Security news that informs and inspires

2376 articles by

The Challenge of Securing Critical Operational Technology Systems at the Ground Level

As the federal government contemplates how it approaches operational technology security measures, a "big opportunity" exists as infrastructure is upgraded or replaced.

Critical Infrastructure

CISA Warns of Critical Flaw in Honeywell SoftMaster PLC Software

A critical vulnerability in the Honeywell SoftMaster PLC controller software can allow an attacker to execute arbitrary code on vulnerable machines.

ICS Security

U.S. Government Hits Alleged Iranian Hackers with Indictments, Sanctions

The U.S. government indictments, sanctions and detailing of TTPs were part of a wave of actions against Iran-linked threat actors that allegedly targeted critical infrastructure organizations since 2020.

Iran

Software Supply Chain Security Takes Center Stage in Washington

The Biden administration issued new guidance on software supply chain security for federal agencies, which includes requirements for self-attestations and SBOMs.

Government, Supply Chain, Solarwinds

Microsoft Fixes Exploited Windows Bug

The vulnerability in the Windows Common Log File system could allow an authenticated attacker to execute code with elevated privileges.

Microsoft, Patch Tuesday