Are you ready to accelerate digital transformation? @BuschRo, our President and CEO, is! 🚀 Join him, and other top industry and tech leaders, on 29 June 5pm CEST at #SiemensAccelerate ✨ Click to register now!
Get ready to accelerate change! Soon you will find out how to accelerate your business and sustainable innovation. Join us, on 29 June, as we unlock the potential of #DigitalTransformation; making it fast, easy and scalable.
Hundreds of high-ranking international military and politicians will gather in Munich this weekend at the Munich Security Conference. All major foreign and security policy issues are discussed at the #MSC2022. Meanwhile, some are increasingly talking abou…https://t.co/kIn1siqskU
2021 is coming to an end. Since it's not easy to meet in person these days, we tried to combine the best of our real and digital home office worlds in this year's seasons greetings for you. We wish you and your families #HappyHolidays and all the best for 2022 🌟 #staysafe
Quoting from article: "An organization that thinks its Log4Shell problem is solved may let down its guard.
...the biggest threat here is that people have already gotten access and are just sitting on it, and even if you remediate the problem somebody’s already in the network”
The listing of products and systems affected by #log4shell maintained by the Netherlands Cybersecurity Center (NCSC-NL) on this github site is impressive. Even covers #ICS vendor announcements - including ours https://t.co/LUNbBIC5Q8
https://t.co/eUaCaSTWwz
“Log4j & Log4Shell” Free online vulnerability checker by Huntress Labs. It's Security Now's GRC shortcut of the week:
grc[dot]sc/849
The page issues each visitor a unique GUID to be used in forms, queries, etc. They monitor for incoming LDAP queries which can then be looked up.
#Log4Shell quoting the crux of the needed fix from the article: " CVE-2021-44228 can only be abused if the log4j2.formatMsgNoLookups option in the library’s configuration is set to false."
@Paul4innovating@Paul4innovating Incident Response and Disaster Recovery are very much within the scope of the Peoples / Processes / Products triad. Of course, a true blackout is not likely to happen with a single cyber incident. Nevertheless, one must plan for the worst case with the 3Ps.
@mirko_ross@Siemens@Hackwerk_io@TylerCohenWood Yes, security patch management and vulnerability management are absolute musts for an ISO's policies. Prerequisite of course being Asset Inventory management for all power grid equipment.