FBI’s election-meddling task force loses key official

An FBI official who co-led a taskforce to prevent foreign meddling in U.S. elections quietly left for the private sector last month. The departure of Jeffrey Tricoli, a roughly two-decade veteran of the FBI, comes as the bureau works to track misinformation online just months before the midterm elections. Tricoli has joined Charles Schwab as a senior vice president for business and cyber resiliency, the brokerage company confirmed to CyberScoop. An FBI spokesperson did not respond to a request for comment. The Wall Street Journal was first to report Tricoli’s move to Charles Schwab. FBI Director Christopher Wray announced the creation of the foreign-influence task force late last year. In January, Tricoli laid out his goals for the quietly-held initiative, whose charge is to warn U.S. companies about efforts to sow misinformation online. “Our responsibility in the government is to bring forth that visibility and that transparency to” such foreign […]

The post FBI’s election-meddling task force loses key official appeared first on Cyberscoop.

Continue reading FBI’s election-meddling task force loses key official

Senators call for DOJ investigation of Fancy Bear’s ‘CyberCaliphate’ ruse

A bipartisan pair of senators is calling on the Department of Justice to investigate the alleged harassment of U.S. military families by Russian government hackers posing as Islamic State sympathizers. “We urge you to investigate this potential false flag operation and to hold any perpetrators accountable,” Sens. Cory Gardner, R-Colo., and Ron Wyden, D-Ore., wrote in a July 9 letter to Attorney General Jeff Sessions. The senators’ call for inquiry builds on evidence that Russian military hackers have masqueraded as Islamic State extremists to harass U.S. military family members. A group calling itself the CyberCaliphate sent death threats to the wives of U.S. military personnel in 2015. However, activity from the CyberCaliphate coincided with attempts by the Russian hacking group, known as APT28 or Fancy Bear, to breach the women’s email accounts, the Associated Press reported in May. The same Russian hacking group is accused of meddling in the 2016 presidential […]

The post Senators call for DOJ investigation of Fancy Bear’s ‘CyberCaliphate’ ruse appeared first on Cyberscoop.

Continue reading Senators call for DOJ investigation of Fancy Bear’s ‘CyberCaliphate’ ruse

Electric utilities use red-teaming, AI to prepare for advanced threats

The U.S. electric industry has responded to a steady stream of cyberthreats with more rigorous red-teaming and by using artificial intelligence, utility executives said. “We’re penetrating our own system to ensure that we are moving the envelope,” said Brian Harrell, Duke Energy Corp.’s managing director of enterprise protective services. “We’re trying to find the vulnerabilities before anyone else does.” “Just yesterday I [was] having a six-hour conversation with the FBI about somebody trying to penetrate our system,” Harrell said Friday at an event at George Washington University’s (GWU) Center for Cyber and Homeland Security. “These are the kinds of things that are happening on a day in and day out basis.” Harrell told CyberScoop that Duke Energy, which has 7.6 million customers across six states, is still responding to the security incident, declining to go into detail. The episode could turn out to be insignificant, he said, but is nonetheless […]

The post Electric utilities use red-teaming, AI to prepare for advanced threats appeared first on Cyberscoop.

Continue reading Electric utilities use red-teaming, AI to prepare for advanced threats

Mysterious malware campaign targets just 13 iPhones in India

An application-warping malware campaign in India is aimed at just 13 iPhones in what researchers are calling a “highly targeted” operation. The attackers are using an open-source mobile device management (MDM) server to distribute the malware through popular apps like Telegram and WhatsApp, researchers from Talos, Cisco’s threat intelligence unit, revealed Thursday. The use of MDM, a popular enterprise tool for administering mobile apps, allows hackers to control how their malware is interacting with the target phones. “This campaign is of note since the malware goes to great lengths to replace specific mobile apps for data interception,” researchers Warren Mercer, Paul Rascagneres, and Andrew Williams wrote in a blog post. The researchers don’t know who was targeted in the campaign, who carried out the attack, or why. While the hackers apparently tried to plant a “false flag” by posing as Russian, evidence suggests they were operating in India, according to Talos. […]

The post Mysterious malware campaign targets just 13 iPhones in India appeared first on Cyberscoop.

Continue reading Mysterious malware campaign targets just 13 iPhones in India

Senators question vulnerability disclosure process after Spectre and Meltdown stumbles

Shortcomings in the industry-led process for disclosing software and hardware bugs could rear their heads again, U.S. senators said Wednesday at a hearing on the Spectre and Meltdown chip flaws. “While these vulnerabilities seemed to have been patched reasonably well, what about the next one? And we might not know about it until it’s too late,” Florida Democrat Bill Nelson said at the Commerce, Science and Transportation Committee hearing. Lawmakers are pondering what can be done to improve the complex vulnerabilities disclosure process, which involves spreading enough word among vendors to address a bug but not so much as to risk leaking information before patches are ready. “We need to consider additional ways to require the federal government’s equipment suppliers to promptly notify [the Department of Homeland Security] of potential breaches or vulnerabilities that could weaken our federal systems,” Sen. Maggie Hassan, D-N.H., said at the hearing. The worry is always that foreign governments […]

The post Senators question vulnerability disclosure process after Spectre and Meltdown stumbles appeared first on Cyberscoop.

