Security News > 2023 > April > Supply Chain Attacks and Critical Infrastructure: How CISA Helps Secure a Nation's Crown Jewels

According to Etay Maor, Senior Director Security Strategy at Cato Networks, "It's interesting to note critical infrastructure doesn't necessarily have to be power plants or electricity. A nation's monetary system or even a global monetary system can be and should be considered a critical infrastructure as well."
Not to mention the infamous Colonial Pipeline attack, which has become the poster child of critical infrastructure attacks.
Supply chain attacks are a key way to attack critical infrastructure.
Just like bombings in WW2 targeted factories that provided supplies to the military, supply chain cyber attacks target the nation's critical infrastructure suppliers.
The potential severity of attacks on critical infrastructure has driven nations to establish a cyber defense organization to defend their critical assets, and prepare for conflicts.
To learn more about how CISA operates and how to prevent supply chain attacks on critical infrastructure, the Cato Networks' Cyber Security Masterclass series is available for your viewing.
News URL
https://thehackernews.com/2023/04/supply-chain-attacks-and-critical.html
Related news
- CISA warns of hackers targeting critical oil infrastructure (source)
- Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories' CI/CD Secrets Exposed (source)
- ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More (source)
- Critical auth bypass bug in CrushFTP now exploited in attacks (source)
- Recent GitHub supply chain attack traced to leaked SpotBugs token (source)
- SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack (source)
- That massive GitHub supply chain attack? It all started with a stolen SpotBugs token (source)
- CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks (source)
- CISA extends funding to ensure 'no lapse in critical CVE services' (source)
- CISA tags SonicWall VPN flaw as actively exploited in attacks (source)