As ransomware hobbled Atlanta, banks drilled for next iteration of attacks

As the Atlanta city government struggled to recover from March’s ransomware attack, cybersecurity personnel from U.S. banks huddled two miles from city headquarters to practice dealing with the same type of disruptive malware. The exercise, which assembled 18 financial institutions and the industry’s threat-sharing center, simulated a bank’s computer network and tasked participants with defeating “WannaCry-like” ransomware, according to ManTech International Corp., the cybersecurity company that hosted the drill in April. Participants, including big U.S. banks, connected to ManTech’s Advanced Cyber Range Environment (ACRE), a computing facility that can test network defenses against various strains of malware. Some participated from the Federal Reserve office in midtown Atlanta, according to ManTech spokesman Jim Crawford. In this case, exercise planners mimicked the WannaCry ransomware, which struck more than 300,000 computers in 150 countries last year. The company already had practice using that virus for ACRE training “when it was still in the wild,” Brett Barraclough, a ManTech […]

The post As ransomware hobbled Atlanta, banks drilled for next iteration of attacks appeared first on Cyberscoop.

Continue reading As ransomware hobbled Atlanta, banks drilled for next iteration of attacks

House defense bill would usher in cybersecurity changes at DOD

The House of Representatives this week overwhelmingly passed a defense policy bill with several cybersecurity measures aimed at better securing Pentagon networks. The legislation — the fiscal 2019 National Defense Authorization Act (NDAA) — seeks closer collaboration between the departments of Defense and Homeland Security in defending against hackers, asks for quick notification of data breaches of military personnel, and continues to crack down on foreign-made telecom products that are deemed security threats. The NDAA is an annual ritual that lawmakers use to shape Pentagon policies and budget plans while throwing in some pet projects to boot. The House bill — a $717 billion behemoth — eventually will be merged with the Senate’s version, which that chamber’s Armed Services Committee also approved this week. It’s unclear when the Senate bill will have floor votes. One key provision of the House bill, according to the Rules Committee print, would set up a pilot program for […]

The post House defense bill would usher in cybersecurity changes at DOD appeared first on Cyberscoop.

Continue reading House defense bill would usher in cybersecurity changes at DOD

U.S. industry experts call for vigilance after Trisis group goes global

U.S. critical infrastructure operators should be on high alert — with a close eye on network anomalies — following the revelation that a hacking group that caused a Saudi industrial plant to shut down last year is targeting facilities outside of the Middle East, industry experts told CyberScoop. “Detecting these types of advanced, stealthy threats requires extraordinary visibility into your OT [operational technology] network,” said Marty Edwards, former head of the Department of Homeland Security’s Industrial Control Systems (ICS) CERT. “Unfortunately, not all U.S. critical infrastructure asset owners are at that level of maturity.” The hacking group’s expanded operations mean that U.S. infrastructure operators “should no longer remain complacent in thinking that this is just an issue somewhere else in the world,” Edwards added. The developers of the Trisis malware, which is designed to ravage the control systems that allow plants to safely shut down, have attacked multiple U.S. companies, […]

The post U.S. industry experts call for vigilance after Trisis group goes global appeared first on Cyberscoop.

Continue reading U.S. industry experts call for vigilance after Trisis group goes global

Lawmakers look to fortify federal cyber defenses ahead of 2018 midterms

A bipartisan pair of House lawmakers have introduced legislation aimed at strengthening U.S. infrastructure ahead of midterm elections this fall. The bill from Reps. Elise Stefanik, R-N.Y., and Val Demings, D-Fla., is an effort to shore up U.S. cyber defenses by, among other measures, urging agencies to fully implement an executive order on cybersecurity that President Donald Trump issued last year. The president’s directive makes agency heads accountable for cyber risk – such as nation-state hacking – that can affect the entire government. Within 60 days of the legislation’s enactment, Trump would owe a report to Congress on what steps agencies had taken to “better detect, monitor, and mitigate cyberattacks.” Stefanik and Demings’s “Defend Against Russian Disinformation Act,” would also boost U.S. military cooperation with NATO. Cybersecurity analysts have held up Estonia, a neighbor of Russia and NATO member, as a model of cyber resiliency. The U.S. intelligence community concluded that […]

The post Lawmakers look to fortify federal cyber defenses ahead of 2018 midterms appeared first on Cyberscoop.

Continue reading Lawmakers look to fortify federal cyber defenses ahead of 2018 midterms

With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

In the wake of the White House’s decision to eliminate its top cybersecurity position, a Department of Homeland Security official has called on the U.S. government to robustly engage on cyber policy issues on the world stage. The Trump administration should have a “strong voice” at internet standards bodies and other global forums, working with allies and non-allies alike, said Jeanette Manfra, assistant secretary for DHS’s Office of Cybersecurity and Communications. “We have to figure out a way to continue to work together to ensure that the stability of the global system is maintained,” Manfra said Tuesday at the Security Through Innovation Summit, presented by McAfee and produced by CyberScoop. Manfra did not mention the recently-nixed White House cybersecurity coordinator in her remarks, but that position has traditionally been key to the United States’ international cybersecurity work. At a February conference in Germany, for example, then-White House cybersecurity coordinator Rob […]

The post With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity appeared first on Cyberscoop.

Continue reading With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

Senators want National Guard on call for cyberattacks

A pair of Senate Democrats have introduced legislation that would give the National Guard a bigger role in defending everything from election systems to dams from cyberattacks. The bill from Sens. Maria Cantwell, Wash., and Joe Manchin, W.Va., would set up National Guard “cyber civil support teams” in every state and territory “to bridge the gap between federal and non-federal cybersecurity efforts,” the senators’ offices said in a release. The bill would put $50 million toward the National Guard teams, which would be tasked with preventing and mitigating the impact of cyber incidents, training critical infrastructure operators, and relaying classified threat information from U.S. Cyber Command to the states and private companies. States would have until September 30, 2022 to make their National Guard cyber teams operational. Another Democrat from Washington State, Rep. Derek Kilmer, has introduced companion legislation in the house. “As cyberattacks on the United States increase, we must […]

The post Senators want National Guard on call for cyberattacks appeared first on Cyberscoop.

Continue reading Senators want National Guard on call for cyberattacks

Tech giants reveal new variant of Meltdown and Spectre vulns

Intel and Microsoft have revealed a new variant of the Meltdown and Spectre chip vulnerabilities that have plagued their products in recent months. The new vulnerability, dubbed “Variant 4,” can be exploited through JavaScript in a web browser to steal data. Like the Meltdown and Spectre vulnerabilities, “Variant 4 uses speculative execution, a feature common to most modern processor architectures, to potentially expose certain kinds of data through a side channel,” Leslie Culbertson, an executive vice president at Intel, wrote in a blog post. Intel isn’t aware of any exploits of Variant 4 in the wild, Culbertson said, crediting the company’s expanded bug bounty program for boosting security. In a security advisory published Monday, Microsoft said that is wasn’t “aware of any exploitable code patterns of this vulnerability class in our software or cloud service infrastructure, but we are continuing to investigate.” The Spectre (Variants 1 and 2) and Meltdown […]

The post Tech giants reveal new variant of Meltdown and Spectre vulns appeared first on Cyberscoop.

Continue reading Tech giants reveal new variant of Meltdown and Spectre vulns

Cisco fixes critical ‘DNA’ software flaws

IT giant Cisco this week released patches for three critical vulnerabilities in its enterprise networking software, two of which could allow an attacker to bypass authentication measures and access data deep into the network. The affected software, known as the Digital Network Architecture (DNA) Center, serves as a hub for configuring devices across an IT network, allowing administrators to track networking flaws. Each of the vulnerabilities is fixed in more recent versions of the software. One of the vulnerabilities stems from an insecure configuration of a DNA Center management system, Cisco said in an advisory. An attacker with the ability to access the management system’s service port “could execute commands with elevated privileges within provisioned containers,” the company said, potentially resulting in the complete compromise of a container. The San Jose, California-based company said it found two of the three software bugs in internal testing (the third was discovered in […]

The post Cisco fixes critical ‘DNA’ software flaws appeared first on Cyberscoop.

Continue reading Cisco fixes critical ‘DNA’ software flaws

House measure asks DHS to share info on potential ZTE cyber threat

A new House of Representatives measure would direct the Department of Homeland Security to give lawmakers more information on potential cybersecurity threats posed by Chinese telecommunications firm ZTE. The “resolution of inquiry” introduced by Rep. Bennie Thompson, D-Miss., would task DHS with giving the committee an assessment of cyber risks introduced by any use of ZTE products on federal, state, and local government networks. U.S. intelligence officials have warned of the risk of cyber-espionage from ZTE due to its alleged ties to the Chinese government, and the U.S. government has fined the company for violating U.S. sanctions on Iran and North Korea. The Pentagon earlier this month told vendors on military bases to stop selling devices from ZTE and another Chinese state-linked telecoms firm, Huawei. ZTE has denied those allegations, saying it values privacy and cybersecurity. In an abrupt divergence from U.S. officials’ warnings, President Donald Trump on Sunday tweeted that […]

The post House measure asks DHS to share info on potential ZTE cyber threat appeared first on Cyberscoop.

Continue reading House measure asks DHS to share info on potential ZTE cyber threat

Lawmakers introduce bill to save top White House cyber job after Bolton eliminated it

House Democrats on Tuesday introduced legislation to codify a top cybersecurity position at the White House following National Security Adviser John Bolton’s decision to eliminate the role. The bill from Democratic Reps. Jim Langevin, R.I., and Ted Lieu, Calif., would establish a National Office for Cyberspace in the Executive Office of the President – and a Senate-confirmed head of that office. That official would synchronize cybersecurity policy across agencies in much the same way that White House cybersecurity coordinator Rob Joyce was doing until he stepped down last week. Against the backdrop of Joyce’s decision to leave the coordinator role and return to the National Security Agency, a power struggle over cybersecurity leadership at the National Security Council has ensued. Bolton ultimately decided to scrap the coordinator role. An aide to Bolton emailed NSC staff on Tuesday saying the move would help cut “another layer of bureaucracy.” Politico was first to report on Bolton’s […]

The post Lawmakers introduce bill to save top White House cyber job after Bolton eliminated it appeared first on Cyberscoop.

Continue reading Lawmakers introduce bill to save top White House cyber job after Bolton eliminated it