< ciso
brief />
Tag Banner

All news with #critical infrastructure tag

432 articles · page 3 of 22

Executive Order Accelerates Post‑Quantum Readiness

🔒 The White House Executive Order signed June 22, 2026 mandates migration of federal systems to NIST‑approved post‑quantum cryptography, setting milestones for key establishment by 2030 and digital signatures by 2031. It extends urgency to critical infrastructure, federal contractors, and procurement, highlights "harvest now, decrypt later" risk, and calls for cryptographic bill of materials guidance to drive visibility and operational readiness.
read more →

NCSC: 75% of CNI Incidents Linked to Hostile States

🛡️ Richard Horne, CEO of the UK National Cyber Security Centre, told the RUSI Annual Security Lecture that three-quarters of cyber incidents affecting UK critical national infrastructure over the past year were traced to nation-state actors or hostile states. The NCSC handled around 200 incidents between June 2025 and May 2026, with threats described across three contested digital spaces: far, mid and near. Horne warned that AI and cloud supply-chain exploitation increase attacker scale and urged organisations to prioritise continuous defence, fix legacy vulnerabilities and close IT-OT knowledge gaps.
read more →

India’s Telegram Ban, BGP Fallout and Workarounds

📰 India blocked Telegram until June 22 after leaked exam materials circulated on the platform, prompting Telegram CEO Pavel Durov to allege BGP hijacking by Reliance that affected users as far as the UAE. The ban, and an additional restriction on message editing, prompted legal challenges and criticism from digital-rights groups calling the move disproportionate. Analysts confirmed a routing leak from AS18101 via FLAG Telecom but dispute claims of deliberate sabotage; MTProto proxies are recommended to restore access.
read more →

EU Cybersecurity Reserve Extended to Ukraine

🛡️ The Council of the EU approved Ukraine’s inclusion in the EU Cybersecurity Reserve on June 16, allowing the Ukrainian government to request emergency EU cyber support for large-scale incidents. Managed by ENISA, the reserve leverages 47 trusted private providers who passed an ownership control assessment. The initiative is funded under the Digital Europe Work Programme 2025–2027 and grounded in the EU Cyber Solidarity Act.
read more →

Protecting Legacy OT Systems From Modern Threats

🔒 Manufacturing facilities often rely on long-running operational technology (OT) that was built for stability, not security. As IT and OT converge, previously isolated systems face increased exposure to internet-borne attacks, ransomware, and supply-chain disruption. Effective defenses start with asset visibility, careful deployment choices, network protections for agentless devices, and long-term vendor support to mitigate risks without disrupting production.
read more →

Anubis Ransomware Targets Adriatic Port Authority

🔒 New analysis from Resecurity details a ransomware attack by the Anubis group that targeted the Adriatic Port Authority, operator of Ancona port. The breach, traced to December 11, 2025 and publicly claimed by Anubis in January 2026, reportedly affected about 2% of the authority's data while backups preserved most records. Resecurity says the incident disrupted operations, forced vessel rerouting, and involved a reported $10m Bitcoin ransom demand, with sensitive safety and security plans among the stolen files.
read more →

Short lapse in Section 702 surveillance affects US monitoring

🔍 Congress failed to extend Section 702 of the Foreign Intelligence Surveillance Act, creating a short pause in warrantless monitoring of foreign communications. The extension vote was rejected, leaving surveillance put on hold until the next possible vote on June 28, and creating uncertainty about immediate intelligence collection practices. CISOs should note potential impacts on cross-border communications and legal challenges ahead.
read more →

Japanese energy firm loses drive with 10.9M accounts

🔒 Kyushu Electric Power disclosed a physical security incident after an external backup drive containing private data for up to 10.9 million accounts went missing from a server room cabinet. The company said the drive was used on April 27 due to storage capacity limits and was found absent on May 26 when staff returned. The lost data reportedly includes customer names, addresses, usage data, phone numbers, and retail provider names, but not bank or credit card details. Authorities and Japan’s privacy commission have been notified, and an investigation and individual notifications are underway.
read more →

Critical IoT Platform Flaws Enable Device Takeover

🔒 CISA published an advisory on multiple critical vulnerabilities in the Naxclow IoT Platform that allow device impersonation, credential exposure, and fleet enumeration. A replayable onboarding flow and inadequate authorization let attackers reassign devices, while persistent, non-rotating relay credentials enable long-term access. Additional weaknesses include a hard-coded platform salt for request signing, predictable device identifiers, and cleartext Wi‑Fi secrets exposed via UART.
read more →

Ivanti patches critical Sentry gateway vulnerabilities

🔒 Ivanti patched two critical vulnerabilities in Ivanti Sentry, an in-line secure mobile gateway formerly called MobileIron Sentry, that could allow unauthenticated remote attackers to take full control of devices. One flaw, CVE-2026-10523, lets attackers bypass authentication to create administrative accounts and is rated 9.9/10. The second, CVE-2026-10520, is a command injection leading to root remote code execution and is rated 10/10. Customers should upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.
read more →

