2022 Week 7 Security Summary
Summary
Sorry for the late release. There was so little news I debated doing a 2-week report but decided Monday morning that the week of the 8th might turn out to be pretty busy.
The news of most interest is that we have seen a lot of increase in attacks against all aspects of critical infrastructure and with the threat of war in the Euro-Asian theater this is probably only going to increase.
News
News that spans all of the areas of this blog points out that we are increasingly seeing attacks against critical infrastructure sectors. Once upon a time, these were generally considered off-limits by attackers and state actors as disruptions to these could affect lives or the supply chain and lead to very active state-sponsored reprisals. The article points out that in the US alone attacks were launched against 14 of the 16 critical sectors last year (2021).
ICS
Lloyd's released a report that dives in to the growing threat to Industrial Control Systems (ICS). Among the findings in the report are:
- Cyber insurance is maturing but still has trouble with cyber-physical risks.
- Stakeholders should be actively monitoring products for risks.
- While large-scale attacks are unlikely, the threat is growing.
- Stakeholders need to be assessing the risks of attacks bridging Operational Technology (OT) and Information Technology (IT) networks.
- There must be a focus on procedures as well as the components of ICS networks
- Intelligence needs to be part of operations
- More should be done to raise awareness of the risks
Siemens released 9 advisories that address 27 vulnerabilities in their Programmable logic controllers (PLCs). They are tracked as CVE-2021-37185, CVE-2021-37204, CVE-2021-45106, and CVE-2021-37205.
Healthcare
Memorial Hermann Health Systems in southern Texas notified patients of a breach via a contracted vendor named Advent Health Partners. Over 6000 patients protected health information may have been affected.
Comments
Post a Comment