Week in Review: Water cyber-regs rescinded, Cisco zero-day attacks, Signal debunks zero-day
Oct 20, 2023
auto_awesome
Guest Andrew Wilder, CISO, Community Veterinary Partners, discusses the disappointment in Biden admin's decision to withdraw water cyber regs, zero-day attacks on Cisco, signal debunking zero-day claim. 'Sleeping Dragon' data vulnerability and solutions for vulnerability management and prioritization are also discussed.
The US EPA is rescinding its cybersecurity audit requirements for water utilities, undermining the Biden administration's efforts to enhance critical infrastructure security.
Over 10,000 Cisco devices are vulnerable to zero-day attacks, exposing the network traffic and enabling malicious actors to perform man-in-the-middle attacks due to lack of patch implementation.
Deep dives
EPA Rescinds Cyber Regulations for Water Sector
The US Environmental Protection Agency (EPA) is withdrawing its requirements to conduct cybersecurity audits of water utilities due to litigation. This decision is a blow to the Biden administration's efforts to increase cybersecurity in vital infrastructure.
Zero-Day Attacks on Cisco Devices
More than 10,000 Cisco devices are affected by zero-day attacks. These attacks exploit a critical vulnerability that allows threat actors to monitor network traffic and perform man-in-the-middle attacks. The lack of patch implementation by users leaves these devices vulnerable to exploitation.
Signal Debunks Zero-Day Reports
Signal, the encrypted messaging app, denies the existence of a zero-day vulnerability that would compromise targeted mobile devices. While concerns have been raised, Signal emphasizes that there is no evidence to support the claim and remains committed to maintaining strong encryption and subscriber privacy.
“Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta’s market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode