Threat actors are targeting one newly discovered and three previously known vulnerabilities in Pulse Connect Secure enterprise VPNs, according to a CISA emergency directive and alert, as well as blog posts by FireEye and Ivanti. “There is no indication the identified backdoors were introduced through a supply chain compromise of the company’s network or software deployment process,” FireEye noted.
By Brad D. WilliamsOnly after months of investigation by nearly 100 highly skilled digital forensics experts did FireEye discover the malicious “implant” in the most unlikely place. We break it all down in plain language.
By Brad D. Williams“But we are seeing in the information spaces especially … we are seeing those that are trying to take advantage of this situation,” Gen. Goldfein said in a wide-ranging discussion this morning sponsored by the Mitchell Institute.
By Theresa HitchensWASHINGTON: The deputy director of the National Security Agency said today that the Intelligence Community should declassify the existence of more cyber attacks to improve the agency’s ability to mobilize the private sector and to get help when needed. I asked Richard Ledgett at the end of a session at the Intelligence and National Security Summit…
By Colin Clark