CISA: CISA Launches National Public Service Announcement Campaign Encouraging Americans to Take Steps to Keep Themselves and Their Families Safe Online

CISA: CISA Launches National Public Service Announcement Campaign Encouraging Americans to Take Steps to Keep Themselves and Their Families Safe Online. “The campaign includes a public service announcement (PSA) that will air on stations around the country, as well as digital content, a toolkit, and other resources. Recognizing that technology is an integral part of our modern lives, Congress tasked CISA with creating this program to provide small businesses, communities, and individuals with the guidance and tools they need to protect themselves online.”

Bleeping Computer: CISA warns of breach risks from IDOR web app vulnerabilities

Bleeping Computer: CISA warns of breach risks from IDOR web app vulnerabilities. “CISA warned today of the significant breach risks linked to insecure direct object reference (IDOR) vulnerabilities impacting web applications in a joint advisory with the Australian Cyber Security Centre (ACSC) and U.S. National Security Agency (NSA). IDOR vulnerabilities are flaws in web apps (or apps that use affected web APIs) that enable attackers to access and manipulate sensitive data by directly referencing internal objects or resources.”

CISA: U.S. and International Partners Release Comprehensive Cyber Advisory on LockBit Ransomware

CISA: U.S. and International Partners Release Comprehensive Cyber Advisory on LockBit Ransomware. “This joint advisory is a comprehensive resource with common tools; exploitations; and tactics, techniques, and procedures (TTPs) used by LockBit affiliates, along with recommended mitigations for organizations to reduce the likelihood and impact of future ransomware incidents.”

CISA: CISA, FBI, NSA, MS-ISAC Publish Updated #StopRansomware Guide 

CISA: CISA, FBI, NSA, MS-ISAC Publish Updated #StopRansomware Guide . “The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) today published the #StopRansomware Guide—an updated version of the 2020 guide containing additional recommended actions, resources, and tools.”

CISA: U.S. and International Partners Publish Secure-by-Design and -Default Principles and Approaches

CISA: U.S. and International Partners Publish Secure-by-Design and -Default Principles and Approaches. “This guidance, the first of its kind, is intended to catalyze progress toward further investments and cultural shifts necessary to achieve a safe and secure future. In addition to specific technical recommendations, this guidance outlines several core principles to guide software manufacturers in building software security into their design processes prior to developing, configuring, and shipping their products.”

CISA: Malicious Cyber Activity Against Election Infrastructure Unlikely to Disrupt or Prevent Voting

CISA, and a PDF, unfortunately: Malicious Cyber Activity Against Election Infrastructure Unlikely to Disrupt or Prevent Voting . “The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) assess that any attempts by cyber actors to compromise election infrastructure are unlikely to result in largescale disruptions or prevent voting. As of the date of this report, the FBI and CISA have no reporting to suggest cyber activity has ever prevented a registered voter from casting a ballot, compromised the integrity of any ballots cast, or affected the accuracy of voter registration information.”

CISA: Action required now to prepare for quantum computing cyber threats (ZDNet)

ZDNet: CISA: Action required now to prepare for quantum computing cyber threats. “Action must be taken now to help protect networks from cybersecurity threats that will emerge in the advent of power of quantum computing, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. While quantum computing could bring benefits to computing and society, it also brings new cybersecurity threats – and the CISA alert warns that critical infrastructure in particular is at risk.”

Cybersecurity and Infrastructure Security Agency: CISA Releases Toolkit Of Free Cybersecurity Resources For Election Community

Cybersecurity and Infrastructure Security Agency (CISA): CISA Releases Toolkit Of Free Cybersecurity Resources For Election Community. “The Cybersecurity and Infrastructure Security Agency (CISA) released its ‘Protecting U.S. Elections: A CISA Cybersecurity Toolkit’ today, a one-stop catalog of free services and tools available for state and local election officials to improve the cybersecurity and resilience of their infrastructure.”