Vane3alga

Business
Focused
Technology

A new joint cybersecurity advisory from CISA, the FBI, and the NSA cautions organizations against Russian-based attacks and provides mitigations to be implemented.

It’s one thing to see an advisory that simply says “hey, we’re seeing bunch more attacks.” But when you also see 8 pages of recommended security measures and a statement encouraging “the cybersecurity community—especially critical infrastructure network defenders—to adopt a heightened state of awareness and to conduct proactive threat hunting”, you know they know something you don’t.

www.knowbe4.comhubfsCISA LOGO

This is exactly what is in yesterday’s cybersecurity advisory entitled “Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure”.

While the advisory isn’t focused on a specific threat, it does begin with some general statements of what’s been observed:

Historically, Russian state-sponsored advanced persistent threat (APT) actors have used common but effective tactics—including spearphishing, brute force, and exploiting known vulnerabilities against accounts and networks with weak security—to gain initial access to target networks.

Russian state-sponsored APT actors have also demonstrated sophisticated tradecraft and cyber capabilities by compromising third-party infrastructure, compromising third-party software, or developing and deploying custom malware. The actors have also demonstrated the ability to maintain persistent, undetected, long-term access in compromised environments—including cloud environments—by using legitimate credentials.

Even if you’re not a “critical infrastructure” organization, this advisory is solid reading. It offers real-world examples of Russia-based attacks, vulnerabilities used, observed tactics and techniques mapped to the MITRE ATT&CK Framework, and practical guidance to shore up your Detection, Incident Response, and Mitigation efforts.

In general, the advisory makes the following high-level recommendations:


Source: KnowBe4

Success Stories

Principal Owner, Marketing Firm

Bringing IT360 on as our technology services “department” was one of the smartest business decisions we’ve made. Over the years, we’ve tried various similar services and have also hired internal IT staff, and we’ve never felt confident that we were adequately supported. IT360 has changed all that. They not only provide proactive, comprehensive technical support and consulting, they engage with us in a way that feels like they are part of our company…a true business partner.

Principal Owner, Marketing Firm

Recent
Technology News

IT 360 News - Why Your Old Phone System Is Holding You Back
Why Your Old Phone System Is Holding You Back

It’s Time to Rethink How Your Business Communicates Many businesses are still relying on traditional phone systems that were designed for a very different era—when everyone worked in one building, at one desk, on one device. Today’s workforce looks nothing like that. Teams are remote or hybrid. Employees expect mobility. Companies are growing, changing, and […]

Read more
IT 360 News - Why Technology Governance Is Moving From “IT Issue” to Executive Responsibility
Why Technology Governance Is Moving From “IT Issue” to Executive Responsibility

Over the past year, technology failures have increasingly made headlines—not because of system outages alone, but because of their business consequences. Cyber incidents, operational disruptions, and data exposure events are no longer viewed as isolated IT problems; they are now framed as governance, risk, and leadership issues. This shift is not theoretical. Insurers are tightening […]

Read more