{"id":4598,"date":"2024-05-17T17:57:12","date_gmt":"2024-05-17T05:57:12","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/05\/17\/news20240517\/"},"modified":"2025-03-10T17:06:33","modified_gmt":"2025-03-10T04:06:33","slug":"news20240517","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/05\/17\/news20240517\/","title":{"rendered":"Recent news &#8211; May 17"},"content":{"rendered":"\n<p>What we&#8217;ve been reading &#8230; <\/p>\n\n\n\n<p><strong>U.S. critical infrastructure organizations need to improve cyber hygiene<\/strong><\/p>\n\n\n\n<p>In almost all attacks seen against U.S. critical infrastructure organizations, cyber actors have taken advantage of poor cyber hygiene practices. These include the use of default or weak passwords, unpatched known vulnerabilities, and poorly secured network connections. Avril Haines, Director of National Intelligence, said they are seeing record levels of attacks against U.S. industrial control systems typically used to automate industrial processes and widely used by critical infrastructure organizations. <a href=\"https:\/\/www.defense.gov\/News\/News-Stories\/Article\/Article\/3763862\/good-cyber-hygiene-can-impede-adversary-meddling-in-us-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Defense.gov<\/a><\/p>\n\n\n\n<p><strong>Aiden for addressing vulnerabilities and keeping Windows endpoints at the desired specification<\/strong><\/p>\n\n\n\n<p>Aiden Technologies announced new security capabilities to mitigate vulnerabilities faster across Windows endpoints. Its AidenVision system identifies and alerts on high and critical CVEs across all Windows endpoints, maps what new software patches are needed to address these CVEs, and then automates remediation. Pre-AidenVision, the company says that organizations typically took 55 days to remediate 50% of the most critical KEVs from CISA. Post-AidenVision, organizations can deal with 97% of the most critical CVEs within 3 days. The reporting system gives audit-ready evidence to meet enquiries from regulatory bodies and insurance carriers. <a href=\"https:\/\/www.meetaiden.com\/blog\/press-release-aiden-announces-groundbreaking-new-capabilities-to-discover-and-remediate-windows-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Aiden Technologies<\/a><\/p>\n\n\n\n<p><strong>Another reason to stop relying on SMS for MFA<\/strong><\/p>\n\n\n\n<p>Receiving one-time codes by SMS is a very convenient way of enacting multi-factor authentication requirements. It is, however, one of the least secure methods of MFA and one we continually recommend against. With phishing kits routinely including MFA bypass capabilities for one-time codes, SMS and other MFA mechanisms that take this approach should be deprecated in your security posture. And here&#8217;s another reason: fraudsters are targeting employees at mobile carriers with offers of money to perform a SIM swap, thus giving them access to a user&#8217;s phone number to receive MFA codes, among other malicious benefits. <a href=\"https:\/\/securityboulevard.com\/2024\/04\/sim-swap-bribe-t-mobile-300-richixbw\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security Boulevard<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent news: need for cyber hygiene in critical infrastructure organizations, addressing vulnerabilities across a Windows environment, and SIM swappers targeting mobile carrier employees.<\/p>\n","protected":false},"author":384585,"featured_media":4317,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027488,712027501,712027505],"tags":[712027529],"class_list":["post-4598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-critical-infrastructure","category-news-roundup","category-vulnerability-management","tag-whats-going-down"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/03\/approov2022.png?fit=1160%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1ca","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4598"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4598\/revisions"}],"predecessor-version":[{"id":4666,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4598\/revisions\/4666"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4317"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}