GSG Monthly Newsletter – 1st Edition October 2024
Cybersecurity News
MICROSOFT IS MAKING SOME MAJOR WINDOWS SECURITY CHANGES FOLLOWING CROWDSTRIKE OUTAGE:
CrowdStrike’s problematic update, which caused widespread system crashes, sparked several debates about the risks of kernel access, and a recent Microsoft-hosted security summit has now led to the company’s decision to revise its OS.
For more information: Microsoft is making some major Windows security changes following CrowdStrike outage (msn.com)
EQUIFAX HACKERS STOLE 200K CREDIT CARD ACCOUNTS IN ONE FELL SWOOP:
Visa and MasterCard are sending confidential alerts to financial institutions across the United States this week, warning them about more than 200,000 credit cards that were stolen in the epic data breach announced last week at big-three credit bureau Equifax.
For more information: Equifax Hackers Stole 200k Credit Card Accounts in One Fell Swoop – Krebs on Security
IRANIAN GOVERNMENT-BACKED HACKERS TARGETING THE ELECTION CAMPAIGNS:
Google’s Threat Analysis Group (TAG) has reported that Iranian government-backed hackers, directed by Iran’s Revolutionary Guard Corps (IRGC), have targeted the election campaigns of US presidential candidates Kamala Harris and Donald Trump, as well as targets in Israel. The hackers use phishing to collect login information from campaign workers. TAG say the group is actively targeting campaign workers associated with the Trump and Harris presidential election campaigns.
For more information: APT42: Iranian Hackers At Work (cybersecurityintelligence.com)
CISA RELEASES ANALYSIS OF FY23 RISK AND VULNERABILITY ASSESSMENTS:
CISA has unveiled a new analysis and infographic based on 143 Risk and Vulnerability Assessments (RVAs) conducted across various critical infrastructure sectors in fiscal year 2023 (FY23). The analysis illustrates a sample attack path, including tactics and steps that a cyber threat actor might use to exploit common vulnerabilities observed during FY23 RVAs. The accompanying infographic outlines the most effective techniques for each tactic identified in the assessments. Both the analysis and infographic align threat actor behaviors with the MITRE ATT&CK® framework.
For more information: CISA Releases Analysis of FY23 Risk and Vulnerability Assessments
Digital Transformation News
The Now Platform Xanadu release:
Actionable AI across the enterprise: With one of the most ambitious AI roadmaps in enterprise software today, NOW Platform Xanadu release, features actionable AI innovations to help organizations put AI to work to increase productivity, personalization and value.
Please connect with GSG ServiceNow Team to learn more and how our team can help.
For more information: https://www.servicenow.com/uk/blogs/2024/now- platform-xanadu-release-actionable-ai
*Disclaimer: This newsletter contains links to sites on the Internet that are owned and operated by third parties. We do not claim ownership of any third-party content. Trademarks, logos, and brand names are the property of their respective owners.
**These are basic steps; advanced issues may need expert intervention. Consult our team for detailed analysis.