Krebs: NPPD must use threat intel better

The agency inside the Department of Homeland Security charged with protecting critical infrastructure needs to get better at assessing cyber risk rather than chasing threats, according to a top DHS official. “We have a threat intelligence problem…because we obsess about the threat,” Christopher Krebs said Wednesday at the Cybersecurity Leadership Forum presented by Forcepoint and produced by CyberScoop and FedScoop. “We’re running this way and that way, hunting down every little piece of threat intelligence and reacting without a lot of context.” As an example, Krebs pointed to the Illinois voter registration system that Russian hackers breached ahead of the 2016 presidential election.Even if the hackers had been able to delete voter files, Krebs said, voters would still have been able to cast their ballots by having their registration verified through other records, meaning the risk was manageable. Putting the risk, or lack thereof, of cyberthreats into context is a big task […]

The post Krebs: NPPD must use threat intel better appeared first on Cyberscoop.

Continue reading Krebs: NPPD must use threat intel better

White House taps Karen Evans as assistant Energy secretary for cybersecurity

President Donald Trump plans to nominate Karen Evans, a veteran of federal IT security, to be assistance secretary of Energy for cybersecurity, energy security and emergency response, the White House announced late Tuesday. A former top IT official at the Office of Management and Budget under President George W. Bush, Evans has also served as the Department of Energy’s chief information officer. More recently, she was an IT adviser on Trump’s transition team. Outside of government, she has been an advocate of improving the nation’s cybersecurity workforce through the U.S. Cyber Challenge. Evans would rejoin DOE at a momentous time for the department as it looks to execute a new cybersecurity strategy and boost the defenses of U.S. energy companies through an information-sharing program. Energy Secretary Rick Perry has been outspoken lately about the industry’s cybersecurity challenges. “The sustained and growing threat of cyberattacks to our energy infrastructure requires us to think […]

The post White House taps Karen Evans as assistant Energy secretary for cybersecurity appeared first on Cyberscoop.

Continue reading White House taps Karen Evans as assistant Energy secretary for cybersecurity

Election security legislation gains attention on Capitol Hill

Senators are making a renewed push to secure voting infrastructure ahead of the midterm elections through measures that would boost states’ cooperation with U.S. intelligence agencies and require the use of paper ballots. As the Senate considers an annual defense policy bill, Sen. Amy Klobuchar, D-Minn., is urging support for a bipartisan amendment that would tighten cyberthreat information sharing between states and the intelligence community. “With the new kind of [information] warfare we’re seeing,” Klobuchar said Tuesday at a Senate Judiciary Committee hearing, failing to update U.S. law would be “a very big lost opportunity.” The Secure Elections Act sponsored by Klobuchar and Sen. James Lankford, R-Okla., would task the Department of Homeland Security – which is already a hub for passing intelligence from federal to state officials – with quickly sharing election-related threats with all state election agencies. The bill also aims to speed up the security-clearance process for state […]

The post Election security legislation gains attention on Capitol Hill appeared first on Cyberscoop.

Continue reading Election security legislation gains attention on Capitol Hill

Wyden asks election commission to issue fresh cybersecurity guidance

Sen. Ron Wyden, D-Ore., has asked the Election Assistance Commission to issue updated cybersecurity guidance to states to protect their voting infrastructure ahead of the 2018 midterm elections. Congress allotted $380 million to states through a March spending bill to help secure their voting systems, a move that analysts welcomed as necessary, but insufficient to replace paperless voting machines that could fall prey to digital manipulation. “Absent guidance from the EAC, some states may opt to spend these new funds on insecure voting technology,” Wyden wrote in a letter obtained by CyberScoop. “Election security experts have worked tirelessly to understand and articulate the vulnerabilities certain types of machines can introduce into elections,” Wyden wrote, adding that new EAC guidance must incorporate those findings. The senator also wants the EAC to answer a series of questions by July 15, including whether the commission has any fulltime cybersecurity experts on staff and if it […]

The post Wyden asks election commission to issue fresh cybersecurity guidance appeared first on Cyberscoop.

Continue reading Wyden asks election commission to issue fresh cybersecurity guidance

FBI announces arrest of 74 email fraudsters on three continents

The FBI on Monday announced the arrest of 74 people across three continents for hijacking bank transfers using email fraud. The “cyber-enabled financial fraud” allegedly carried out by those apprehended could involve social engineering and computer intrusions to dupe company executives into wiring money, the FBI said. A criminal could use an executive’s compromised email to facilitate a transfer or request W-2 information from within the organization, for example. The scam is essentially a more sophisticated version of the “Nigerian prince” emails that pester the average email user for money. Twenty-nine of the suspects were arrested in Nigeria, 42 in the United States, and the rest in Canada, Mauritius, and Poland. Several of the cases involved global criminal groups that defrauded companies big and small, according to the FBI. The departments of Homeland Security and Treasury, along with the U.S. Postal Inspection Service, were also in on “Operation WireWire” to take down […]

The post FBI announces arrest of 74 email fraudsters on three continents appeared first on Cyberscoop.

