critical infrastructure
How Chinese-Speaking APT Exploits TinyRCT Backdoor to Target Southeast Asia
A Chinese-speaking APT group has been using a new custom backdoor called TinyRCT to infiltrate government and critical infrastructure entities in Southeast Asia. Experts analyze the threat and provide mitigation strategies.
How to Secure Lantronix EDS5000 Devices From Active Exploitation
CISA warns of active exploitation of a critical flaw in Lantronix EDS5000 industrial Ethernet devices. IT and OT teams must act quickly to patch vulnerable systems and strengthen overall security.
Poor security left hackers inside water company network for nearly two years
The UK’s data protection regulator, the Information Commissioner’s Office (ICO), fined South Staffordshire Water’s parent company £963,900 over security failures linked to a cyberattack that exposed the personal data of 633,887 people. According to the ICO, the South Staffordshire breach began in September 2020 with a phishing email that tricked an employee into opening an attachment, allowing attackers to install…