Category: CISO Tips
-
Russian Hackers Stole Microsoft Code – and the Attack isn’t Over!
Microsoft recently disclosed that Russian hackers known as Nobelium have continued their attack on the company, accessing source code and internal systems. The group, responsible for the SolarWinds attack, has been leveraging exfiltrated email information to breach further into Microsoft’s systems. Despite the ongoing attack, there is no evidence of customer-facing systems being breached.
-
Russia-Sponsored Cyberattackers Infiltrate Microsoft’s Code Base
Midnight Blizzard APT, a Russian state-sponsored advanced persistent threat group, has stolen Microsoft source code and is conducting a sustained cyber campaign. The group, also known as APT29, Cozy Bear, Nobelium, and UNC2452, is using stolen information to probe the company’s environment and may be preparing for future attacks. Microsoft noted a tenfold increase in…
-
Criticality of the Cybersecurity Policy
In today’s digital landscape, cybersecurity policies are crucial for protecting an organization’s digital assets, sensitive information, and infrastructure from cyber threats. To ensure policy effectiveness, focus on establishing a strong tone at the top, outlining high-level expectations in simple terms, and clearly communicating the consequences of non-adherence. Additionally, the policy should reference security, privacy, and…
-
Who should own the Cyber security Policy
The Information Security policy should be overseen by the highest-level executive to ensure organization-wide enforcement. Specific policies, such as Acceptable Use and Network security, should be owned by relevant department executives. The policy owner often doubles as the risk owner, ensuring accountability at every level.
-
Microsoft Zero-Day Used by Lazarus in Rootkit Attack
The Lazarus Group, a North Korean state-backed actor, utilized a zero-day exploit in Microsoft’s AppLocker to execute a rootkit cyberattack. The flaw was fixed on February 13 following its discovery by Avast researchers, who noted the increased sophistication of Lazarus’ techniques. This incident underscores the importance of effective vulnerability management and the need for timely…
-
Ensuring that the Information Security policies are maintained and current
The main challenge in Information Security/Cybersecurity policy is keeping them current. Delegating responsibility to stakeholders, who need to stay updated on regulations and incidents, is vital. They must review exceptions, risks, and treatment activities, periodically revise the policy, and ensure its comprehensiveness. Driven by a GRC lead, overly vague or strict policies lead to non-conformance…
You must be logged in to post a comment.