Private sector isn’t sharing data with DHS’s threat portal

For years, U.S. government officials have been trying to provide firms with actionable threat data in time for corporate officials to block hackers from compromising their networks. The 2015 Cybersecurity Information Sharing Act (CISA) gave firms legal cover to provide threat data to the government; the Department of Homeland Security rolled out an automated threat-sharing program in 2016; and Republican and Democratic administrations have preached the information-sharing gospel at conferences across the country. But today, amid consistent nation-state cyberthreats to U.S. companies, there is a growing consensus in Congress and in the private sector that these federal efforts are falling way short of expectations and needs. Two years after DHS established its Automated Indicator Sharing (AIS) program, just six non-federal organizations are using it to share threat indicators with the government, a DHS official told CyberScoop. “That’s unacceptable and it surely doesn’t reach the threshold I hoped it was going […]

The post Private sector isn’t sharing data with DHS’s threat portal appeared first on Cyberscoop.

Continue reading Private sector isn’t sharing data with DHS’s threat portal

Krebs: Companies need ‘military-grade’ investments to defend against foreign government hackers

Last year was a “seminal year” for nation-state-backed cyberattacks from American adversaries, a top Department of Homeland Security official said Wednesday, adding that companies may need U.S. government support to cope with such advanced threats. “We’ve known for years that there are primarily four nation-state actors that are most active in the cybersecurity space, but push really came to shove” in 2017, Christopher Krebs said Wednesday, referring to China, Iran, North Korea, and Russia. American companies can handle most cyberthreats through their own security investments, but a “military-grade level of investment” is needed to cope with nation-state hackers, Krebs, DHS’s top infrastructure security official, said at a conference in Washington, D.C. Experts say it is very difficult for a company of any size to cope with advanced and well-resourced hackers, but DHS is trying to make the fight less lopsided by providing companies with threat intelligence and risk assessments. Further, basic practices like […]

The post Krebs: Companies need ‘military-grade’ investments to defend against foreign government hackers appeared first on Cyberscoop.

Continue reading Krebs: Companies need ‘military-grade’ investments to defend against foreign government hackers

Senators want Commerce to help U.S. firms ditch ZTE

A bipartisan trio of senators have asked the Department of Commerce to clarify that U.S. companies are welcome to remove products from their networks made by controversial Chinese telecom company ZTE. Republican Sens. Tom Cotton, Ark., and Marco Rubio, Fla., along with Sen. Chris Van Hollen, D-Md., say they strongly support the department’s April “denial order” barring ZTE from buying U.S. technology components for seven years. However, the senators are concerned that the order is ambiguous to the point of hindering the removal of ZTE gear from U.S. infrastructure. On Monday, they wrote Secretary of Commerce Wilbur Ross asking his department to issue guidance and waivers to help U.S. companies clear their networks of ZTE software and hardware. U.S. officials have long warned that the Chinese government could leverage technology built by ZTE and fellow Chinese telecom Huawei to spy on Americans – accusations the companies deny. The Commerce Department […]

The post Senators want Commerce to help U.S. firms ditch ZTE appeared first on Cyberscoop.

Continue reading Senators want Commerce to help U.S. firms ditch ZTE

‘Tick’ espionage group is likely trying to hop air gaps, researchers say

A cyber espionage group known for attacking organizations in Japan and South Korea has targeted USB drives in a likely effort to infect “air gapped” systems, according to new research. The so-called Tick hacking group has gone after a specific type of USB drive made by an unnamed South Korean defense company, said researchers with cybersecurity company Palo Alto Networks. The newly revealed malware isn’t part of an active campaign and was likely used in attacks years ago, according to the researchers. Nonetheless, the apparent effort to infiltrate air-gapped systems speaks to the lengths to which advanced hackers will go to reach sensitive infrastructure. Whereas other malware used by Tick requires an internet connection to reach a command-and-control server, the group’s “SymonLoader” malware needs no such connectivity, according to the researchers. Instead, the malware tries to extract a hidden payload from a plugged-in USB drive – a technique that is […]

The post ‘Tick’ espionage group is likely trying to hop air gaps, researchers say appeared first on Cyberscoop.

Continue reading ‘Tick’ espionage group is likely trying to hop air gaps, researchers say

DHS chief: We’re cracking down on hackers more than Obama did

The U.S. government is trying to more effectively deter cyberattacks by imposing clear consequences on nation-state-linked hackers, Homeland Security Secretary Kirstjen Nielsen said Thursday, casting the Trump administration as tougher on the issue than the Obama administration. “This is one of those areas where deterrence has to be clear,” Nielsen said Thursday at a Capitol Hill security event. “We will no longer stand by while nation-states attack the government or our private sector entities.” “For so long, we’ve had these attacks, it’s taken us over a year to attribute it in some cases,” she said. “Then you attribute it, nothing happens.” Under both presidential administrations, the U.S. has clamped down on hackers linked with the Chinese, Russian, and Iranian governments through indictments and sanctions. In 2014, Obama’s Department of Justice brought the first U.S. charges of cyber-espionage against a nation-state with the indictment of five Chinese military officers. In March, Trump’s DOJ indicted nine Iranian […]

The post DHS chief: We’re cracking down on hackers more than Obama did appeared first on Cyberscoop.