Continue reading FBI announces arrest of 74 email fraudsters on three continents

DHS cyber specialist: look for behavior patterns with APTs

To better track advanced hacking groups, U.S.-based companies should watch for signals in human behavior instead of changing tactics, according to Casey Kahsen, an IT specialist at the Department of Homeland Security. From one campaign to another, there are “a lot of similarities” in the behavior of a Russian government hacking group that has targeted U.S. energy companies, Kahsen said Friday at a cybersecurity event on Capitol Hill. “Some things have changed, but the behavior element remains largely the same because that’s expensive to change,” he said. “The actors are going to change tactics; they’re going to change tools,” Kahsen explained at the event, hosted by the Lexington Institute. “We need to be looking for the things that they did that are more difficult to change – the human behavior element.” The human behavior that Kahsen referenced typically includes a group’s hours of operations or coding style, which cybersecurity experts say […]

The post DHS cyber specialist: look for behavior patterns with APTs appeared first on Cyberscoop.

Continue reading DHS cyber specialist: look for behavior patterns with APTs

Congress wants to prevent states from weakening encryption

A bipartisan group of House lawmakers has reintroduced legislation that would preempt any attempts by states to weaken encryption. The bill would bar states from compelling a tech company to “design or alter the security functions in its product or service to allow the surveillance of any user of such product or service,” according to its text. Republican Reps. Mike Bishop of Michigan and Jim Jordan of Ohio and Democratic Reps. Ted Lieu of California and Suzan DelBene of Washington are the bill’s sponsors. The bill also would keep states from prohibiting the sale of products or services with strong encryption. Lieu introduced the legislation in 2016, but it stalled during that congressional session. Law enforcement officials have said strong encryption has hampered numerous investigations by thwarting access to a suspect’s communications. However, those claims were undercut after the FBI admitted in May it had vastly overstated the number of encrypted devices […]

The post Congress wants to prevent states from weakening encryption appeared first on Cyberscoop.

Continue reading Congress wants to prevent states from weakening encryption

Lawmakers advance bill to codify DHS cyber center for industrial plants

The House Homeland Security Committee on Wednesday advanced legislation that would establish a Department of Homeland Security cybersecurity center as the lead agency for handling threats to industrial control systems, like those underpinning the energy sector. The bill would make clear that DHS’s National Cybersecurity and Communications Integration Center (NCCIC) is the hub for mitigating ICS vulnerabilities and provide the private sector with a “permanent place for assistance to address cybersecurity risk,” Rep. Don Bacon, R-N.E., who introduced the bill, said at a markup. “We know we are vulnerable…to these cyberattacks on our energy grid, and the time is now to start building that resiliency in our energy grid,” Bacon stated. With DHS and the Department of Energy both concerning themselves with ICS, “there’s some ambiguity [on] who does what” on the issue, Bacon told CyberScoop after the hearing. “The NCCIC has been doing a lot of this,” he explained. […]

The post Lawmakers advance bill to codify DHS cyber center for industrial plants appeared first on Cyberscoop.

Continue reading Lawmakers advance bill to codify DHS cyber center for industrial plants

House panel rejects call for cyberthreat report on ZTE amid Trump deal

On the heels of a reported U.S. deal with embattled Chinese telecom company ZTE, American lawmakers rejected a Democratic measure that would have directed the Department of Homeland Security to provide more information on any cybersecurity risks posed by the international tech company. The top Republican and Democrat on the House Homeland Security Committee sparred over the utility of the resolution, which would have tasked DHS with providing any documentation it has on cyber risks introduced by the use of ZTE products on federal, state and local government networks. The Republican-led panel voted 16-11 against the measure. Instead, lawmakers will get a classified briefing from officials at DHS, the FBI and the Defense Department on June 13 about the  national security risks posed by ZTE and Huawei, another Chinese technology giant. Texas Republican Michael McCaul, the committee’s chairman, announced the briefing at a committee markup Wednesday on Capitol Hill. U.S. […]

The post House panel rejects call for cyberthreat report on ZTE amid Trump deal appeared first on Cyberscoop.

Continue reading House panel rejects call for cyberthreat report on ZTE amid Trump deal

Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say

A new widespread vulnerability that lets an attacker execute remote commands affects web development tools offered by Amazon Web Services, HP, and other companies, according to secure-coding startup Snyk. The so-called “Zip Slip” vulnerability, which is particularly prevalent in JavaScript, “affects thousands of projects” supported by those internet giants plus other companies, Snyk co-founder Danny Grander said in an advisory. “[T]his type of vulnerability has existed before, but recently it has manifested itself in a much larger number of projects and libraries,” Grander wrote. The vulnerability allows an attacker to “gain access to parts of the file system outside of the target folder in which they should reside,” according to Snyk, potentially letting the adversary overwrite configuration files. To do that, an attacker needs both a “a malicious archive and extraction code that does not perform validation checking,” the firm said. Snyk said that it began privately disclosing the vulnerability to […]

The post Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say appeared first on Cyberscoop.

Continue reading Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say