CISA is worried that critical infrastructure is vulnerable to ransomware attacks

ransomware avast
(Image credit: Avast)

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is worried about critical infrastructure organizations being targeted by ransomware actors. 

To minimize the chances of that happening, the government body launched a new pilot program to help scan networks for bad actors, and help vulnerable firms fix their flaws before the problem escalates.

The program is called the “Ransomware vulnerability warning pilot” (RVWP), and it was officially launched on January 2023. 

Securing the perimeter

"As part of RVWP, CISA leverages existing authorities and technology to proactively identify information systems that contain security vulnerabilities commonly associated with ransomware attacks," the organization said. 

“Once CISA identifies these affected systems, our regional cybersecurity personnel notify system owners of their security vulnerabilities, thus enabling timely mitigation before damaging intrusions occur."

Ever since the devastating attack on Colonial Pipeline, which happened in early May 2021, the United States government has been hard at work looking to protect its critical infrastructure and has started proactively targeting ransomware threat actors. 

The attack against Colonial Pipeline is considered the biggest cyberattack on an oil infrastructure organization in US history, as it disrupted oil and gas distribution in 17 states.

The group behind the attack was identified as DarkSide, and reports claim that Colonial Pipeline paid the ransom demand (approximately $4.4 million) in bitcoin just a few hours after the attack. Less than a month later, though, the US Department of Justice announced that they had seized almost all of the bitcoin used to pay the ransom (63.7 out of 75). But DarkSide still managed to steal at least 100GB of sensitive data. 

That same month, CISA released the Ransomware Readiness Assessment (RRA), a new module for its Cyber Security Evaluation Tool (CSET), helping businesses analyze how prepared they are for a ransomware scenario. Later that year, CISA published additional guidance, helping at-risk organizations tackle the growing problem of ransomware attacks.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
UK Government launches ransomware protection proposals
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening