House and Senate members propose legislation for CISA to step up cyber defenses for biotech

Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it.

The post House and Senate members propose legislation for CISA to step up cyber defenses for biotech appeared first on CyberScoop.

Continue reading House and Senate members propose legislation for CISA to step up cyber defenses for biotech→

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud.

The post Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges appeared first on CyberScoop.

Continue reading Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges→

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices.

The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop.

Continue reading Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks→

CISA outlines improvement plan for CVE program

The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilities and Exposures (CVE) program as the number of CVEs surges.

The post CISA outlines improvement plan for CVE program appeared first on CyberScoop.

Continue reading CISA outlines improvement plan for CVE program→

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives.

The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop.

Continue reading Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack→

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program.

The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.

Continue reading After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program→

Another worry for water systems: infostealer exposure

SpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants.

The post Another worry for water systems: infostealer exposure appeared first on CyberScoop.

Continue reading Another worry for water systems: infostealer exposure→

Dems seek top-to-bottom assessment of CISA workforce

After the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

Continue reading Dems seek top-to-bottom assessment of CISA workforce→

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide.

The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.

Continue reading International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data→

CISA promotes a fresh way to deter cyberattackers: Lie to them

It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries.

The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.

Continue reading CISA promotes a fresh way to deter cyberattackers: Lie to them→