DHS unveils long-stalled cyber strategy

The Department of Homeland Security on Tuesday released a long-awaited cybersecurity strategy that looks to more proactively tackle the agency’s mandate to protect critical infrastructure from cyberattacks. The department’s cybersecurity support for critical infrastructure operators must “focus on systemic risk or address risk at individual entities that have the greatest potential impact on national security, public health and safety, and economic security,” the strategy states. The document will chart DHS’s course in cyberspace over the next five years and is an effort to keep pace with a changing threat landscape, the department said. “Nation-states continue to present a considerable cyber threat,” the document states, “but non-state actors are emerging with capabilities that match those of sophisticated nation-states.” The five broad aims of the strategy are to better identify digital risks, reduce threats and vulnerabilities, mitigate the consequences of cyberattacks, and “enable cybersecurity outcomes” by making infrastructure more resilient and improving DHS […]

The post DHS unveils long-stalled cyber strategy appeared first on Cyberscoop.

Continue reading DHS unveils long-stalled cyber strategy

Department of Energy strategy aims to make power systems more resilient to hacking

Citing an increase in criminal and nation-state hackers targeting the energy sector, the Department of Energy has released a five-year strategy to cut down on the risk of power-supply disruptions resulting from cyber incidents. “Despite improving defenses, it has become increasingly difficult for energy companies to keep up with growing and aggressive cyberattacks,” the document states. The department is trying to change that dynamic through a strategy to boost threat-sharing with the private sector, curb supply-chain risk, and accelerate research and development to make energy systems more resilient to hacking. The strategy will serve as a roadmap for the new Office of Cybersecurity, Energy Security, and Emergency Response, for which President Donald Trump’s fiscal 2019 budget requests $96 million. “Today, any cyber incident has the potential to disrupt energy services, damage highly specialized equipment, and threaten human health and safety,” Bruce Walker, an assistant secretary of Energy, wrote in the […]

The post Department of Energy strategy aims to make power systems more resilient to hacking appeared first on Cyberscoop.

Continue reading Department of Energy strategy aims to make power systems more resilient to hacking

Spyware campaign targets Turkish dissidents, research shows

Spyware made by a notorious vendor has been used to target critics of the Turkish government via Twitter, according to digital rights advocacy group Access Now. Attackers used spyware from FinFisher to target protestors focused on the Turkish government in 2017, Access Now said in a report. Hackers allegedly used Twitter-linked malicious websites to install spyware on activists’ phones. The perpetrators used a “benign-looking mobile application” as cover for the FinFisher spyware, which was part of “a broad social engineering attack” against opponents of Turkey’s ruling party, the report stated. “The broad and aggressive use of [the spyware] to target individuals involved in the March for Justice movement in Turkey provides a rare window into the current deployment of FinFisher,” Access Now said. “It gives us new clues and patterns of behavior of how social media is used in conjunction with the malware…” the organization added. There is evidence that surveillance […]

The post Spyware campaign targets Turkish dissidents, research shows appeared first on Cyberscoop.

Continue reading Spyware campaign targets Turkish dissidents, research shows

Wyden calls for FCC investigation into cell-phone tracking used by law enforcement

Democratic Senator Ron Wyden has asked the Federal Communications Commission to investigate revelations that U.S. law enforcement officials have access to a tracking service that can geolocate almost any phone in the country. The tracking service provided by Securus Technologies accesses location data from big wireless carriers like AT&T and Verizon to pinpoint phone users, and a former Missouri sheriff allegedly used the service to track other officers without court orders, the New York Times reported. A spokesperson for Securus, a Texas-based provider of prison phone services, told The Times that the firm requires customers to submit legal evidence, such as an affidavit or warrant, that the surveillance is authorized. But in his letter to the FCC, Wyden said Securus employees confirmed to his office that the firm “takes no steps to verify” that those documents legally authorize surveillance. The Oregon senator called Securus’s vetting process “nothing more than the legal equivalent of […]

The post Wyden calls for FCC investigation into cell-phone tracking used by law enforcement appeared first on Cyberscoop.

Continue reading Wyden calls for FCC investigation into cell-phone tracking used by law enforcement

Sen. Wyden blocks Krebs nomination over Stingray demands

Democratic Sen. Ron Wyden has blocked Christopher Krebs’s nomination to be undersecretary for the Department of Homeland Security’s National Protection and Programs Directorate until the department is more forthcoming about its detection of unauthorized mobile surveillance devices, commonly known as Stingrays, in the United States. In a congressional notice Thursday, Wyden said he was objecting to Senate floor consideration of the nomination until the department makes public a presentation it gave to federal employees on Stingrays in February.  “That presentation included important information that I believe the American people have a right to know,” the Oregon senator wrote. Krebs is currently NPPD’s acting head. A Department of Homeland Security spokesperson declined to comment on Wyden’s move. In a March letter to Wyden, Krebs acknowledged the presence of apparently unauthorized mobile surveillance devices in the Washington, D.C., area and elsewhere in the country that could be exploited by foreign spies to track and […]

The post Sen. Wyden blocks Krebs nomination over Stingray demands appeared first on Cyberscoop.

Continue reading Sen. Wyden blocks Krebs nomination over Stingray demands

Government would be barred from mandating crypto backdoors under House bill

A bipartisan group of House lawmakers on Thursday reintroduced legislation that would bar the government from mandating “backdoors” — configurations that enable surveillance — in commercial software and hardware products. The move is the latest salvo in a long-running legislative fight over law enforcement access to encrypted communications, and it comes after a Senate committee recently sought input from big technology firms on regulating encryption. Law enforcement officials say encryption has hampered investigations by preventing access to suspects’ communications, while cryptographers warn that weakening encryption could greatly undercut digital security for everyday people. “It is troubling that law enforcement agencies appear to be more interested in compelling U.S. companies to weaken their product security than using already available technological solutions to gain access to encrypted devices and services,” Rep. Zoe Lofgren, D-Calif., one of the bill’s sponsors, said in a statement. She introduced the bill in 2014 and has repeatedly sounded the alarm […]

The post Government would be barred from mandating crypto backdoors under House bill appeared first on Cyberscoop.

Continue reading Government would be barred from mandating crypto backdoors under House bill

NIST wants to the federal government to pay more attention to the supply chain

A federal IT standards body has moved to add key supply-chain provisions to its risk management guidance at a time of growing concern that Russian and Chinese companies pose a threat to national security. The National Institute of Standards and Technology on Wednesday released a draft update to its influential Risk Management Framework, which federal agencies use to assess cyber risk. The provisional update includes measures to guard against untrusted suppliers and the possibility of hackers slipping malicious code into the supply chain. Defining — let alone securing — all the components and systems that organizations get from third parties can be a struggle, according to the document. One answer, NIST says, is building “a chain of trust” with suppliers to ensure that each one of them provides adequate security protections for their products. The new measures are critical because of the globalized nature of the IT supply chain, according to NIST fellow Ron Ross, one of the publication’s authors. […]

The post NIST wants to the federal government to pay more attention to the supply chain appeared first on Cyberscoop.

Continue reading NIST wants to the federal government to pay more attention to the supply chain

House panel advances State Department bug bounty bill

The House Foreign Affairs Committee on Wednesday advanced a bill that would establish a bug bounty program at the State Department, the latest effort by lawmakers and security gurus to encourage agencies to use ethical hackers to secure their networks. The Hack Your State Department Act would task the Secretary of State with setting up a vulnerability disclosure process for researchers to hunt for and disclose flaws in the department’s public-facing websites and applications. The program, which would emulate the Hack the Pentagon project the Defense Department carried out in 2016, would pay researchers for finding vulnerabilities of which State officials were unaware. “Any agency or private sector company should have an independent way of testing security,” Rep. Ted Lieu, D-Calif., the bill’s sponsor, told CyberScoop. “This is one of the ways to do it – get an independent check on the strength of the cybersecurity system.” “A lot of these […]

The post House panel advances State Department bug bounty bill appeared first on Cyberscoop.

Continue reading House panel advances State Department bug bounty bill

Lawmakers call for action following revelations that APT28 posed as ISIS online

The world got a fresh reminder Tuesday of the difficulties associated with assigning blame for hacking – and of the consequences when a case of mistaken identity takes hold. New evidence reinforces the notion that a group dubbed the CyberCaliphate, which sent death threats to the wives of U.S. military personnel in 2015 under the banner of the Islamic State, is actually an infamous Russian-government-linked hacking group accused of meddling in the 2016 U.S. presidential election, the Associated Press reported. Activity from the CyberCaliphate coincided with attempts by the Russian group, known as APT28 or Fancy Bear, to breach the womens’ email accounts, according to the Associated Press. The episode brings to life established links between the CyberCaliphate and APT28 in a way that no cybersecurity research did. The hacking victims were led to believe that jihadists, and not state-backed Russians, were breaching their accounts and leaving threatening messages. Amy […]

The post Lawmakers call for action following revelations that APT28 posed as ISIS online appeared first on Cyberscoop.

Continue reading Lawmakers call for action following revelations that APT28 posed as ISIS online

Senate panel advances Krebs nomination to lead NPPD

A Senate committee has approved Christopher Krebs to be undersecretary for the Department of Homeland Security’s National Protection and Programs Directorate, a key role for the department as it tackles digital threats to infrastructure and readies a new cybersecurity strategy. Krebs’s nomination, which President Donald Trump made in February, now goes to the Senate floor for a vote. During an April 25 confirmation hearing, Krebs described the undersecretary position as the “pinnacle of national risk management in cyber and physical infrastructure.” He also vowed to prioritize the department’s work on election security ahead of crucial midterm elections this fall. A group of former senior national security officials wrote to the Senate Homeland Security and Governmental Affairs Committee leadership last month in support of Krebs’s nomination, lauding his leadership during DHS’s response to the WannaCry ransomware attacks and the Meltdown and Spectre computer-chip vulnerabilities. Members of the committee, who have praised […]

The post Senate panel advances Krebs nomination to lead NPPD appeared first on Cyberscoop.

Continue reading Senate panel advances Krebs nomination to lead NPPD