Newly-formed international alliances vow to improve cybersecurity, in moves China sees as affront

A coalition of four nations — Australia, India, Japan and the U.S. — has committed to promoting cybersecurity standards and practices as one of their chief goals, in one of several recent moves from countries widely viewed as a counter to China in cyberspace and elsewhere. The group, which calls itself the Quad, held its first in-person gathering on Friday. when President Joe Biden hosted Prime Minister Scott Morrison of Australia, Prime Minister Narendra Modi of India and Prime Minister Yoshihide Suga of Japan at the White House. “Today, we begin new cooperation in cyberspace and pledge to work together to combat cyber threats, promote resilience and secure our critical infrastructure,” the group said in a joint statement. The group will hold more meetings between its leaders and collaborate with industry on improving in areas like the development of secure software, and building up cybersecurity workforces, according to a fact […]

The post Newly-formed international alliances vow to improve cybersecurity, in moves China sees as affront appeared first on CyberScoop.

Continue reading Newly-formed international alliances vow to improve cybersecurity, in moves China sees as affront

EU takes aim at Russia over ‘Ghostwriter’ hacking campaign against politicians, government officials

The European Union formally blamed Russia on Friday, just ahead of this weekend’s German elections, for a hacking campaign targeting EU government officials and politicians. And the EU is threatening to take unspecified action. “The European Union will revert to this issue in upcoming meetings and consider taking further steps,” reads a statement from the high representative of the EU. Known as Ghostwriter, the campaign drawing the EU’s ire has previously taken aim at NATO and launched disinformation efforts as well, according to researchers who have tied its goals to Russian interests but not attributed it to the government. “The European Union and its Member States strongly denounce these malicious cyber activities, which all involved must put to an end immediately,” the EU statement reads. “We urge the Russian Federation to adhere to the norms of responsible state behaviour in cyberspace.” The EU says that Ghostwriter targets in its member […]

The post EU takes aim at Russia over ‘Ghostwriter’ hacking campaign against politicians, government officials appeared first on CyberScoop.

Continue reading EU takes aim at Russia over ‘Ghostwriter’ hacking campaign against politicians, government officials

Biden administration officials push Congress to shape breach reporting mandates

U.S. cybersecurity officials are seeking to put their stamp on cyber incident reporting legislation, wading into debates on Capitol Hill about questions like how swiftly companies must report attacks to federal agencies — and what happens if they don’t. The head of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency testified at a Senate hearing Thursday in favor of requiring critical infrastructure owners and operators, federal contractors and agencies to report attacks to CISA within 24 hours of detection. There are three leading proposals in Congress, each with a different timeframe for reporting attacks. The leaders of the Senate Intelligence Committee favor a 24-hour deadline. A draft bill from leaders of the Senate Homeland Security and Governmental Affairs Committee would set the range at between 72 hours and seven days, as determined by CISA. And a draft from leading members of the House Homeland Security Committee proposes leaving […]

The post Biden administration officials push Congress to shape breach reporting mandates appeared first on CyberScoop.

Continue reading Biden administration officials push Congress to shape breach reporting mandates

Espionage group targeted hotels, governments, seized on Microsoft Exchange vulnerability

ESET said it discovered the group, which has been active since 2019.

The post Espionage group targeted hotels, governments, seized on Microsoft Exchange vulnerability appeared first on CyberScoop.

Continue reading Espionage group targeted hotels, governments, seized on Microsoft Exchange vulnerability

Key lawmakers to CISA: Let us send you more money, power

The Department of Homeland Security’s cyber division, a key government agency charged with helping stop and respond to cyberattacks, might be getting ready for a bigger role in the spotlight.  One key House committee advanced legislation in July to give the Cybersecurity and Infrastructure Security Agency an extra $400 million. Then, another committee on Sept. 14 separately advanced its take on legislation that would provide an additional nearly $800 million to the agency, which has a $2 billion total budget in the current fiscal year. Those proposed funds come on top of another extra $650 million that Congress and President Joe Biden already provided to CISA in March through the American Rescue Plan focused on COVID-19 relief. And the recent moves on Capitol Hill to bolster CISA, an agency formally established only three years ago, aren’t limited to cash. Both chambers of Congress are contemplating legislation that would make CISA the […]

The post Key lawmakers to CISA: Let us send you more money, power appeared first on CyberScoop.

