Security News > 2021 > December > CISA warns critical infrastructure to stay vigilant for ongoing threats

The Cybersecurity and Infrastructure Security Agency warned critical infrastructure organizations today to strengthen their cybersecurity defenses against potential and ongoing threats.
"In the lead up to the holidays and in light of persistent and ongoing cyber threats, CISA urges critical infrastructure owners and operators to take immediate steps to strengthen their computer network defenses against potential malicious cyber attacks," the cybersecurity agency said [PDF].
"CISA encourages leadership at all organizations-and critical infrastructure owners and operators in particular-to review the CISA Insights and adopt a heightened state of awareness."
CISA "Strongly" urged orgs from critical infrastructure sectors to increase organizational vigilance, prepare for rapid response, ensure network defenders implement cybersecurity best practices, stay informed about current cybersecurity threats and malicious techniques, and immediately report incidents and anomalous activity.
While CISA did not detail what these ongoing threats are, they are likely referring to the large-scale Log4j exploitation targeting vulnerable systems worldwide.
Two weeks ago, the FBI revealed in a flash alert issued in coordination with CISA that the Cuba ransomware gang alone has compromised the networks of at least 49 organizations from critical infrastructure sectors since it started attacking US targets.
News URL
Related news
- CISA: Medusa ransomware hit over 300 critical infrastructure orgs (source)
- DHS says CISA will not stop monitoring Russian cyber threats (source)
- US charges Chinese hackers linked to critical infrastructure breaches (source)
- CISA tags critical Ivanti EPM flaws as actively exploited in attacks (source)
- UAT-5918 Targets Taiwan's Critical Infrastructure Using Web Shells and Open-Source Tools (source)
- For flux sake: CISA, annexable allies warn of hot DNS threat (source)
- As CISA braces for more cuts, threat intel sharing takes a hit (source)
- CISA extends funding to ensure 'no lapse in critical CVE services' (source)