The guidance, from a cluster of US and international agencies published on Wednesday, urges businesses to shore up their defenses by continually validating their security program against known threat behaviors, rather than a more piecemeal approach. “The authoring agencies recommend continually testing your security program, at scale,” according to an alert from the Cybersecurity and Infrastructure Security Agency and several other US and international agencies. The alert warned malicious cyber actors allegedly affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps are exploiting known vulnerabilities for ransom operations. An official at CISA told Bloomberg ahead of the announcement that emulating adversaries and testing against them is key to defending against cyberattacks. Central to the effort is a freely available list of cyberattackers’ most common tactics and procedures that was first made public in 2015 by MITRE, a federally funded research and development center, and is now regularly updated. While many organizations and their security contractors already consult that list, too few check if their systems can actually detect and overcome them, the CISA official said.
Moderna-Merck Vaccine Cuts Recurrence And Spread of Melanoma, Raises New Treatment Hope
A major success in a new field of cancer treatment this week, as Moderna and Merck announced a personalized mRNA cancer vaccine reduced the risk of recurrence and spread of melanoma in a late-stage trial. Read more…