Saturday, January 21, 2023

Short Takes – 1-21-23

FBI warns of neo-Nazi plots as attacks on Northwest power grid spike. OPB.org article. Includes catalogue of recent attacks in NE. Pull quote: “Utilities are required to have measures in place on their most critical assets to prevent cascading or uncontrolled power outages. Utility industry officials say the recent grid attacks in the Northwest and North Carolina hit smaller substations that were unlikely to lead to any cascading outages and were not required to have defensive measures in place.”

Chainguard Trains Spotlight on SBOM Quality Problem. SecurityWeek.com article. Pull quote: ““This analysis suggests that standard SBOMs already provide a great deal of information but not enough to satisfy  the minimum [OMB required] elements. Additionally, this research implies that the push to make SBOMs “everywhere” should be accompanied by an effort to measure and improve the quality of SBOMs,” the company said.”

EXCLUSIVE: U.S. airline accidentally exposes ‘No Fly List’ on unsecured server. DailyDot.com article. Not clear if it was ‘no fly list’ or Terrorism Screening Data Base. Name points to former, size to later.  Pull quote: ““The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth,” CommuteAir Corporate Communications Manager Erik Kane said. “In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation.””

Critical Manufacturing Sector in the Bull's-eye. DarkReading.com article. A good bit of technobabble. Pull quote: “"Many of these incidents have involved ransomware where the threat actor, usually in the form of a criminal group, sets out to make money through extortion," he says. "While the ransomware problem is global, we’ve seen a rising number of attacks on critical infrastructure come from nation-state actors in pursuit of various geopolitical objectives."”

No comments:

 
/* Use this with templates/template-twocol.html */