Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say

A new widespread vulnerability that lets an attacker execute remote commands affects web development tools offered by Amazon Web Services, HP, and other companies, according to secure-coding startup Snyk. The so-called “Zip Slip” vulnerability, which is particularly prevalent in JavaScript, “affects thousands of projects” supported by those internet giants plus other companies, Snyk co-founder Danny Grander said in an advisory. “[T]his type of vulnerability has existed before, but recently it has manifested itself in a much larger number of projects and libraries,” Grander wrote. The vulnerability allows an attacker to “gain access to parts of the file system outside of the target folder in which they should reside,” according to Snyk, potentially letting the adversary overwrite configuration files. To do that, an attacker needs both a “a malicious archive and extraction code that does not perform validation checking,” the firm said. Snyk said that it began privately disclosing the vulnerability to […]

The post Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say appeared first on Cyberscoop.

Continue reading Widespread ‘Zip Slip’ vulnerability affects AWS, HP tools, researchers say

DHS official: States will probably know first if malicious cyber-activity hits primaries

The Department of Homeland Security is on standby to alert state officials about any malicious cyber-activity during Tuesday’s primary elections, but the states themselves will likely know first if something is amiss, Matthew Masterson, a senior cybersecurity adviser at DHS, told CyberScoop. With voters going to the polls in eight states, Tuesday’s primaries are a chance for DHS to test the communication protocols it has sought to ingrain in election personnel across the country. State officials, who generally have the best views of their networks, will flag potentially malicious activity for DHS, which can in turn alert other states, according to Masterson. “If we see or have information to suggest something is going on, we have the ability to immediately share it with the states,” he said in an interview. Ahead of the midterm elections, DHS has looked to “ramp up” its cyberthreat reports to state officials to get them information that […]

The post DHS official: States will probably know first if malicious cyber-activity hits primaries appeared first on Cyberscoop.

Continue reading DHS official: States will probably know first if malicious cyber-activity hits primaries

Rick Perry: U.S. must use technology prowess to defend power grid

The United States must harness its technical know-how to defend energy infrastructure from advanced hacking, Energy Secretary Rick Perry said Monday, touting his department’s investments in cybersecurity research and development. Cyberattacks have gotten easier to carry out and their sophistication, scale and frequency have increased, Perry said in a speech at a Department of Energy conference in Austin. “The sustained and growing threat of cyberattacks to our energy infrastructure requires us to think differently, to act proactively,” the former Texas governor said. That means investing in new technologies to fortify the grid against hackers whose toolkits are only expanding, according to Perry. DOE in April announced $25 million in funding for research and development to boost cybersecurity in energy delivery systems. Last September, the department awarded $50 million through its national laboratories to improve energy-sector resiliency, including about $20 million in cybersecurity projects. With the unveiling of a new cybersecurity strategy […]

The post Rick Perry: U.S. must use technology prowess to defend power grid appeared first on Cyberscoop.

Continue reading Rick Perry: U.S. must use technology prowess to defend power grid

Rick Perry: U.S. must use technology prowess to defend power grid

The United States must harness its technical know-how to defend energy infrastructure from advanced hacking, Energy Secretary Rick Perry said Monday, touting his department’s investments in cybersecurity research and development. Cyberattacks have gotten easier to carry out and their sophistication, scale and frequency have increased, Perry said in a speech at a Department of Energy conference in Austin. “The sustained and growing threat of cyberattacks to our energy infrastructure requires us to think differently, to act proactively,” the former Texas governor said. That means investing in new technologies to fortify the grid against hackers whose toolkits are only expanding, according to Perry. DOE in April announced $25 million in funding for research and development to boost cybersecurity in energy delivery systems. Last September, the department awarded $50 million through its national laboratories to improve energy-sector resiliency, including about $20 million in cybersecurity projects. With the unveiling of a new cybersecurity strategy […]

The post Rick Perry: U.S. must use technology prowess to defend power grid appeared first on Cyberscoop.

Continue reading Rick Perry: U.S. must use technology prowess to defend power grid

DHS: ‘Nefarious actors’ could be exploiting SS7 flaw

The Department of Homeland Security has received reports that “nefarious actors” may be exploiting cellular communications vulnerabilities to spy on Americans, according to Chris Krebs, a senior DHS official. Cybersecurity experts have warned that longstanding vulnerabilities in the telephony protocol known as Signaling System No. 7 (SS7) could allow spying on callers and interception of their data. Krebs revealed the possible exploitation of SS7 in a May 22 letter to Sen. Ron Wyden, D-Ore., that also said DHS had “received reports from third parties about the unauthorized use” of mobile surveillance devices. The devices in question, known as Stingrays or IMSI catchers, imitate a cell tower to capture caller location and other associated data. They have been used by U.S. law enforcement for years, but their use for foreign espionage and hacking in the U.S. has been a source of speculation. From January to November 2017, DHS deployed sensors in Washington, […]

The post DHS: ‘Nefarious actors’ could be exploiting SS7 flaw appeared first on Cyberscoop.

