The uphill battle to relaunch State Department’s cybersecurity policy office

Be it through legislation or some internal decree, restoring the State Department’s cybersecurity policy office to a prominent place in the agency can’t come soon enough for advocates of U.S. digital diplomacy. Analysts and former government officials say U.S. leadership in shaping international behavior in cyberspace has stalled at a time when nation-state hacking groups are flexing their muscles. “I worry about a gap that leaves allies wondering and adversaries savoring the chance to take advantage of the perceived lack of U.S. leadership,” Christopher Painter, State’s former cybersecurity coordinator, told CyberScoop. “When you have diminished resources [and] when you have uncertainty, inevitably that causes some loss of momentum.” In the eight months since former Secretary of State Rex Tillerson said he would downgrade the department’s cybersecurity office, the United States has blamed North Korea for the destructive WannaCry ransomware attack, indicted Iranian hackers for terabytes worth of intellectual property theft, and […]

The post The uphill battle to relaunch State Department’s cybersecurity policy office appeared first on Cyberscoop.

Continue reading The uphill battle to relaunch State Department’s cybersecurity policy office

State Department to double cyber defense aid to Ukraine

The State Department will double the cyber defense aid it pledged to Ukraine last year to $10 million in an effort to bolster the security of an ally in the crosshairs of alleged Russian hackers, according to department spokesperson. Wess Mitchell, the assistant secretary of State for European and Eurasian Affairs, made the announcement Wednesday after meeting with Ukrainian President Petro Poroshenko, State Department Spokeswoman Heather Nauert said. “The threat from Russia is real,” Nauert tweeted. “Our commitment to Ukraine is unbending.” A different department spokesperson declined to comment when CyberScoop asked how the new money will be used. The two countries held their first bilateral cybersecurity dialogue in Kiev in September, at which the United States announced $5 million in new cybersecurity assistance to “strengthen Ukraine’s ability to prevent, mitigate, and respond to cyberattacks.” The Ukrainian power grid has been a ripe target for hackers, who carried out advanced […]

The post State Department to double cyber defense aid to Ukraine appeared first on Cyberscoop.

Continue reading State Department to double cyber defense aid to Ukraine

New vuln discovered in Schneider Electric software, patches already issued

A significant vulnerability in Schneider Electric software used at manufacturing and energy facilities could allow hackers to execute arbitrary code and,”in a worst-case scenario, disrupt or cripple plant operations,” cybersecurity firm Tenable announced Wednesday. According to the Maryland-based company, an attacker without credentials could use the vulnerability to compromise Schneider Electric software used to develop – and build applications for – the human machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems that drive industrial automation. After compromising a machine, a hacker could move laterally within an organization’s network to carry out other attacks, according to Tenable. Schneider Electric issued patches for the software – versions of InduSoft Web Studio and InTouch Machine Edition – and urged affected customers to swiftly apply them lest an attacker use the vulnerability to “remotely execute code with high privileges.” “This Schneider Electric vulnerability is particularly concerning because of the potential access it grants […]

The post New vuln discovered in Schneider Electric software, patches already issued appeared first on Cyberscoop.

Continue reading New vuln discovered in Schneider Electric software, patches already issued

Ruppersberger calls for DHS to improve threat-sharing, warns of nation-state hacking tools

As the Department of Homeland Security prepares a new cybersecurity strategy, a report released Monday by Rep. Dutch Ruppersberger, D-Md., called on the department to improve its information-sharing program and warned of the threat posed by nation-state hacking tools to federal networks. Talk of making cyberthreat sharing real-time and robust has “gone on far too long,” and U.S. networks “can no longer rely solely on reactive, indicator-based sharing programs” to defend against hacking, stated the report to the House Appropriations Subcommittee on Homeland Security. DHS has worked to quicken the pace at which it shares threat information with the private sector via the Automated Indicator Sharing program. Homeland Security Secretary Kirstjen Nielsen last week touted the program in testimony to the House Homeland Security Committee. “We’re encouraging more and more companies and entities to [participate in the program] so, at machine speed, we can advise them of incoming threat vectors,” […]

The post Ruppersberger calls for DHS to improve threat-sharing, warns of nation-state hacking tools appeared first on Cyberscoop.

Continue reading Ruppersberger calls for DHS to improve threat-sharing, warns of nation-state hacking tools

State threat-sharing center warns of multiple PHP vulnerabilities

A popular programming language contains multiple vulnerabilities, the worst of which could allow attackers to execute commands of their choice, according to a new advisory from the Multi-State Information Sharing and Analysis Center. The center said the vulnerabilities were a high risk to government organizations and businesses of all sizes. The vulnerabilities concern the Hypertext Preprocessor (PHP), an open-source script language for web development. “Depending on the privileges associated with the application, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights,” warned the MS-ISAC, a threat-sharing center for state, local, tribal and territorial government agencies. The advisory urges users to upgrade to the newest PHP version immediately after testing, and to ensure that there haven’t been any unauthorized system changes before applying patches. Tom Kellermann, chief cybersecurity officer at cloud-security firm Carbon Black, said the PHP revelations were evidence of slack attention […]

The post State threat-sharing center warns of multiple PHP vulnerabilities appeared first on Cyberscoop.

