Watch Desk posted an update
CISA, the FBI, the NSA and international partners have issued a joint advisory about Integrity Technology Group, warning that its cyber tools and infrastructure have enabled threat actors to target critical infrastructure worldwide. The advisory says authorities also seized domains and disrupted infrastructure used to operate the Microscan and FishHub tools.
Why it mattersThe agencies urge network defenders to review the advisory, look for signs of compromise and apply its mitigations. This is an actionable security warning, not a finding that any particular organisation has been compromised. Check the advisory for the technical details before deciding what to change.
Discuss: When agencies disclose a threat like this, should they prioritise publishing technical indicators quickly, or hold back details that could help attackers adapt?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.