CMA investigates Simba Sleep’s online sales practices 

  • Post author:
  • Post category:

iStock The Competition and Markets Authority (CMA) has launched an investigation to examine whether Simba Sleep Limited has misled consumers about price reductions and put unfair pressure on consumers to make quick purchases. The concerns being investigated focus on:  Simba Sleep’s use of potentially misleading claims about the extent of price reductions on its mattresses

Continue ReadingCMA investigates Simba Sleep’s online sales practices 

CISA Secure by Design Alert Urges Manufacturers to Eliminate Default Passwords

  • Post author:
  • Post category:

Today, CISA published guidance on How Manufacturers Can Protect Customers by Eliminating Default Passwords as a part of our new Secure by Design (SbD) Alert series. This SbD Alert urges technology manufacturers to proactively eliminate the risk of default password exploitation by implementing principles one and three of the joint guidance, Shifting the Balance of

Continue ReadingCISA Secure by Design Alert Urges Manufacturers to Eliminate Default Passwords

CISA Releases Advisory on Cyber Resilience for the HPH Sector

  • Post author:
  • Post category:

Today, CISA released a Cybersecurity Advisory, Enhancing Cyber Resilience: Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment, that details findings from our risk and vulnerability assessments of a Health and Public Health (HPH) Sector organization. CISA encourages all critical infrastructure organizations as well as software manufacturers to review the advisory and

Continue ReadingCISA Releases Advisory on Cyber Resilience for the HPH Sector

Enhancing Cyber Resilience: Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment

  • Post author:
  • Post category:

SUMMARY In January 2023, the Cybersecurity and Infrastructure Security Agency (CISA) conducted a Risk and Vulnerability Assessment (RVA) at the request of a Healthcare and Public Health (HPH) sector organization to identify vulnerabilities and areas for improvement. An RVA is a two-week penetration test of an entire organization, with one week spent on external testing

Continue ReadingEnhancing Cyber Resilience: Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment

ICS Advisory: Siemens SINEC INS

  • Post author:
  • Post category:

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.1 ATTENTION: Exploitable remotely/low attack

Continue ReadingICS Advisory: Siemens SINEC INS