Thursday, January 23, 2025
HomeCyber Security NewsCISA Releases Advisory to Monitor Networks to Detect Malicious Cyber Actors

CISA Releases Advisory to Monitor Networks to Detect Malicious Cyber Actors

Published on

SIEM as a Service

Follow Us on Google News

The National Security Agency (NSA) has partnered with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and other entities to release a critical advisory.

This initiative comes in response to the exploitation of major global telecommunications providers by a threat actor affiliated with the People’s Republic of China (PRC).

The advisory is encapsulated in the Cybersecurity Information Sheet (CSI) titled “Enhanced Visibility and Hardening Guidance for Communications Infrastructure.”

This document offers comprehensive defensive strategies designed to enhance the monitoring of networks and reinforce device security.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

It targets engineers and system administrators overseeing communications infrastructure but is also relevant to organizations managing on-premises enterprise equipment.

Dave Luber, NSA Cybersecurity Director, emphasized the importance of vigilance in cybersecurity, stating, “Vigilance is key for defending against network compromise. Always have eyes on your systems and patch and address known vulnerabilities before they become targets.”

The CSI outlines several critical measures aimed at enhancing visibility into network activities. These measures include logging all configuration changes and management connections at network perimeters and setting up alerts for unforeseen activities.

Moreover, the advisory underscores the significance of adopting robust hardening practices, such as disabling unused, unauthenticated, or unencrypted protocols, securing passwords, restricting management connections and privileged accounts, and ensuring timely patching and upgrading of devices.

According to the National Security Agency report, the guidance notably focuses on strengthening Cisco operating systems, which the PRC-affiliated threat actor specifically targeted.

The document provides detailed recommendations to mitigate these vulnerabilities, reducing the risk of malicious cyber activities.

The release of this advisory marks a proactive step towards safeguarding critical infrastructure against evolving cyber threats.

Organizations are encouraged to adopt these guidelines to bolster their defenses and protect sensitive communications networks from potential security breaches.

As cyber threats continue to grow in sophistication, such collaborative efforts are crucial in maintaining the integrity and security of global telecommunications infrastructure.

Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Critical Vulnerability in Next.js Framework Exposes Websites to Cache Poisoning and XSS Attacks

A new report has put the spotlight on potential security vulnerabilities within the popular...

New Cookie Sandwich Technique Allows Stealing of HttpOnly Cookies

The "Cookie Sandwich Attack" showcases a sophisticated way of exploiting inconsistencies in cookie parsing...

GhostGPT – Jailbreaked ChatGPT that Creates Malware & Exploits

Artificial intelligence (AI) tools have revolutionized how we approach everyday tasks, but they also...

Tycoon 2FA Phishing Kit Using Specially Crafted Code to Evade Detection

The rapid evolution of Phishing-as-a-Service (PhaaS) platforms is reshaping the threat landscape, enabling attackers...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

GhostGPT – Jailbreaked ChatGPT that Creates Malware & Exploits

Artificial intelligence (AI) tools have revolutionized how we approach everyday tasks, but they also...

Tycoon 2FA Phishing Kit Using Specially Crafted Code to Evade Detection

The rapid evolution of Phishing-as-a-Service (PhaaS) platforms is reshaping the threat landscape, enabling attackers...

Microsoft Unveils New Identity Secure Score Recommendations in General Availability

Microsoft has announced the general availability of 11 new Identity Secure Score recommendations in...