Top

Category: Cybersecurity


Cybersecurity

How US SEC legal actions put CISOs at risk and what to do about it

November 16, 2023

Via: CSO Online

With the US Securities and Exchange Commission (SEC) having taken legal action against CISOs at both SolarWinds and Uber, security executives feel the pressure to be absolutely precise when writing up security incidents that the company has decided are material. […]


Cybersecurity, IT Policy, Tech

A key US spy tool will lapse at year’s end unless Congress and the White House can cut a deal

November 15, 2023

Via: Washington's Top News

With just seven weeks until the end of the year, the Biden administration is running out of time to win the reauthorization of a spy program it says is vital to preventing terrorism, catching spies and disrupting cyberattacks. The tool, […]


Cybersecurity

State of Maine Becomes Latest MOVEit Victim to Surface

November 10, 2023

Via: Dark Reading

In an online overview published on Nov. 9, the government of Maine confirmed that a group of cybercriminals exploiting the now-infamous vulnerability in the MOVEit file-transfer tool to allow them access to files belonging to the State of Maine between […]


Cybersecurity

US launches “Shields Ready” campaign to secure critical infrastructure

November 8, 2023

Via: CSO Online

The US Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Emergency Management Agency (FEMA) have announced the launch of the “Shields Ready” campaign to promote critical national infrastructure (CNI) security and resilience. Shields […]


Cybersecurity

Pro-Russia hackers target inboxes with 0-day in webmail app used by millions

October 26, 2023

Via: ArsTechnica

A relentless team of pro-Russia hackers has been exploiting a zero-day vulnerability in widely used webmail software in attacks targeting governmental entities and a think tank, all in Europe, researchers from security firm ESET said on Wednesday. The previously unknown […]


Cybersecurity

Beijing-backed green energy firm is expanding in US, posing serious national security risk: report

October 24, 2023

Via: Fox News

The Chinese government is leveraging green energy companies in an effort to create technological dependencies and “achieve strategic, political, and intelligence advantages” over the U.S., according to a sprawling new report. The report — published Monday by the Foundation for […]


Cybersecurity

How the US DOD Cyber Strategy changes national cyber defense

October 19, 2023

Via: CSO Online

A decade ago, then-Secretary of Defense Leon Panetta uttered a phrase that would go on to live in infamy: “cyber Pearl Harbor.” Panetta was using his platform as the country’s leading national security official to warn of dire future digital […]


Cybersecurity

Israel-Hamas conflict extends to cyberspace

October 11, 2023

Via: CSO Online

Amid the ongoing conflict between Israel and Hamas, a new battleground has opened up in cyberspace, with hackers from both sides trying to attack each other’s infrastructure, while also dragging supporters of each other into the conflict. “Analysts have noted […]


Cybersecurity

New CISA, NSA guidance highlights pain points in identity and security management

October 6, 2023

Via: Government Executive

Federal agencies and the private sector still face significant challenges in adopting and implementing critical security controls like multifactor authentication and single sign-on services, according to new guidance from the Cybersecurity and Infrastructure Security Agency and the National Security Agency. […]


Cybersecurity

Cybersecurity experts raise concerns over EU Cyber Resilience Act’s vulnerability disclosure requirements

October 3, 2023

Via: CSO Online

Dozens of global cybersecurity experts have raised concerns about the proposed vulnerability disclosure requirements of the EU’s Cyber Resilience Act (CRA). An open letter signed by representatives from a wide range of organizations including Google, the Electronic Frontier Foundation, the […]


Cybersecurity

What happens to government devices during a shutdown?

September 29, 2023

Via: Government Executive

Federal agencies are racing to release guidance for staff as a looming government shutdown threatens to furlough thousands of employees, disrupt critical services and reduce national cyber operations to skeleton crews. Federal employees are learning whether they will be considered […]


Cybersecurity

Zero Trust: Understanding the US government’s requirements for enhanced cybersecurity

September 26, 2023

Via: CIO

The concept of Zero Trust has gained significant traction in recent years, as organizations look to enhance their cybersecurity defenses and safeguard their digital assets. The US government has been at the forefront of promoting this approach, with a series […]


Cybersecurity

Chinese state actors behind espionage attacks on Southeast Asian government

September 25, 2023

Via: CSO Online

A series of attacks targeting a Southeast Asian government has been found to be carried out by distinct threat actors affiliated with Chinese interests, according to Unit 42, the Palo Alto research arm closely studying the attacks. Initially thought to […]


Cybersecurity

CISA announces free security scans for public water utilities

September 13, 2023

Via: StateScoop

The U.S. Cybersecurity and Infrastructure Security Agency is offering free security scans for critical infrastructure facilities, such as water utilities, to help protect them from cyberattacks. The midweek announcement comes as water treatment facilities across the country have suffered from […]


Cybersecurity

Fed Warning: US Space Industry Subject To Foreign Spying, Disruptions

August 21, 2023

Via: Dark Reading

Foreign adversaries are waging cyber espionage campaigns against the US space industry, according to a joint warning issued this week by the National Counterintelligence and Security Center (NCSC), FBI, and the Air Force Office of Special Investigations (AFOSI). The two-page […]


Cybersecurity

New CISA guidance looks to guard against supply chain hacks

August 16, 2023

Via: Nextgov

The Cybersecurity and Infrastructure Security Agency released its first remote monitoring and management software guidance document on Wednesday, part of the agency’s larger Joint Cyber Defense Collaborative initiative. The Remote Monitoring & Management Cyber Defense Plan specifically focuses on the […]


Cybersecurity

Lawmaker pushes AI companies for more safety and security commitments

August 16, 2023

Via: Nextgov

Sen. Mark Warner, D-Va., chair of the Senate Select Committee on Intelligence, wants artificial intelligence companies to commit to extending existing voluntary pledges to all of their systems and make more commitments to address high-risk areas like real-time facial recognition. […]


Cybersecurity

What CISA and NSA Guidance Means for Critical Infrastructure Security

August 11, 2023

Via: Dark Reading

The Cybersecurity Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently collaborated to produce an important new document, “Identity and Access Management: Recommended Best Practices for Administrators.” Part of the Enduring Security Framework (ESF), it presents a distillation […]


Cybersecurity

Report reveals ‘sudden surge’ in cyberattacks targeting government agencies

August 8, 2023

Via: Government Executive

Anew report has found that cyberattacks targeting government agencies and the public sector increased at an alarming rate in recent months, as threat actors unleashed a slate of novel malware campaigns that impacted financial institutions, healthcare services and critical infrastructure […]


Cybersecurity

Colorado higher education department reports ransomware attack

August 7, 2023

Via: StateScoop

The Colorado Department of Higher Education on Friday reported it was the victim of a data breach following a ransomware attack this past June, and that the personal information of students and teachers dating back to 2004 may have been […]