Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
CISA red-team exercises revealed divergent security capabilities across critical infrastructure sectors, with water utilities successfully detecting and halting simulated attacks while a government organization failed to stop the same intrusion attempts after initial compromise. The findings highlight significant gaps in incident response and threat detection maturity within some government agencies compared to their water sector counterparts. These controlled tests underscore the varying levels of preparedness for advanced persistent threats across critical infrastructure.
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
Illinois prosecutors unlawfully shared defendants' personal data with federal immigration agents without obtaining criminal warrants, public disclosure, or legislative authorization. This undisclosed practice raises significant concerns about civil liberties, due process violations, and the lack of oversight mechanisms governing law enforcement data sharing between local and federal authorities.