ZeroHour

Search: “NSA”

3 stories

CISA promotes a fresh way to deter cyberattackers: Lie to them

CISA issued first-time guidance advising critical infrastructure operators to deploy honeypots, honeytokens, and decoys to detect and distract intruders.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response,' a 22-page guide marking the agency's first guidance on decoys such as honeypots and honeytokens. Acting executive director Chris Butera described decoys as a low-cost, high-fidelity way to detect adversaries already inside networks, complementing zero-trust and assume-compromise approaches. The guidance covers decoy principles, definitions, deployment scenarios, and is aimed especially at resource-constrained critical infrastructure sectors.

CyberScoop · 14h agoAdvisory

CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks

CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.

CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.

GBHackers · 1d agoAdvisory

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

CISA red teamers compromised both a government and a water organization; water defenders detected and contained the simulated attack, government defenders did not.

CISA's red team gained initial access, elevated domain privileges, and lateral movement into sensitive business systems and cloud resources at an unnamed government organization, whose SOC ignored low- and medium-severity EDR alerts buried under thousands of false positives. A water organization's SOC quarantined phishing-compromised workstations within 2, 10, and 20 minutes, and later detected and isolated intrusions reaching the OT DMZ bastion host. Both organizations underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access and refresh tokens. This is one of CISA's rare public red-team reports since 2023.

CyberScoop · 22d agoAdvisory1