Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Microsoft Releases Fix for New Zero-Day with May 2022 Patch Tuesday Updates cyber security news
  • UK Affirms Commitment to Regulate Stablecoins Following Terra Meltdown – Regulation Bitcoin News bitcoin news
  • NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages cyber security news
  • Blue Chip NFTs 101 – How Did Moonbirds Conquer The World In A Bearish Market? bitcoin news
  • Veteran Investor Jim Rogers Optimistic About Future of Crypto Money – Bitcoin News bitcoin news
  • Digital Collectible Owners Continue to Take Loans out Using NFTs as Collateral – Blockchain Bitcoin News bitcoin news
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over bitcoin news
  • MicroStrategy Will Not Dump Any Of Its Bitcoin, CFO Reveals bitcoin news

Government Agencies Warned of Increase in Cyberattacks Targeting MSPs

Posted on May 12, 2022 By root


Multiple cybersecurity authorities from Australia, Canada, New Zealand, the U.K., and the U.S. on Wednesday released a joint advisory warning of threats targeting managed service providers (MSPs) and their customers.

Key among the recommendations include identifying and disabling accounts that are no longer in use, enforcing multi-factor authentication (MFA) on MSP accounts that access customer environments, and ensuring transparency in ownership of security roles and responsibilities.

MSPs have emerged as an attractive attack route for cybercriminals to scale their attacks, as a vulnerable provider can be weaponized as an initial access vector to breach several downstream customers at once.

The spillover effects of such intrusions, as witnessed in the wake of high-profile breaches aimed at SolarWinds and Kaseya in recent years, have once again underlined the need to secure the software supply chain.

The targeting of MSPs by malicious cyber actors in an effort to “exploit provider-customer network trust relationships” for follow-on activity such as ransomware and cyber espionage against the provider as well as its customer base, the agencies cautioned.

The major security measures and operational controls outlined in the advisory are as follows –

  1. Prevent initial compromise by securing internet-facing devices and implementing protections against brute-forcing and phishing attacks
  2. Enable effective monitoring and logging of systems
  3. Secure remote access applications and mandate MFA where possible
  4. Isolate critical business systems and apply appropriate network security safeguards
  5. Apply the principle of least privilege throughout the network environment
  6. Deprecate obsolete accounts through periodic audits
  7. Prioritize security updates for operating systems, applications, and firmware, and
  8. Regularly maintain and test offline backups for incident recovery.

The Five Eyes alert arrives a week after the U.S. National Institute of Standards and Technology (NIST) published updated cybersecurity guidance for managing risks in the supply chain.

“MSPs should understand their own supply chain risk and manage the cascading risks it poses to customers,” the agencies said. “Customers should understand the supply chain risk associated with their MSP, including risk associated with third-party vendors or subcontractors.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange Servers
Next Post: Everything We Learned From the LAPSUS$ Attacks

Related Posts

  • What You Need to Know to Stay Resilient cyber security news
  • Chinese “Override Panda” Hackers Resurface With New Espionage Attacks cyber security news
  • How to Protect Your Data When Ransomware Strikes cyber security news
  • Thousands of Borrowers’ Data Exposed from ENCollect Debt Collection Service cyber security news
  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • North Korean Hackers Target Journalists with GOLDBACKDOOR Malware cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys
  • ETH Back Under $2,000 as Balenciaga Gains Lose Steam – Market Updates Bitcoin News

Recent Comments

No comments to show.
  • Lawmakers, SEC Commissioner Slam Chair Gensler for Focusing on Crypto Enforcement – Regulation Bitcoin News bitcoin news
  • Bitcoin Seen Dropping To $32K – But Not This Month bitcoin news
  • SEC Halts $62 Million Crypto Mining, Trading Scheme — DOJ Indicts Founder – Regulation Bitcoin News bitcoin news
  • ‘A Dark Day for Crypto’ — A Deep Dive Into the Obliterated Terra Token Ecosystem and Damaged Apps – Bitcoin News bitcoin news
  • Which Hole to Plug First? Solving Chronic Vulnerability Patching Overload cyber security news
  • BTC Slips to Its Lowest Point Since December 2020 – Market Updates Bitcoin News bitcoin news
  • Credibility Concerns — Gallop Poll Shows Fed Chair’s Confidence Ratings Slid by Double Digits – News Bitcoin News bitcoin news
  • Global Asset Manager Vaneck Launches Community NFT Project — 1,000 NFTs to Be Airdropped This Week – Featured Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme