White House unveils process behind disclosing software vulnerabilities

The White House has released a charter that will give more clarity and bring more transparency to the vulnerabilities equities process, the course by which the U.S. government determines to either withhold or disclose information to tech companies about flaws in their software. The charter lays out the core considerations taken into account by the U.S. government when a vulnerability is in its possession, weighing “the benefit to national security and the national interest when deciding whether to disclose or restrict knowledge of a vulnerability.” “Vulnerability management requires sophisticated engagement to ensure protection of our people, the safeguarding of critical infrastructure, and the defense of important commercial and national security interests,” reads the charter, which was released Wednesday. “The new VEP Charter balances those interests in a way that is repeatable and defensible, and its publication will bolster the confidence of the American people as we continue to carry out […]

The post White House unveils process behind disclosing software vulnerabilities appeared first on Cyberscoop.

Continue reading White House unveils process behind disclosing software vulnerabilities

Rep. Connolly: National data breach notification law could be coming

A cybersecurity-focused lawmaker says Congress may have to consider national data-breach notification legislation if companies don’t do a better job of alerting people when they’ve suffered a breach. Rep. Gerry Connolly, D-Va., said he hopes for a national standard to evolve among the private sector, but massive breaches like that at credit monitoring firm Equifax may force Congress’s hand. Congress doesn’t “want to upset the technology community with obtrusive regulation,” but the private sector has been poor in instilling confidence that it will act in the public’s best interest, he said. “I think its headed that way absent some fresh look by industry, a benchmark standard that everybody’s accepted voluntarily to meet, so that federal regulation is unnecessary,” Connolly told CyberScoop Thursday during Dell Technologies’ Digital Transformation Summit. ”I think Equifax is a great test of whether industry is capable of meeting that test.” Equifax has come under great scrutiny for […]

The post Rep. Connolly: National data breach notification law could be coming appeared first on Cyberscoop.

Continue reading Rep. Connolly: National data breach notification law could be coming

A chaotic first year in the cybersecurity community

On our launch date one year ago today, I wrote the following: “…as we’ve seen from the halls of federal agencies to C-suite boardrooms to the smartphones in our pocket, cybersecurity is often neglected, misunderstood or outright ignored.” These were the stories that followed over the following 48 hours: Medical device maker Johnson & Johnson notified patients of a cybersecurity vulnerability in one of the company’s popular insulin pumps, finding that the device could be exploited to cause insulin overdoses in diabetic patients.  Yahoo allowed U.S. intelligence agencies to search emails sent to its customers via a special program built in secret by company engineers. A Booz Allen Hamilton contractor was arrested, with the FBI conducting the arrest on suspicion of the contractor stealing hacking tools used by the NSA to break into foreign governments’ computer networks. Those stories set a tone and showed my words were a complete understatement. From Mirai to […]

The post A chaotic first year in the cybersecurity community appeared first on Cyberscoop.

Continue reading A chaotic first year in the cybersecurity community

A chaotic first year in the cybersecurity community

On our launch date one year ago today, I wrote the following: “…as we’ve seen from the halls of federal agencies to C-suite boardrooms to the smartphones in our pocket, cybersecurity is often neglected, misunderstood or outright ignored.” These were the stories that followed over the following 48 hours: Medical device maker Johnson & Johnson notified patients of a cybersecurity vulnerability in one of the company’s popular insulin pumps, finding that the device could be exploited to cause insulin overdoses in diabetic patients.  Yahoo allowed U.S. intelligence agencies to search emails sent to its customers via a special program built in secret by company engineers. A Booz Allen Hamilton contractor was arrested, with the FBI conducting the arrest on suspicion of the contractor stealing hacking tools used by the NSA to break into foreign governments’ computer networks. Those stories set a tone and showed my words were a complete understatement. From Mirai to […]

The post A chaotic first year in the cybersecurity community appeared first on Cyberscoop.

Continue reading A chaotic first year in the cybersecurity community

Equifax CEO retires after mega breach

Equifax CEO Richard Smith will be stepping down from his position as chairman of the board and chief executive officer, the company announced Thursday. The change comes three weeks after the credit monitoring company revealed a data breach affecting up to 143 million U.S. residents. Data on names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers were stolen from the company’s databases. “Serving as CEO of Equifax has been an honor, and I’m indebted to the 10,000 Equifax employees who have dedicated their lives to making this a better company,” Smith said in a release.  “The cybersecurity incident has affected millions of consumers, and I have been completely dedicated to making this right.  At this critical juncture, I believe it is in the best interests of the company to have new leadership to move the company forward.” Current Equifax board member Mark Feidler will serve […]

The post Equifax CEO retires after mega breach appeared first on Cyberscoop.

Continue reading Equifax CEO retires after mega breach

Multiple class-action lawsuits filed in wake of Equifax breach

Two class-action lawsuits have been filed against Equifax after the company divulged a data breach potentially affecting 143 million U.S. consumers. Not even 24 hours after the Georgia-based credit reporting company announced the incident, lawsuits were filed in federal courts in Georgia and Oregon. In the case filed in Oregon on Thursday evening, plaintiffs say Equifax “negligently failed to maintain adequate technological safeguards to protect … information from unauthorized access by hackers.” “Equifax knew and should have known that failure to maintain adequate technological safeguards would eventually result in a massive data breach,” the lawsuit reads. “Equifax could have and should have substantially increased the amount of money it spent to protect against cyber-attacks but chose not to.” In the case filed in the Northern District of Georgia, lawyers for a separate group level similar accusations. “Equifax disregarded the rights of Plaintiffs and Class members by intentionally, willfully, recklessly, or negligently […]

The post Multiple class-action lawsuits filed in wake of Equifax breach appeared first on Cyberscoop.

Continue reading Multiple class-action lawsuits filed in wake of Equifax breach

Sqrrl adds $12.3 million to coffers in Series C funding round

Buoyed by the growth surrounding cyberthreat hunting, Cambridge, Massachusetts-based Sqrrl announced a $12.3 million Series C round of investment on Wednesday. The funding was led by Boston-based Spring Lake Equity Partners, with existing investors Matrix Partners, Rally Ventures and Accomplice also participating in the round. The new round comes as popularity in threat hunting platforms continues to grow. Various analyst groups have emphasized the platforms as a good way for security operations centers to proactively detect threats. According a SANS Institute paper released earlier this year, 88 percent of respondents found threat hunting to considerably reduce the amount of time malicious actors patrolled enterprise networks. “We are giving the tools to the analyst to rapidly understand what is happening in their environment and ask questions based on what they see in front of them,” Sqrrl CEO Mark Terenzoni told CyberScoop. Sqrrl (pronounced “squirrel”) was created in 2012, born out of an NSA database project […]

The post Sqrrl adds $12.3 million to coffers in Series C funding round appeared first on Cyberscoop.

Continue reading Sqrrl adds $12.3 million to coffers in Series C funding round

Bill would create bug bounty program inside DHS

A bipartisan group of senators have introduced a bill that would create a bug bounty program inside the Department of Homeland Security. Sens. Maggie Hassan, D-N.H., and Rob Portman, R-Ohio, introduced the Hack Department of Homeland Security Act, which would establish a bug bounty pilot program similar to ones in use at the Department of Defense and major tech companies around the world. “Federal agencies like DHS are under assault every day from cyberattacks.  These attacks threaten the safety, security and privacy of millions of Americans and in order to protect DHS and the American people from these threats, the Department will need help,” Hassan said in a statement. Bug bounty programs have started to catch on inside the government, buoyed by the Hack the Pentagon program that saw DOD issue $71,200 in bounties to hackers who found vulnerabilities are certain agency websites and systems. Since then, various military branches have created their own […]

The post Bill would create bug bounty program inside DHS appeared first on Cyberscoop.

Continue reading Bill would create bug bounty program inside DHS

NASA cybersecurity chief to leave agency

Jeanette Hanna-Ruiz will be leaving her position as NASA’s chief information security officer, CyberScoop has learned. Hanna-Ruiz’s departure comes nearly nine months after she took the position. A spokesperson for the space agency confirmed Hanna-Ruiz’s departure, with April 28 as her last day. Mike Witt, a former deputy director of US-CERT, will serve as acting CISO. Hanna-Ruiz helped write the Cyberspace Policy Review that outlined the country’s cyber strategy when President Barack Obama took office in 2009. She also worked at the Department of Homeland Security-National Security Agency Joint Cyber Coordination Group, and helped develop DHS’s cyber missions and capabilities. In 2012, Hanna-Ruiz joined Microsoft, where she served as a senior leader in services businesses and was the public sector civilian lead for cybersecurity. Last month, Hanna-Ruiz was named as one of CyberScoop’s top women in cybersecurity. Her departure was first reported by Federal News Radio.

The post NASA cybersecurity chief to leave agency appeared first on Cyberscoop.

Continue reading NASA cybersecurity chief to leave agency

Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits

The Shadow Brokers, the mysterious group linked to exploits stolen from the National Security Agency, have released a large catalog of files Saturday that give further insight into the elite spy agency’s hacking methods. In a lengthy blog post on Medium, the group reveals a password that unlocks an encrypted folder full of files the group previously tried to sell in an online auction. The group says their motive for unlocking the files is disappointment with President Donald Trump since he assumed office, including missile strikes on a Syrian air base carried out earlier this week. “TheShadowBrokers doesn’t want this to be happening to you, Mr. Trump,” the group wrote in the rambling, grammatically poor post. “TheShadowBrokers is wanting to see you succeed. TheShadowBrokers is wanting America to be great again. TheShadowBrokers acknowledging, we don’t be having all the inside information you do, things might look different inside the bubble. […]

The post Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits appeared first on Cyberscoop.

Continue reading Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits