Bill would create bug bounty program inside DHS

A bipartisan group of senators have introduced a bill that would create a bug bounty program inside the Department of Homeland Security. Sens. Maggie Hassan, D-N.H., and Rob Portman, R-Ohio, introduced the Hack Department of Homeland Security Act, which would establish a bug bounty pilot program similar to ones in use at the Department of Defense and major tech companies around the world. “Federal agencies like DHS are under assault every day from cyberattacks.  These attacks threaten the safety, security and privacy of millions of Americans and in order to protect DHS and the American people from these threats, the Department will need help,” Hassan said in a statement. Bug bounty programs have started to catch on inside the government, buoyed by the Hack the Pentagon program that saw DOD issue $71,200 in bounties to hackers who found vulnerabilities are certain agency websites and systems. Since then, various military branches have created their own […]

The post Bill would create bug bounty program inside DHS appeared first on Cyberscoop.

Continue reading Bill would create bug bounty program inside DHS

NASA cybersecurity chief to leave agency

Jeanette Hanna-Ruiz will be leaving her position as NASA’s chief information security officer, CyberScoop has learned. Hanna-Ruiz’s departure comes nearly nine months after she took the position. A spokesperson for the space agency confirmed Hanna-Ruiz’s departure, with April 28 as her last day. Mike Witt, a former deputy director of US-CERT, will serve as acting CISO. Hanna-Ruiz helped write the Cyberspace Policy Review that outlined the country’s cyber strategy when President Barack Obama took office in 2009. She also worked at the Department of Homeland Security-National Security Agency Joint Cyber Coordination Group, and helped develop DHS’s cyber missions and capabilities. In 2012, Hanna-Ruiz joined Microsoft, where she served as a senior leader in services businesses and was the public sector civilian lead for cybersecurity. Last month, Hanna-Ruiz was named as one of CyberScoop’s top women in cybersecurity. Her departure was first reported by Federal News Radio.

The post NASA cybersecurity chief to leave agency appeared first on Cyberscoop.

Continue reading NASA cybersecurity chief to leave agency

Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits

The Shadow Brokers, the mysterious group linked to exploits stolen from the National Security Agency, have released a large catalog of files Saturday that give further insight into the elite spy agency’s hacking methods. In a lengthy blog post on Medium, the group reveals a password that unlocks an encrypted folder full of files the group previously tried to sell in an online auction. The group says their motive for unlocking the files is disappointment with President Donald Trump since he assumed office, including missile strikes on a Syrian air base carried out earlier this week. “TheShadowBrokers doesn’t want this to be happening to you, Mr. Trump,” the group wrote in the rambling, grammatically poor post. “TheShadowBrokers is wanting to see you succeed. TheShadowBrokers is wanting America to be great again. TheShadowBrokers acknowledging, we don’t be having all the inside information you do, things might look different inside the bubble. […]

The post Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits appeared first on Cyberscoop.

Continue reading Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits

McAfee pushes government to craft improved cybersecurity game plans

In the face of malware’s growth in both category and character, government experts joined private sector leaders Thursday to formulate better ways to tackle cybersecurity challenges. During McAfee’s 2017 Security Through Innovation Summit, both sides of the public and private sector relationship talked about changes needed at every aspect of the security ecosystem, from better information sharing to more automation to a total revamp of the government acquisition process. “We as an industry have been tackling this cybersecurity problem in the fundamentally wrong way,” said Brian Dye, McAfee’s executive vice president of products, at the event hosted by CyberScoop and FedScoop. Automation was a continuing theme Thursday, promoted not only as a way to address cybersecurity workforce shortages but also improve the consistency and reliability of network defenses. A panel of government speakers drew a distinction between tasks that could be made “automatic” — where no input was required — and […]

The post McAfee pushes government to craft improved cybersecurity game plans appeared first on Cyberscoop.

Continue reading McAfee pushes government to craft improved cybersecurity game plans

Russian bank threatens researcher with CFAA suit over DNS request data

A Russian bank under investigation for possible ties to the Trump Organization has threatened at least one security researcher with a lawsuit over the dissemination of data that point to a server connection between the bank and the company.   In a document obtained by CyberScoop, Alfa Bank sent Indiana University computer researcher L. Jean Camp a notice that it’s pursuing “all available options” after Camp’s research suggested the bank engaged in some form of communication with the Trump Organization. Washington-based law firm Kirkland & Ellis sent the letter on the bank’s behalf on March 17. Among the options listed is litigation under the Computer Fraud and Abuse Act’s civil action provision, which allows companies to sue for damages in the event of unauthorized computer access. Foreign entities can bring cases to U.S. federal courts under a CFAA provision that allows private causes of action. Camp’s research has pointed to Alfa Bank’s servers making […]

The post Russian bank threatens researcher with CFAA suit over DNS request data appeared first on Cyberscoop.