Continue reading DHS: ‘Nefarious actors’ could be exploiting SS7 flaw

After security testing, CFPB to resume collecting consumer data

After an “exhaustive” review of the agency’s security practices, the Consumer Financial Protection Bureau will resume collecting consumers’ personal data, acting agency director Mick Mulvaney told employees Thursday. An independent security assessment “concluded that ‘externally facing bureau systems appear to be well-secured,’” Mulvaney said. CFPB has a mandate to collect consumer data on things like credit cards and mortgages. The agency’s cybersecurity practices drew the scrutiny of lawmakers in April, when Mulvaney told the Senate Committee on Banking, Housing, and Urban Affairs that the agency had suffered roughly 240 data security breaches and 800 suspected breaches.  An CFPB spokesperson told CyberScoop the breaches of personally identifiable information happened before Mulvaney took the agency’s helm in November 2017. “When I first arrived at the bureau, I was concerned that the information the bureau collects about consumers could fall prey to hackers or other actors,” Mulvaney said in an email to agency staff […]

The post After security testing, CFPB to resume collecting consumer data appeared first on Cyberscoop.

Continue reading After security testing, CFPB to resume collecting consumer data

The latest attempt by the State Department to set behavior norms

Following lawmakers’ calls for the Trump administration to lay out a clear cyber deterrence strategy, the State Department has proposed developing a broader set of consequences that the government can impose on adversaries to ward off cyberattacks. The unclassified version of the State Department’s deterrence recommendations, published Thursday, calls for the U.S. to work with allies to inflict “swift, costly, and transparent consequences” on foreign governments that use “significant” malicious cyber activity to harm U.S. interests. To do that, the U.S. government needs to clearly and publicly outline the malicious activity it seeks to deter, according to the State Department report, which was required by a 2017 White House executive order. The document doesn’t go into detail on deterrence tools, but U.S. officials have said that sanctions, indictments, publicly attributing attacks, and covert offensive operations are all on the table. Dating back to the Obama administration, lawmakers have urged the executive branch to delineate a […]

The post The latest attempt by the State Department to set behavior norms appeared first on Cyberscoop.

Continue reading The latest attempt by the State Department to set behavior norms

House of Representatives to boost info-sharing program with Five Eyes allies

The U.S. House of Representatives is looking to ramp up a cyberthreat information-sharing program with the parliaments of allies Australia, Canada, New Zealand, and Britain, according to House CISO Randy Vickers. The information traded could be unclassified threat intelligence used to bolster the legislative bodies’ security. Vickers said there were already strong information-sharing relationships with the allied parliaments, the goal was simply to leverage them more. “We’re looking at ways to better share information on a more routine basis,” Vickers told CyberScoop Thursday. “It really is just about ensuring that we all have a common knowledge across our environments.” In practice, the program could be as simple as notifying the group of a new cybersecurity advisory from the Department of Homeland Security, Vickers said on the sidelines of the Cyberthreat Intelligence Forum presented by FireEye and produced by CyberScoop and FedScoop. The U.S. and the four other countries comprise the Five Eyes […]

The post House of Representatives to boost info-sharing program with Five Eyes allies appeared first on Cyberscoop.

Continue reading House of Representatives to boost info-sharing program with Five Eyes allies

In war against botnets, manufacturers need to step up, report says

The problem of botnets — the legions of computers used to carry out distributed denial-of-service attacks — is exacerbated by the fact that developers do not have the cost incentives to build more security into their products, according to a new report from the departments of Commerce and Homeland Security. “Product developers, manufacturers, and vendors are motivated to minimize cost and time to market, rather than to build in security or offer efficient security updates,” states the report mandated by a White House executive order last year. “Market incentives must be realigned to promote a better balance between security and convenience when developing products.” The report says the government should give companies some help by prioritizing research and development funding for botnet-thwarting products, and it suggests the private sector should expedite its own work on those technologies. The R&D — in techniques like data analytics, machine learning, and artificial intelligence is — “urgently needed to get […]

The post In war against botnets, manufacturers need to step up, report says appeared first on Cyberscoop.

Continue reading In war against botnets, manufacturers need to step up, report says

OMB slams agencies on cyber risk, calls for ‘bold’ new approaches

Nearly three quarters of 96 agencies reviewed by federal officials have cybersecurity programs that are either “at risk” or at “high risk,” meaning “bold approaches” are needed to secure federal networks, according to the Office of Management and Budget. Risk assessments carried out by OMB show that a lack of threat information available to agencies “results in ineffective allocations” of their limited budgets, OMB said in a report released last week. “This situation creates enterprise-wide gaps in network visibility, IT tool and capability standardization, and common operating procedures, all of which negatively impact federal cybersecurity.” In the report, a “high risk” designation means that key cybersecurity policies and tools are either absent or insufficiently deployed, while an “at risk” rating means some key policies are in place to lessen cyber risk, “but significant gaps remain.” An executive order that President Donald Trump signed last year mandated the governmentwide survey of […]

The post OMB slams agencies on cyber risk, calls for ‘bold’ new approaches appeared first on Cyberscoop.

Continue reading OMB slams agencies on cyber risk, calls for ‘bold’ new approaches