NDAA Conference: Opportunity to Improve the Nation’s Cybersecurity Posture | McAfee Blogs

NDAA Conference: Opportunity to Improve the Nation’s Cybersecurity Posture | McAfee Blogs

As Congress prepares to return to Washington in the coming weeks, finalizing the FY2021 National Defense Authorization Act (NDAA) will be a top priority. The massive defense bill features several important cybersecurity provisions, from strengthening CISA and promoting interoperability to creating a National Cyber Director position in the White House and codifying FedRAMP. These are vital components of the legislation that conferees should work together to include in the final version of the bill, including:…

Read More

Weekly Threat Briefing: Malware, Lazarus Group, Vulnerabilities and More

Weekly Threat Briefing: Malware, Lazarus Group, Vulnerabilities and More

The various threat intelligence stories in this iteration of the Weekly Threat Briefing discuss the following topics: APT, Cryptojacking, DDoS, North Korea, Shlayer, Trojan, and Vulnerabilities. The IOCs related to these stories are attached to the Weekly Threat Briefing and can be used to check your logs for potential malicious activity. Figure 1 – IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed. Trending…

Read More

Vulnerability Discovery in Open Source Libraries: Analyzing CVE-2020-11863 | McAfee Blogs

Vulnerability Discovery in Open Source Libraries: Analyzing CVE-2020-11863 | McAfee Blogs

Open Source projects are the building blocks of any software development process. As we indicated in our previous blog, as more and more products use open source code, the increase in the overall attack surface is inevitable, especially when open source code is not audited before use. Hence it is recommended to thoroughly test it for potential vulnerabilities and collaborate with developers to fix them, eventually mitigating the attacks. We also indicated that we were…

Read More
1 2,539 2,540 2,541