Continue reading State threat-sharing center warns of multiple PHP vulnerabilities

Nuclear Power Plants Have a ‘Blind Spot’ for Hackers. Here’s How to Fix That.

Malware hunters, regulators, and plant employees are hunting further down the supply chain for vulnerabilities as hackers continue to target critical infrastructure. Continue reading Nuclear Power Plants Have a ‘Blind Spot’ for Hackers. Here’s How to Fix That.

Regulators tightening controls on devices connecting to utility company networks

U.S. regulators are cracking down on the cybersecurity risks to the electric grid posed by everyday electronics like laptops and flash drives. A ruling issued last week by the Federal Energy Regulatory Commission requires utilities to implement security controls on portable devices that interact with “low-impact” systems, or ones that utilities deem less critical. FERC also ordered the revision of power reliability standards “to mitigate the risk of malicious code” stemming from the devices. The move comes as the Department of Homeland Security has warned that Russian government hackers have their sights on U.S. energy firms, and as Congress readies legislation to secure the grid. Observers say FERC’s tightening of security controls further down the grid could shake up how large portions of the sector approach cybersecurity. Daniel Skees, a lawyer who represents utilities before FERC, said the new ruling amounts to a “sea change” for utilities because it will […]

The post Regulators tightening controls on devices connecting to utility company networks appeared first on Cyberscoop.

Continue reading Regulators tightening controls on devices connecting to utility company networks

Fed contractors aren’t using DMARC, new study finds

Just one of the 50 biggest federal IT contractors have adopted an important email security measure to guard against phishing, according to a new study. The Global Cyber Alliance’s (GCA) survey of the who’s who of Beltway contractors, including Lockheed Martin, Booz Allen Hamilton, and AT&T, found that all but one – analytics firm Engility, failed to use the Domain-based Message, Authentication, Reporting and Conformance (DMARC) protocol to block phishing attempts. Only one other contractor, the engineering firm and consultancy Tetra Tech, was implementing the second-highest DMARC control, in which phishing emails are quarantined.  Meanwhile, more than half the contractors had yet to implement any DMARC policy whatsoever, according to the study. Phishing is one of hackers’ favorite tools for breaching a network, and the federal government has been trying to defend against it for years. DMARC fights phishing by creating a public record for checking whether an email sender […]

The post Fed contractors aren’t using DMARC, new study finds appeared first on Cyberscoop.

Continue reading Fed contractors aren’t using DMARC, new study finds

‘Aggressive posture’ defines election security work, DHS official tells senators

A senior Department of Homeland Security official on Tuesday defended its work to help secure voting systems before midterm elections, but a top Democratic lawmaker worried those efforts were insufficient. DHS has “adopted an aggressive posture” to help state officials secure their voting infrastructure and will do all it can ahead of Election Day, DHS’s Jeanette Manfra told the Senate Homeland Security and Governmental Affairs Committee. At the same time, she said, the department has yet to detect Russian cyber-activity on state systems this election season. DHS will use the $26 million in additional election-security funding provided by the March omnibus to increase vulnerability assessments and other services it offers states, Manfra told CyberScoop after the hearing. That money is separate from the $380 million the bill allocated directly to individual states to do things like upgrade their computer systems and train officials in cybersecurity. But Sen. Claire McCaskill, D-Mo., the committee’s […]

The post ‘Aggressive posture’ defines election security work, DHS official tells senators appeared first on Cyberscoop.

Continue reading ‘Aggressive posture’ defines election security work, DHS official tells senators

‘Orangeworm’ hacking campaign hits X-ray and MRI machines

Malware from a newly disclosed hacking campaign has infected the networks of multinational health care companies, including some X-ray and MRI machines, cybersecurity firm Symantec warned Monday. The hacking group, dubbed Orangeworm, has hit a relatively small number of companies in more than 20 countries, Symantec said in an advisory. Nearly 40 percent of Orangeworm’s victims are in the health care industry, the advisory said. Manufacturers and IT companies that do business in health care have also been infected. Orangeworm’s custom malware has shown up on machines that control “high-tech imaging devices such as X-ray and MRI machines,” Symantec said. The Orangeworm revelation adds to a slew of cybersecurity challenges, including ransomware, facing the health care sector. An Indiana hospital in January paid roughly $50,000 in bitcoin to hackers that held its computer system hostage. Congress has taken notice of the sector’s vulnerabilities. House lawmakers on Friday issued a request for information asking industry […]

The post ‘Orangeworm’ hacking campaign hits X-ray and MRI machines appeared first on Cyberscoop.

Continue reading ‘Orangeworm’ hacking campaign hits X-ray and MRI machines