China-linked JDY botnet broadens US military focus

🛡️ JDY is a distributed reconnaissance botnet tied to China-nexus actors that has expanded from ~650 to over 1,500 compromised SOHO and IoT devices, with a heavy focus on U.S. military and associated networks. Researchers at Black Lotus Labs observed JDY rapidly scanning for newly disclosed vulnerabilities, collecting banners, TLS certificates, and protocol fingerprints. The botnet uses Tor-hidden services and a central Dispatch Service to receive scanning tasks and exfiltrate results, and supports TCP/SSL/UDP/ICMP scanning plus service fingerprinting.
read more →

Military used GPS to distribute cryptographic keys

🔍 Steven Murdoch uncovered that U.S. military satellites have been broadcasting hidden codes via public GPS for nearly two decades, effectively turning each satellite into a covert distribution channel. He identified synchronized transmissions across all 31 operational satellites on May 26, 2011, matching the rollout timeline of the military’s Over-the-Air Distribution (OTAD) and Over-the-Air Rekeying (OTAR) systems. This mechanism allowed remote rekeying of military GPS receivers, replacing manual key distribution.
read more →

French government messaging platform breached by hijack

🔐 DINUM warned that a hijacked user account was used to breach Tchap, the French government's encrypted messaging platform. Developed with ANSSI in 2018 on the Matrix protocol, Tchap serves the French public sector and has grown rapidly since its mandated adoption in August 2025. DINUM and CNIL were alerted after ANSSI detected the intrusion and the compromised account was promptly blocked while investigations continue. A threat actor claimed responsibility and shared samples, alleging large-scale data and message exfiltration.
read more →

White House EO Aligns AI Policy with Cybersecurity

🔒 The White House Executive Order on advanced AI seeks practical public–private coordination to address AI-driven cyber risks while preserving innovation. It prioritizes voluntary model assessments, improved federal defenses, faster vulnerability discovery and remediation, and expanded cybersecurity talent. Successful implementation will hinge on operationalizing AI-assisted defense, translating insights into timely guidance and mitigations, and supporting resource-constrained critical infrastructure operators.
read more →

Critical UniFi OS bug enables unauthenticated root access

🔒 Researchers found that three fixed flaws in UniFi OS Server (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) can be chained to achieve remote code execution with root privileges on versions 5.0.6 and earlier. Bishop Fox validated the full attack path on a live instance, showing an authentication bypass via URI normalization differences and a subsequent command injection that escalates to root due to passwordless sudo. A detection script and guidance are available; upgrade to 5.0.8 or later.
read more →

Resilience and Self-Reliance in Cyber Conflict

🛡️ Dmytro Kuleba, Ukraine’s former foreign minister, told Infosecurity Europe that preparation, resilience and self-reliance are crucial for cybersecurity professionals facing wartime threats. He cited KyivStar’s rapid recovery from a December 2023 hack and stressed the value of wargaming and muscle-memory incident response. Kuleba warned that innocuous services such as CRMs can be weaponized and urged businesses to distrust products from potential adversaries.
read more →

CISA warns of attacks on fuel tank monitoring systems

🔒 CISA and multiple US agencies warn that internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks are being targeted by cyber actors. The advisory notes attackers exploit authentication bypasses, hardcoded credentials, command-execution flaws, SQL injection, and privilege-escalation vulnerabilities. If compromised, attackers can alter network and tank settings, disable alerts, and impair monitoring, increasing risk to safety and operations. Agencies recommend blocking public access, enforcing strong credentials and MFA, applying updates, and monitoring for unauthorized changes.
read more →

Anthropic expands Project Glasswing to 150 more firms

🔎 Anthropic has added 150 additional companies to its Project Glasswing initiative, prioritizing critical infrastructure sectors like power, water, healthcare, communications, and hardware. Analysts view the expansion positively for increasing vulnerability discovery, but warn of a remediation bottleneck: vendors and SOCs may struggle to validate, prioritize, and patch a potential 10x or greater increase in findings. Experts emphasize the need for confidence scoring, automation, and third-party validation to maintain trust and ensure timely remediation.
read more →

NCSC: Act Now to Build Cyber Resilience

🔒 Paul Chichester of the NCSC warned at Infosecurity Europe that escalating technological change, geopolitical tensions and evolving threats make predicting cyber risk harder than ever. He highlighted hyper-connectivity, rapid tech transformation and state-backed cyber operations as key challenges, and urged stronger public-private collaboration. Chichester praised the Cyber Security and Resilience Bill and called for practical steps like reducing attack surface, addressing legacy systems, enforcing access controls and running incident exercises.
read more →

CISA and Partners Urge Hardening of ATG Systems

🔒 The Cybersecurity and Infrastructure Security Agency (CISA), alongside multiple federal partners, warns of malicious cyber activity targeting internet-exposed automatic tank gauge (ATG) systems used across energy, chemical, food and agriculture, and transportation sectors. The advisory outlines observed tactics—such as authentication bypass, command execution, and privilege escalation—and urges owners to remove ATG devices from public internet exposure, apply patches, enforce strong credentials, and monitor device logs. It also lists reporting contacts and mitigation resources.
read more →