Cybersecurity Infrastructure Security Administration
‘FRED’ Security FAIL — Ignored by US Rail for 20 YEARS
Richi Jennings | | American Association of Railways (AAR), cisa, CISA Advisories, CISA Advisory, CISA Alert, CISA cybersecurity advisory, CVE-2025-1727, Cybersecurity and Infrastructure Security Agency, Cybersecurity Infrastructure Security Administration, FRED, ICS/SCADA, ICS/SCADA Cybersecurity, ICS/SCADA Security, ICS/SCADA systems, ICS/SCADA Wireless Attacks, RADIO-STOP, Rail Cybersecurity, railroad, Railway Security, SB Blogwatch, sdr, software defined radio (SDR), trains, wireless
BCH vs. SDR, AAR vs. CISA: Railroad industry first warned about this nasty vulnerability in 2005 ...
Security Boulevard
GitLab ‘Perfect 10’ Bug Gets a CISA Warning: PATCH NOW
Richi Jennings | | cisa, CISA Advisories, CISA Advisory, CISA Alert, CISA KEV, cisa known exploited vulnerabilities, cisa known exploited vulnerabilities catalog, CISA Threat Update, CISA warning, CISA.gov, CVE-2023-7028, CVSS10, Cybersecurity Infrastructure Security Administration, GitLab, GitLab Community Edition, GitLab CVE-2023-7028 CVE-2023-5356, GitLab Enterprise Edition, GitLab Patches, GitLab Security, GitLab Vulnerability, NSA/CISA, Password reset, Password reset protection, SB Blogwatch, software supply chain, software supply chain attack, software supply chain attacks, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity
Password reset FAILURE: The U.S. Cybersecurity and Infrastructure Security Agency warns GitLab users of a 100-day-old, maximum severity vulnerability ...
Security Boulevard
Biden Review Board Gives Microsoft a Big, Fat Raspberry
Richi Jennings | | Active Directory, Authentication, azure, Azure Active Directory, Azure AD, Azure security, cisa, CISA.gov, CSRB, Cyber Safety Review Board, Cybersecurity Infrastructure Security Administration, Entra ID, Exchange, Microsoft, Microsoft Azure, Microsoft Azure Active Directory, Microsoft Azure Security, Outlook.com, SB Blogwatch, Storm-0558
Storm-0558 forecast: Last year’s Chinese hack of federal agencies’ email is still a mystery, and “should never have occurred,” says CISA ...
Security Boulevard
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?
BrianKrebs | | A Little Sunshine, CVE-2020-4006, Cybersecurity Infrastructure Security Administration, Democratic National Committee, FBI, fireeye, GoldMax, Lexicon.exe, Microsoft, National Security Agency, National Telecommunications and Information Administration, NTIA, solarwinds-hack, Sunshuttle, The Wall Street Journal, U.S. Commerce Department, U.S. Treasury Department, VirusTotal, VMware
On Aug. 13, 2020, someone uploaded a suspected malicious file to VirusTotal, a service that scans submitted files against more than five dozen antivirus and security products. Last month, Microsoft and FireEye ...

