The Cybersecurity and Infrastructure Security Agency (CISA) is urging U.S. organizations to strengthen their cyber defenses against data-wiping attacks that have recently targeted Ukrainian government agencies and businesses.

See also: CISA: Apache Log4j scanner released to detect vulnerable apps
As reported by BleepingComputer, Ukrainian government agencies and corporate entities suffered coordinated cyberattacks last Friday, where websites were defaced and data-wiping malware was deployed to destroy data and render Windows devices inoperable.
Sources told cybersecurity journalist Kim Zetter that the attackers likely carried out the website defacement using the CVE-2021-32648 vulnerability in the OctoberCMS platform. Ukrainian police say they are investigating the use of Log4j vulnerabilities and stolen credentials as another way to access networks and servers.
CNN also reports that the Ukrainian IT services company that helped develop many of these sites was also a victim, raising concerns of a supply chain attack.
The website defacements and data-wiping malware attacks were initially thought to be separate attacks. However, Ukraine issued a press release yesterday stating that entities were affected by both attacks, leading to the belief that they were coordinated. Ukraine blames Russia for these attacks.
See also: CISA & White House on cyberattacks: Be on alert ahead of Christmas

CISA urges US organizations to defend against similar attacks
CISA is now urging U.S. business leaders and organizations to take the following steps to prevent similar devastating attacks on their networks.
While CISA's recommendations are in response to recent cyberattacks in Ukraine, the following suggested steps are good advice for preventing any network intrusion, including those leading to ransomware.
Reduce the chance of a harmful cyber intrusion:
- Confirm that all remote access to the organization's network and privileged or administrative access requires multi-factor authentication.
- Ensure software is up to date, prioritizing updates that address known exploitable vulnerabilities identified by CISA.
- Confirm that the organization's IT staff has disabled all ports and protocols that are not necessary for business purposes.
- If the organization uses cloud services, ensure that IT staff has reviewed and implemented robust controls outlined in CISA guidance.
- Sign up for CISA's free cyber hygiene services, including vulnerability scanning, to help reduce your exposure to threats.
See also: CISA: Fix the BrakTooth bugs – Exploits have also been released
Take steps to quickly detect a potential intrusion:
- Ensure that cybersecurity personnel are focused on identifying and quickly assessing any unexpected or unusual network behavior. Enable logging to better investigate issues or incidents.
- Confirm that the entire organization's network is protected by antivirus/antimalware software and that the signatures in these tools are up to date.
- If you work with Ukrainian organizations, make sure to monitor, inspect, and isolate traffic from these organizations.
- Designate a cyber crisis response team.
- Run a drill to ensure all participants understand their roles during an incident.
Maximize the organization's resilience to a catastrophic cyber incident:
- Test your backup processes to ensure that critical data can be quickly restored if the organization is affected by ransomware or a catastrophic cyberattack. Also, make sure that backups are isolated from network connections.
- If you use industrial control systems or operational technology, conduct a test of manual controls to ensure that critical functions remain operational if the organization's network is unavailable or insecure.
CISA recommends that cybersecurity and IT personnel also read their recent bulletin on mitigating Russian state-sponsored cyber threats to U.S. critical infrastructure.
Information source: bleepingcomputer.com
