Computer Emergency Response Team (CERT-UA), cybersecurity firm ESET, and Microsoft.

read more

CISA Tells Orgs to Patch WatchGuard Flaw Exploited for Months Before Disclosure

cisa-tells-orgs-to-patch-watchguard-flaw-exploited-for-months-before-disclosure

The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies three weeks to patch a WatchGuard firewall vulnerability exploited in attacks linked to a Russian state-sponsored threat actor. While the US government has known about the exploitation of this flaw for several months, federal agencies are apparently only now being told to patch it.

read more

Spring4Shell Vulnerability Exploited by Mirai Botnet

spring4shell-vulnerability-exploited-by-mirai-botnet

Cybersecurity firm Trend Micro on Friday confirmed some earlier reports that the new Spring4Shell vulnerability has been exploited by the Mirai botnet.

Two critical vulnerabilities have been patched recently in the popular Java application development framework Spring: CVE-2022-22965 (aka Spring4Shell and SpringShell) and CVE-2022-22963.

read more