Author Archives: CSIRT

Cybersecurity, Ransomware Climb Policy Ladder at NATO, G-7 Meetings

Cybersecurity in general, and ransomware in specific, climbed high onto the ladder of major policy issues at both the weekend meeting of G-7 nations this weekend, and the NATO Summit that concluded on June 14. The increasing importance of cybersecurity on the national stage tracks with U.S. policy in recent months, including Federal government responses […]

Citrix Patches Vulnerability in Workspace App for Windows

Citrix this week announced that it has patched a local privilege escalation vulnerability in the Citrix Workspace app for Windows. Tracked as CVE-2021-22907, the vulnerability could be exploited by local attackers to escalate their privileges to SYSTEM level. All supported versions of Citrix Workspace app for Windows are affected by the security hole. The issue, […]

Four Years On: Two-thirds of Global Firms Still Exposed to WannaCry

Over two-thirds (67%) of organizations are still running an insecure Windows protocol largely responsible for the infamous WannaCry and NotPetya attacks of 2017 and 2018, according to new research. Security vendor ExtraHop used its network detection and response (NDR) capabilities to analyze anonymized metadata from an unspecified number of customer networks, in order to better […]

Rapid7 Source Code Exposed in Codecov Supply Chain Attack

Rapid7 says unauthorized third-party accessed source code, customer data during Codecov supply chain breach Enterprise security vendor Rapid7 says it was among the victims of the Codecov software supply chain attack and warned Thursday that data for a subset of its customers was accessed in the breach. Rapid7, widely known for its tools that automate […]

Biden Executive Order Mandates Zero Trust and Strong Encryption

President Biden has issued a long-awaited executive order (EO) designed to improve supply chain security, incident detection and response and overall resilience to threats. Although every President in recent years has issued an order to improve the nation’s cybersecurity, experts believe this one is more detailed and has a better chance of success than previous efforts. […]