The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official

The internet domain registration system is a major weakness that malicious hackers can exploit, but is often being overlooked, a senior Secret Service official said Thursday. “It is staggering to me that we live in a world where domain registrars and registrars will do bulk registration of various spellings of a major institution’s brand name […]

The post The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official appeared first on CyberScoop.

Continue reading The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official

US wants to push its view of AI cybersecurity standards to the rest of the world

The Trump administration also envisions artificial intelligence playing a role in protecting federal government networks.

The post US wants to push its view of AI cybersecurity standards to the rest of the world appeared first on CyberScoop.

Continue reading US wants to push its view of AI cybersecurity standards to the rest of the world

Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers

The Senate Judiciary Committee held a hearing on Section 702, set to sunset at the end of April, but with no Trump administration witnesses present.

The post Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers appeared first on CyberScoop.

Continue reading Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers

OMB rescinds ‘burdensome’ Biden-era secure software memo

Russell Vought’s updated memo using a common attestation form voluntary. A critic told CyberScoop it’s the “first major policy step back” on cybersecurity under Trump.

The post OMB rescinds ‘burdensome’ Biden-era secure software memo appeared first on CyberScoop.

Continue reading OMB rescinds ‘burdensome’ Biden-era secure software memo

Industry, government, nonprofits weigh voluntary rules for commercial hacking tools

The weekend discussion about the next step of the Pall Mall Process revealed some of the topics rules-writers will have to weigh.

The post Industry, government, nonprofits weigh voluntary rules for commercial hacking tools appeared first on CyberScoop.

Continue reading Industry, government, nonprofits weigh voluntary rules for commercial hacking tools

Researchers find Jordan government used Cellebrite phone-cracking tech against activists

The incidents occurred amid Gaza protests and suggest human rights violations, Citizen Lab said.

The post Researchers find Jordan government used Cellebrite phone-cracking tech against activists appeared first on CyberScoop.

Continue reading Researchers find Jordan government used Cellebrite phone-cracking tech against activists

Lawmakers probe CISA leader over staffing decisions

The House Homeland Security Committee grilled Madhu Gottumukkala, the acting director of the agency, over cutbacks both broad and specific.

The post Lawmakers probe CISA leader over staffing decisions appeared first on CyberScoop.

Continue reading Lawmakers probe CISA leader over staffing decisions

Congressional appropriators move to extend information-sharing law, fund CISA

The legislation also includes mandates on election security funding and CISA staff levels, as well as an extension of a state and local cyber grant program.

The post Congressional appropriators move to extend information-sharing law, fund CISA appeared first on CyberScoop.

Continue reading Congressional appropriators move to extend information-sharing law, fund CISA

CISA’s secure-software buying tool had a simple XSS vulnerability of its own

A researcher who discovered the vulnerability said it was fixed in December, after he first reported it to the agency in September.

The post CISA’s secure-software buying tool had a simple XSS vulnerability of its own appeared first on CyberScoop.

Continue reading CISA’s secure-software buying tool had a simple XSS vulnerability of its own