Tuesday , April 1 2025

infosecbulletin

CISA Releases Two Industrial Control Systems Advisories

CISA

CISA released two advisories on February 29, 2024. The advisories warn about security issues, vulnerabilities, and exploits related to Industrial Control Systems (ICS). ICSA-24-060-01 Delta Electronics CNCSoft-B ICSMA-24-060-01 MicroDicom DICOM Viewer EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity Vendor: Delta Electronics Equipment: CNCSoft-B Vulnerability: Stack-based Buffer Overflow RISK …

Read More »

CISA Releases Resource Guide for University Cybersecurity Clinics

CISA

CISA released a Resource Guide for Cybersecurity Clinics today. This guide explains how CISA can collaborate and assist cybersecurity clinics and their clients. University cybersecurity clinics train students to strengthen the digital defenses of under-resourced organizations. They help address the national cyber workforce gap by developing a talent pipeline for …

Read More »

NIST Releases Cybersecurity Framework 2.0 Officially

NIST

NIST has released its Cybersecurity Framework 2.0 after several years of consideration. The new framework expands its recommendations to cover the concerns of organizations beyond critical infrastructure. NIST issued the first CSF in 2014, in response to a presidential executive order, to assist organizations, particularly critical infrastructure, in managing cybersecurity …

Read More »

Alert – Critical SQLi Vulnerability Threatens 200K+ Websites

code

A critical security vulnerability has been revealed in the widely used WordPress plugin called Ultimate Member, which is installed on over 200,000 websites. The vulnerability CVE-2024-1071 has a high CVSS score of 9.8 out of 10. It was discovered and reported by security researcher Christiaan Swiers. WordPress security company Wordfence …

Read More »

Chainalysis Report
$100 million in crypto payments to Myanmar scam syndicate

Myanmar, IMAGE: MOHIGAN / WIKIMEDIA COMMONS / CC BY-SA 3.0

Investigators found that two cryptocurrency addresses linked to a company in Myanmar received nearly $100 million in deposits in less than two years. This sheds light on the lucrative business of conducting romance scams and extorting ransom payments from the families of trafficked workers. Chainalysis and a human rights researcher …

Read More »

Microsoft released PyRIT, A Tool For Generative AI Systems

office

Microsoft has released a new open automation framework called PyRIT (Python Risk Identification Toolkit). It helps security professionals and machine learning engineers identify and reduce risks in generative models. The need for automation in AI Red Teaming: Red teaming AI systems is complex. Microsoft’s AI Red Team consists of experts …

Read More »

NCSA organized a seminar on ‘Safe Internet Usage’ in Rangpur

seminar

The National Cyber Security Agency  (NCSA) rganized a seminar on ‘Safe Internet Usage’ at Rangpur District Shilpakala Academy Auditorium. Over 500 students, teachers, and parents from various educational institutions in Rangpur City Corporation attended the seminar and were informed about staying safe in the cyber world. The National Cyber Security …

Read More »