CFSN Detailed Analysis - Substack Daily Update – 1-11-24 – Free Content – http://tinyurl.com/mrye2ntj
Short Takes – 1-11-24 – Bitcoin service – 5 Alzheimer’s variants – Wrench vulnerabilities – Spending woes redux – PFAS TSCA final rule – Axiom-3 and China resupply missions – Antibiotic politics - http://tinyurl.com/3p35wj7a
Review - 9 Advisories Published – 1-11-24 – NCCIC-ICS control system security advisories for Siemens (6), Schneider, Horner Automation, and Rapid Software – Short version – http://tinyurl.com/3yj24735 #icsSecurity
9 Advisories Published – 1-11-24 – NCCIC-ICS control system security advisories for Siemens (6), Schneider, Horner Automation, and Rapid Software – Includes a look at ‘missing advisories’ in 2023 - http://tinyurl.com/3ts6pn8p Subscription required #icsSecurity
To prove the point that users will continue to click links, regardless of how obvious it is that they shouldn't, I worked with the person in charge of the monthly phishing trainings at $dayjob last month. Historically, they have used the hated ruses like fake gift cards, and I wanted to try to get away from that, especially during the holidays. We ended up using something to the effect of the following:
---
Hello <first name>,
Happy Holidays. This is the monthly phishing test. Yes, really. It's not a trick. Use the <phishing reporting function> to report this as phishing. If you do not know how to use <phishing reporting function>, feel free to ask a colleague. If you still have questions, search for <phishing reporting function> on <internal docs site>.
Do not click the following link as it is there for metrics and will cause you to be assigned phishing awareness training: <phishing training 'malicious' link>
Sincerely,
IT Security Team
---
I don't know how well it was received by users, but I do know that we still had more clicks than two other months in 2023, despite being explicitly told not to click the link. Users will always click links with their link-clicking machines. Relying on their discretion is either ignorant, or I expect in some cases, malicious in that there will always be a scapegoat to blame for the inevitable breach.
OMG!!! XKCD's What If? is now a YouTube channel..... https://www.youtube.com/@xkcd_whatif
CFSN Detailed Analysis - Substack Daily Update – 1-10-24 – Free Content – http://tinyurl.com/yeybf89n
Short Takes – 1-10-24 – US climate pollution falls – Spending bills – Axiom Mission 3 to ISS –http://tinyurl.com/yc62rhr7
Review - HR 6494 Introduced – 2023 PIPES Act – PHMSA Pipeline Safety Regulation reauthorization – Includes congressional guidance on updates to PSR – http://tinyurl.com/3w5h5zan #Legislation #PHMSA #PipelineSafety
HR 6494 Introduced – 2023 PIPES Act – PHMSA Pipeline Safety Regulation reauthorization – Includes congressional guidance on updates to PSR - http://tinyurl.com/3un8ewv5 #Legislation #PHMSA #PipelineSafety
Short Takes – 1-10-24 – Space Geek Edition – Artemis delayed – Moon exploration problems – Indian space program – Space Force cyber – http://tinyurl.com/bdhp9cx2
CFSN Detailed Analysis - Substack Daily Update – 1-9-24 – Free Content – http://tinyurl.com/2e4x6p4j
Short Takes – 1-9-24 – Google AI training tool – Red Sea conflict – NNSA counter UAS operations – Long trains problem – NMSAC meeting – Eye Irritation and corrosion hazard guidance – http://tinyurl.com/x9tdxns4
Review - 1 Updated Published – 1-9-24 – NCCIC-ICS control system advisory update for products from Cambium – http://tinyurl.com/y9j8yjnj #icsSecurity
1 Updated Published – 1-9-24 – NCCIC-ICS control system advisory update for products from Cambium – DTRH look at NCCIC-ICS CVE’s reported in 2023 – http://tinyurl.com/32spc5tx Subscription required #icsSecurity
Today Schnieder published two advisories and six updates - https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Today Siemens published six new advisories and updated 11 - https://www.siemens.com/global/en/products/services/cert.html
CFSN Detailed Analysis - Substack Daily Update – 1-8-24 – Free Content – http://tinyurl.com/sz92maeu
Short Takes – 1-8-24 – Vulcan launch (2) – Dutch Stuxnet vector – Spending deal (2) – Tripledemic – Bird flu and eggs - http://tinyurl.com/yta5k7p8