Continue reading Senators question vulnerability disclosure process after Spectre and Meltdown stumbles

DOJ regrets the error on OPM-linked fraud case

The Department of Justice has apologized for confusion over its announcement last month that a fraudster used information stolen in the infamous 2015 Office of Personnel Management breach — an episode that confounded lawmakers and ran counter to publicly available information on the breach. The confusion began after DOJ announced on June 18 that a Maryland woman had pleaded guilty to using stolen OPM data to get car and personal loans. The public assumption had been – and still is – that Chinese hackers had stolen the data for espionage purposes. But DOJ now says that it hasn’t yet determined whether the woman and her accomplice got the data from the OPM breach or somewhere else. After an internal review, the U.S. Attorney’s Office for the Eastern District of Virginia appended a statement to its press release saying that “numerous victims” of the fraud self-identified as victims of the OPM breach. “The government […]

The post DOJ regrets the error on OPM-linked fraud case appeared first on Cyberscoop.

Continue reading DOJ regrets the error on OPM-linked fraud case

Top State Department cyber official ‘optimistic’ of deal with Russia, China

The State Department’s top cybersecurity official says he is “optimistic” the United States can strike a deal on norms for government behavior in cyberspace with China and Russia, two of Washington’s biggest adversaries in the domain. Despite myriad grievances with the Russian and Chinese governments over their hacking operations, Robert Strayer said there is ample precedent for a new agreement involving the three cyber powers. “I think that it is possible because we have had three successful processes at the [United Nations] that have established that international law applies to cyberspace just like it does in the real world,” Strayer, a deputy assistant secretary of State, said in an interview. “All of those successful, consensus-based documents required that the U.S., China, and Russia came to agreement on the terms.” Despite that history, the latest round of talks at the UN forum, known as the Group of Governmental Experts, collapsed in […]

The post Top State Department cyber official ‘optimistic’ of deal with Russia, China appeared first on Cyberscoop.

Continue reading Top State Department cyber official ‘optimistic’ of deal with Russia, China

Trump taps DOE veteran to head Homeland Security research arm

President Donald Trump plans to nominate William Bryan to be undersecretary for science and technology at the Department of Homeland Security – the top tech adviser to Secretary Kirstjen Nielsen. The position oversees DHS’s Science and Technology Directorate, the department’s research arm, which invests in key cybersecurity technologies to usher them to market. One example of that came Thursday when S&T announced that an upgraded mobile-security product it funded to combat phishing is available to government and commercial users. The White House announced Bryan’s nomination Thursday. Bryan has filled the undersecretary role on an acting basis for the last year. One of his first public acts in the position was to explain how the directorate would cope with the Trump administration’s proposed steep cuts to its budget. Bryan has a strong background in critical infrastructure, having focused on the issue as deputy assistant secretary of Energy and as a top […]

The post Trump taps DOE veteran to head Homeland Security research arm appeared first on Cyberscoop.

Continue reading Trump taps DOE veteran to head Homeland Security research arm

DHS touts tech it funded to block mobile phishing

A Department of Homeland Security-funded product designed to better protect mobile-phone users from phishing is becoming available to government and private-sector clients, the department said Thursday. DHS’s Science and Technology Directorate, which partially funded the tools made by mobile security company Lookout, hailed the product’s ability to block phishing attempts and detect malware lurking in mobile applications.  The beefed-up product, Lookout Mobile Endpoint Security, is now available for Android and iOS operating systems, the department said. Phishing offers hackers a cheap and easy foothold into a network by exploiting people’s trust in the internet. The rate at which victims are falling for phishing attacks on mobile devices has grown an average of 85 percent annually since 2011, according to a study by Lookout, which is based in San Francisco. DHS is trying to lessen the threat to mobile users, including those in government, by investing in Lookout’s technology, which the department said inspects all outbound network […]

The post DHS touts tech it funded to block mobile phishing appeared first on Cyberscoop.

Continue reading DHS touts tech it funded to block mobile phishing

4G is vulnerable to same types of attacks as 3G, researchers say

The 4G wireless telecommunications protocol is vulnerable to the same types of remote exploitation as its 3G predecessor, new research emphasizes. As with the flaw-ridden protocol underlying 3G, the 4G protocol is susceptible to attacks that disclose mobile users’ information or impose a denial of service, according to a report from mobile-security company Positive Technologies. Security researchers have long warned that spies or hackers could exploit the protocol supporting 3G — known as Signaling System No. 7 (SS7) — to intercept or track call data. The move from 3G to 4G, and the latter’s Diameter protocol, was supposed to mitigate some vulnerabilities, but security experts also have made clear that Diameter is no safeguard against hacking. While the new research indicates 4G is vulnerable to a smaller scope of attacks than 3G, it shows that attackers could shift a user’s device to 3G mode to exploit the less-secure SS7. Further, most mobile […]

The post 4G is vulnerable to same types of attacks as 3G, researchers say appeared first on Cyberscoop.

Continue reading 4G is vulnerable to same types of attacks as 3G, researchers say