Intelligent CISO Issue 33 | Page 24

threat updates

1

NORTH AMERICA
Key government departments in the US have been targeted in a major cyberespionage campaign . The suspected state-sponsored attacks were directed at the networks of the treasury , commerce and homeland security departments . Federal civilian agencies were told to disconnect from SolarWinds Orion following the breach by malicious actors . Casey Ellis of Bugcrowd , said : “ The breach of SolarWinds Orion ’ s code poses a major threat to the Federal Civilian Executive Branch agencies that were using its software .”
2
1

2

EUROPE
Ireland ’ s Data Protection Commission ( DPC ) has fined California-based Twitter for infringements of the EU ’ s GDPR data protection laws . A statement from the DPC said : “ The DPC ’ s investigation commenced in January 2019 following receipt of a breach notification from Twitter and the DPC has found that Twitter infringed Article 33 ( 1 ) and 33 ( 5 ) of the GDPR in terms of a failure to notify the breach on time to the DPC and a failure to adequately document the breach .”
GLOBAL
IBM has reported that the organisations involved in the COVID-19 vaccinations supply chain have been targeted by calculated cyberattacks . According to IBM ’ s analysis , the targeted attack began in September 2020 and spanned across six countries . Max Heinemeyer , Director of Threat Hunting at Darktrace , commented : “ Attacking the supply chain is often easier than going after the core target . This particular effort to disrupt vaccine research and development confirms that the barrier between the ‘ cyber ’ and ‘ physical ’ supply chains has all but dissolved .”
24 www . intelligentciso . com