Continue reading DHS chief: We’re cracking down on hackers more than Obama did

Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama

A new bipartisan Senate bill would try to get to the bottom of supply chain risks by setting up a new federal acquisition council that would include representation from the intelligence community and Defense Department. The goal of the bill is to help streamline coordination between agencies so that the government can avoid buying technology that’s bugged by foreign spies. The “Federal Acquisition Supply Chain Security Act” was introduced Tuesday by Sens. James Lankford, R-Okla., and Claire McCaskill, D-Mo. It tasks agencies across the government with creating a strategy to tackle supply chain threats embedded in federally procured technology systems. If a malicious piece of equipment enters the supply chain of government agencies, experts say it could be used for espionage or more destructive purposes. The announcement comes after a year in which top officials have repeatedly grappled with national security concerns surrounding Moscow-based Kaspersky Lab, an anti-virus software maker that […]

The post Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama appeared first on Cyberscoop.

Continue reading Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama

New Android malware hijacks Telegram for surveillance

A new family of malware capable of comprehensive surveillance is targeting Android devices through the encrypted messaging app Telegram, according to research from antivirus vendor ESET. The malware – which has mostly been distributed in Iran – ensnares its victims by posing as an application pledging more social media followers, bitcoin, or free Internet connections, according to ESET.  Once downloaded, the malware can carry out surveillance tasks ranging from intercepting text messages to recording audio and screen images from devices, ESET researcher Lukas Stefanko explained in a blog post. Each compromised device is controlled via a bot that the attacker commandeers via Telegram, which recently boasted 200 million monthly users. “Attackers can control victimized devices by simply tapping the buttons available in the version of the malware they are operating,” Stefanko wrote. The malware family has proliferated since at least last August, according to ESET. In March, its source code was […]

The post New Android malware hijacks Telegram for surveillance appeared first on Cyberscoop.

Continue reading New Android malware hijacks Telegram for surveillance

Capitol Hill staffers learn what really happens when there’s a data breach

In the past three years, U.S. lawmakers have struggled to nail down key details of how two of the biggest data breaches in history affected the public and private sectors. “How far back does your information database go that was compromised?” former Utah Rep. Jason Chaffetz demanded of then-Office of Personnel Management director Katherine Archuleta at a June 2015 hearing. Chaffetz berated Archuleta for failing to secure OPM’s IT systems, from which alleged Chinese hackers extracted data on 22 million current and former federal workers. “I just hope we get to the bottom of this…because this is a mess,” Rep. Ben Ray Luján, D-N.M., said in October after questioning former Equifax CEO Richard Smith on when he knew hackers had struck the credit-reporting firm. The breach compromised data on 148 million people. To try to demystify future breach-related discussions on Capitol Hill, cybersecurity firm FireEye held a quiet training session for roughly […]

The post Capitol Hill staffers learn what really happens when there’s a data breach appeared first on Cyberscoop.

Continue reading Capitol Hill staffers learn what really happens when there’s a data breach

After Trump courts Kim, U.S. issues warning on North Korean malware

Days after the historic United States-North Korea summit, the Department of Homeland Security and FBI have warned U.S. industry about a malware variant tied to North Korean government hackers. The DHS-FBI report released Thursday on the malware, dubbed Typeframe, analyzes 11 samples, including infected Windows files and a malicious Microsoft Word document. “These files have the capability to download and install malware, install proxy and remote access Trojans, connect to command and control servers to receive additional instructions, and modify the victim’s firewall to allow incoming connections,” the report states. Pyongyang’s hackers have gotten considerably more advanced in recent years, allegedly carrying out brazen attacks on banks around the world. Ahead of the high-profile meeting this week between President Donald Trump and North Korean dictator Kim Jong Un, North Korean hackers were not letting up their activity, attacking companies in Asia, Europe, and the United States. The DHS-FBI report encourages computer users to report any […]

The post After Trump courts Kim, U.S. issues warning on North Korean malware appeared first on Cyberscoop.

Continue reading After Trump courts Kim, U.S. issues warning on North Korean malware

Red-teaming by DHS ‘quietly and slowly’ uncovers agency vulnerabilities

The Department of Homeland Security has carried out quiet “red-teaming” exercises at three federal agencies, breaking into networks and telling agency officials how it was done. The goal is for officials to more quickly realize when a hacker has a foothold in their systems to keep them from exfiltrating data. “We go really quietly and slowly, just like an adversary would,” Rob Karas, the DHS official leading the red-team exercises, said Wednesday at the Cybersecurity Leadership Forum presented by Forcepoint and produced by CyberScoop and FedScoop. Karas said his team has carried out five such red-team drills at three agencies, declining to name them. The 90-day assessments begin with about two weeks of reconnaissance that might culminate in a carefully crafted spearphishing email. “We send a phishing email and it beacons back to our host in Arlington, and then we have a foothold” into the organization, said Karas, DHS’s director of national cybersecurity assessments and technical services. […]

The post Red-teaming by DHS ‘quietly and slowly’ uncovers agency vulnerabilities appeared first on Cyberscoop.

Continue reading Red-teaming by DHS ‘quietly and slowly’ uncovers agency vulnerabilities