CERT mailing list archives

Global Threats to Information Systems


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Thu, 21 Jun 2018 16:56:56 -0500

U.S. Department of Homeland Security US-CERT

National Cyber Awareness System:



Global Threats to Information Systems [ 
https://www.us-cert.gov/ncas/current-activity/2018/06/21/Global-Threats-Information-Systems ] 06/21/2018 04:10 PM EDT 
Original release date: June 21, 2018

The advanced capabilities of organized hacker groups and cyber threat actors are an increasing global threat to 
information systems. Rising threat levels place more demands on cybersecurity personnel and network administrators to 
protect information systems. Protecting network infrastructure is critical to preserving the confidentiality, 
integrity, and availability of communication and services across an enterprise.

Cyber campaignssuch as NotPetya [ https://www.us-cert.gov/ncas/alerts/TA17-181A ]are examples of increasingly advanced 
threat actor activity. NotPetya coincided with a national holiday of the targeted nation. NCCIC recommends 
organizations remain vigilant and aware of potential malicious cyber activity ahead of upcoming national holidays, 
including Ukraines Constitution Day on June 28, 2018.

NCCIC encourages users and administrators to review Securing Network Infrastructure Devices [ 
https://www.us-cert.gov/ncas/tips/ST18-001 ] and the United Kingdoms National Cyber Security Centre (NCSC) guidance on 
Internet Edge Device Security [ https://www.ncsc.gov.uk/guidance/internet-edge-device-security ] and implement the 
following recommendations:


  * Segregate networks and functions. 
  * Limit unnecessary lateral communications. 
  * Harden network devices. 
  * Secure access to infrastructure devices. 
  * Perform out-of-band network management. 
  * Validate hardware and software integrity. 
________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: