fbpx
cyber news with cisa

Clive’s weekly Cyber Security roundup – 5 August 2022

Sorry for the delay today – I was involved in a small cyber security issue for a client.

The news this week contains the usual mix of issues that can easily have an impact on any business large or small. Patches and updates are one of the simplest and most essential cyber security steps anyone can take and this has been highlighted by several stories this week – check whether you need to patch or update any of the software you depend on, as this is often the way malware gets into organisations.

We have clients with impacted devices – so our team has been out checking and patching – Smart Thinking Solutions

Cybersecurity and Infrastructure Security Agency exploited vulnerability advisory. How this type of mistake can impact your cyber security and steps to protect yourself. – Smart Thinking Solutions

US CISA security updates advisories – Smart Thinking Solutions

Log4j and ransomware are two topics that always appear in my news stream – this week they came together for a story:

A combination attack that exploits the Log4j vulnerability and VMware to deliver ransomware – Smart Thinking Solutions

You might need to speak to your web designer, software coder or cyber security consultant if you have custom software, to check if this compromises your cybersecurity:

Speaking of ransomware I brought together a number of stories in one article this week, trying to give my readers some idea of the scope of the problem and how they could get to grips with it:

Ransomware, the how and where and what your first step is in defending against it…

The cybersecurity advice for the Ukraine Russia conflict has been updated this week:

Advice from the National Cyber Security Centre and the UK Government – actions to take when the cybersecurity risk is high (Russia Ukraine Conflict) – UPDATED 29 July 2022

I am on leave for the next two weeks. Diana is not coming with me so there will still be news on the Smart Thinking site, but there may not be the weekly round-ups here on the blog. However Octagon does have an news feed page page that updates each time you visit it:

Daily Cyber Security News – Octagon Technology

If you are interested in photography, I will be posting photos of my trip here:

Clive’s Blog

If you are going away have a great time.

Clive Catton MSc (Cyber Security) by-line and other articles

This is a weekly round-up of the articles from Smart Thinking Solutions, our specialist cybersecurity, governance and compliance web site.

The articles are mostly quick reads to give you an overview of the cybersecurity threat landscape facing businesses today, with links to the sources. Many of the posts have action points or top tips to help you navigate these threats to your organisations.

Sometimes they are just there to make you smile!


Because It’s Friday V/VIII/XXII
We have clients with impacted devices – so our team has been out checking and patching
National Cyber Security Centre Threat Report 5 August 2022
Top Malware observed in 2021
US CISA security updates advisories
India does away with its data protection bill in favour of a new bill coming sometime in the future
Ransomware, the how and where and what your first step is in defending against it…
Our future encrypted security – the new algorithm needs more work
A combination attack that exploits the Log4j vulnerability and VMware to deliver ransomware
Seasonal article over on CyberAwake
VMware vital security patches
Chinese Hacktivism UPDATED
Cybersecurity and Infrastructure Security Agency exploited vulnerability advisory. How this type of mistake can impact your cyber security and steps to protect yourself.
It takes only 15 minutes for the threat actors to start scanning for vulnerabilities when they are discovered. How quickly do you respond to gaps in your cybersecurity?
WhatsApp will not lower security
How do threat actors get hold of your login credentials? They just ask you to send them over!
New ransomware article on CyberAwake
Spyware is not an easy way to make a living…
Security patch round-up
It is your mistakes that the opportunistic threat actor is waiting for.
BreachForums is more popular than ever with threat actors
Sealed evidence at risk
The money involved in ransomware
Samba releases security updates
CISA Log4Shell examination
Long term firmware compromise
“Shoddy” customers’ identity security
Stealing emails undetected using Chrome extensions
Commercialised cyberweapons
If a software attack will not work – get out the wire cutters
When your technical defences fail – CyberAwake
European Commission bans EU formal cooperation with UK on online data issues
Was Apple networking diverted through Russia?
And we thought blocking Microsoft Office macros was a good idea – but close one door to the threat actors and of course they find another way to get to you…
Phishing-as-a-Service – called “Robin Banks” you know it is going to be trouble.
Advice from the National Cyber Security Centre and the UK Government – actions to take when the cybersecurity risk is high (Russia Ukraine Conflict) – UPDATED 29 July 2022
Because It’s Friday – how old are deepfakes?