News

SolarWinds MSIB – Breach of Security Reporting Requirement

The US Coast Guard (USCG) published Marine Safety Information Bulletin (MSIB) 03-21 directing any owner or operator of a Maritime Transportation Security Act (MTSA)-regulated facility that relies on SolarWinds software for a system that serves or supports a critical security function to report a Breach of Security if:

  1. They have downloaded the trojanized SolarWinds Orion plug-in (see FBI Private Industry Notification 20201222-001); or
  2. They note any system with a critical security function displaying any signs of compromise, including those that may have not originated from the SolarWinds Orion compromise but utilize similar Tactics, Techniques, and Procedures (TTPs) (see Cybersecurity and Infrastructure Security Agency (CISA) Alert AA20-352A).

CISA recommends utilizing three open-source tools – including a CISA-developed tool, Sparrow – to help detect and remediate malicious activity connected to the SolarWinds incident. Sparrow was created to detect possible compromised accounts and applications in the Azure/Microsoft 365 environment. For guidance on the three open-source tools, see CISA AA21-008A: Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments.

Share:

More Posts

Reduced Cost for Online TWIC Renewal

In August 2022, the Transportation Security Administration (TSA) implemented an online renewal process for Transportation Worker Identification Credential (TWIC) applicants. This new capability permits eligible

Online TWIC Renewal Program

On August 11, 2022, the Transportation Security Administration (TSA) began allowing most current TWIC holders to renew their credentials online without needing to visit an enrollment center.

New TSA Pipeline Security Directive

On Friday, July 23, 2022, the Transportation Security Administration (TSA) issued Security Directive Pipeline 2021-02C (SD-02C). SD-02C has three main components and takes effect on

Send Us A Message