Continue reading Russian bank threatens researcher with CFAA suit over DNS request data

Russian bank threatens researcher with CFAA suit over DNS request data

A Russian bank under investigation for possible ties to the Trump Organization has threatened at least one security researcher with a lawsuit over the dissemination of data that point to a server connection between the bank and the company.   In a document obtained by CyberScoop, Alfa Bank sent Indiana University computer researcher L. Jean Camp a notice that it’s pursuing “all available options” after Camp’s research suggested the bank engaged in some form of communication with the Trump Organization. Washington-based law firm Kirkland & Ellis sent the letter on the bank’s behalf on March 17. Among the options listed is litigation under the Computer Fraud and Abuse Act’s civil action provision, which allows companies to sue for damages in the event of unauthorized computer access. Foreign entities can bring cases to U.S. federal courts under a CFAA provision that allows private causes of action. Camp’s research has pointed to Alfa Bank’s servers making […]

The post Russian bank threatens researcher with CFAA suit over DNS request data appeared first on Cyberscoop.

Continue reading Russian bank threatens researcher with CFAA suit over DNS request data

CyberScoop’s 2017 Top Women in Cybersecurity

  If you’ve been to any type of tech conference, you may have heard someone use the phrase “people, process and technology.” We’ve been told time and time again that if people solely rely on technology to protect their digital assets, the status quo of mega-breaches and wide-scale attacks will only continue. Yet while the security community rushes to give the world the latest and greatest tech tool to upend the onslaught of attacks, the status quo continues unabated on the people side: Cybersecurity is still overwhelmingly dominated by men. According to the 2017 Global Information Security Workforce Study, women make up just 11 percent of the global cybersecurity workforce and earn less than their male counterparts at every level of the industry. In honor of Women’s History Month, we present our inaugural Top Women in Cybersecurity list, filled with individuals who are upending the status quo. This list contains […]

The post CyberScoop’s 2017 Top Women in Cybersecurity appeared first on Cyberscoop.

Continue reading CyberScoop’s 2017 Top Women in Cybersecurity

Top Women in Cybersecurity: Niloofar Howe

Niloofar Howe, Chief Strategy Officer, RSA Niloofar Howe has a lot to balance as the cybersecurity landscape shifts. As Chief Strategy Officer for RSA, she’s responsible for the health and direction of the business, as well as figuring out a way large incumbent companies like RSA can work with a broad set of companies to deliver on the changing needs of her customers. Howe has learned how to hone in on strategies by working alongside former government leaders, including former NSA Director Lt. General Ken Minihan during her time at Paladin Capital Group. Now, she’s busy ensuring RSA is well positioned to deliver globally . Can you talk about the biggest challenge you’ve faced in your career? How did you conquer that challenge? There isn’t one good answer to this question because professional challenges change as you progress in your career. As I progressed and earned a seat at the […]

The post Top Women in Cybersecurity: Niloofar Howe appeared first on Cyberscoop.

Continue reading Top Women in Cybersecurity: Niloofar Howe

Top Women in Cybersecurity: Amelie Koran

Amelie Koran, ‎U.S. Department of Health and Human Services, Office of the Inspector General Societal biases are not always apparent to those who aren’t exposed to them on a daily basis. Amelie Koran has had experience dealing with these biases from multiple angles. As one of the first transgendered advocates inside the White House, she’s been working past those biases as much as she’s been working to set out the IT strategy for various segments of the federal government. Now at HHS, she works to modernize the agency’s infrastructure, implement best practices, and push the security community to navigate through their own biases.  Can you talk about the biggest challenge you’ve faced in your career? How did you conquer that challenge? For me, I’m transgendered. So I managed to go so far in my career, and transitioned, and was told by a number of people that doing so would be a career ender. […]

The post Top Women in Cybersecurity: Amelie Koran appeared first on Cyberscoop.

Continue reading Top Women in Cybersecurity: Amelie Koran

Top Women in Cybersecurity: Ann Barron-DiCamillo

Ann Barron-DiCamillo, Vice President, Cyber Threat Intelligence & Incident Response, American Express Having spent time in both the public and private sector, Ann Barron-DiCamillo has a unique outlook on the way the greater cybersecurity community should work together. Currently serving as the Vice President of Cyber Threat Intelligence and Incident Response at American Express, she is busy finding the “low hanging fruit” in which the company can improve its cybersecurity posture as well as introducing new ways for analysts to automatic security processes. By getting rid of the easy stuff and making the harder stuff simple, she is allowing that fosters innovation allows for agility in addressing the fluidity in the cyber landscape. It’s something she learned during her time in government as director of the U.S. Computer Emergency Readiness team. Can you talk about the biggest challenge you’ve faced in your career?  I think the biggest challenge I’ve faced is something […]

The post Top Women in Cybersecurity: Ann Barron-DiCamillo appeared first on Cyberscoop.

Continue reading Top Women in Cybersecurity: Ann Barron-DiCamillo