top of page

Manufacturing

Public·4 members

Jake Geier
Jake Geier

Pentagon Hits Pause on CMMC Phase II: What Contractors Need to Know


What:

  • The DoD suspended CMMC Phase II requirements until it reviews the program to allow for more innovation in the US defense industrial base infosecurity-magazine

  • Phase II was originally scheduled to come into effect on November 10, 2026, requiring contractors handling CUI to transition from basic self-attestations to mandatory, independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs) against the 110 NIST SP 800-171 controls infosecurity-magazineinfosecurity-magazine

  • The DoD will stand up a 'CMMC Reform Task Force' to conduct a 60-day, top-to-bottom review of the program infosecurity-magazine

  • During the interim, the DoD will enforce compliance via NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments infosecurity-magazine


8 Views

Johnson Controls says ransomware attack cost $27 million, data stolen



Who: Johnson Controls International, a multinational conglomerate specializing in industrial control systems and security equipment, fell victim to a ransomware attack by the Dark Angels ransomware gang in September 2023.


What: The cyberattack involved unauthorized access, data exfiltration, and ransomware deployment, leading to a data breach. The Dark Angels gang claimed to have stolen over 27 TB of confidential data and demanded a $51 million ransom.


How: The attack originated from the firm's Asia offices, spreading throughout the network and forcing a shutdown of IT infrastructure, impacting customer-facing systems. Johnson Controls confirmed expenses of $27 million for responding to and remediating the cyberattack. Despite the breach, the company believes unauthorized activity is contained, and digital products and services are available. Ongoing assessments may result in increased costs as data is analyzed with external cybersecurity experts.


Dark Angels ransom note in Johnson Controls cyberattack


37 Views

High-Severity Flaws Uncovered in Bosch Thermostats and Smart Nutrunners



High-severity flaws in Bosch BCC100 thermostats and Rexroth NXA015S-36V-B smart nutrunners expose potential code execution. Bosch addressed the BCC100 vulnerability (CVE-2023-49722) in November 2023, closing an open port used for unauthorized connections.


Rexroth faces over two dozen flaws allowing attackers to disrupt operations, tamper with configurations, or install ransomware. Patches expected by January 2024; users advised to limit network reachability.

Read the full article HERE

33 Views
Jake Geier
Jake Geier

Marine industry giant Brunswick Corporation lost $85 million in cyberattack, CEO confirms



A cybersecurity incident will cost the Brunswick Corporation as much as $85 million, the company’s CEO told investors last week.


The billion-dollar boating manufacturing firm announced a cyberattack on June 13 that impacted their systems and some of their facilities. The company brought in nearly $6 billion in revenue in 2021 and operates in 24 countries.


Brunswick officials did not confirm that the incident was a ransomware attack but said they were forced to stop operations in some locations while experts and law enforcement dealt with the incident.


During the company’s earnings call last week, CEO Dave Foulkes told investors and board members that the attack had a devastating effect on the company’s Q2 financial outlook.


Foulkes explained that the “IT security incident” caused “second quarter financial results that were lower than initial expectations.” After announcing the incident, it took the company nine days to get back up and running…


32 Views
bottom of page