Continue reading Key lawmakers to CISA: Let us send you more money, power

Key lawmakers to CISA: Let us send you more money, power

The Department of Homeland Security’s cyber division, a key government agency charged with helping stop and respond to cyberattacks, might be getting ready for a bigger role in the spotlight.  One key House committee advanced legislation in July to give the Cybersecurity and Infrastructure Security Agency an extra $400 million. Then, another committee on Sept. 14 separately advanced its take on legislation that would provide an additional nearly $800 million to the agency, which has a $2 billion total budget in the current fiscal year. Those proposed funds come on top of another extra $650 million that Congress and President Joe Biden already provided to CISA in March through the American Rescue Plan focused on COVID-19 relief. And the recent moves on Capitol Hill to bolster CISA, an agency formally established only three years ago, aren’t limited to cash. Both chambers of Congress are contemplating legislation that would make CISA the […]

The post Key lawmakers to CISA: Let us send you more money, power appeared first on CyberScoop.

Continue reading Key lawmakers to CISA: Let us send you more money, power

Ransomware gang strikes Iowa agriculture business New Cooperative, the latest hack on food supply chain

The BlackMatter ransomware gang has struck an Iowa agricultural business, New Cooperative, and is demanding a $5.9 million ransom. Several security researchers first called attention to the hack on Monday, and the company confirmed to Bloomberg that it had been hit with a cyberattack and shut down its systems in response. It’s another big hit against the agriculture industry, following the May ransomware attack on JBS by REvil, a gang that researchers said has ties to BlackMatter. New Cooperative is a grain collective based out of Fort Dodge. In negotiations dated Sept. 19 and posted online, a person speaking on behalf of the company said the attack would cause severe problems in the food supply chain. “We are critical infrastructure – we [sic] intertwined with the food supply chain in the US,” they wrote. “If we are not able to recover very shortly, there is going to be a very […]

The post Ransomware gang strikes Iowa agriculture business New Cooperative, the latest hack on food supply chain appeared first on CyberScoop.

Continue reading Ransomware gang strikes Iowa agriculture business New Cooperative, the latest hack on food supply chain

Bitdefender releases REvil decryptor as ransomware gang shows signs of return

As law enforcement braces for the revival of the REvil ransomware gang, a cybersecurity firm on Thursday released a free decryption tool for early victims of the criminals. The decryptor, which Bitdefender developed in coordination with an unnamed law enforcement partner, will aid victims hit before July 13. The Romania-based company said it was still in the middle of an investigation with its partner, which agreed to release the decryptor before completing the joint inquiry to help as many victims as possible. Bitdefender has a long history of working with Europol to release tools that help victims of digital extortion sidestep the process of making a payment. “We believe new REvil attacks are imminent after the ransomware gang’s servers and supporting infrastructure recently came back online after a two month hiatus,” Bitdefender wrote in a blog post. According to another cybersecurity firm, Flashpoint, REvil is already fully back in business. […]

The post Bitdefender releases REvil decryptor as ransomware gang shows signs of return appeared first on CyberScoop.

Continue reading Bitdefender releases REvil decryptor as ransomware gang shows signs of return

Email scammers posed as DOT officials in phishing messages focused on $1 trillion bill

Shortly after Congress took action on a $1 trillion infrastructure bill, hackers posing as U.S. Transportation Department officials offered fake project bid opportunities to seduce companies into handing over Microsoft credentials, researchers say. The ploy included layers of attempts to disguise the malicious appeals as authentic government solicitations, and even eventually led the would-be victims back to the actual Department of Transportation website, according to a Wednesday blog post from INKY, an email security company. “The basic pitch was, with a trillion dollars of government money flowing through the system, you, dear target, are being invited to bid for some of this bounty,” wrote Roger Kay, vice president of security strategy for the firm. Never mind that the infrastructure legislation hasn’t fully worked its way through Congress yet, nor that few of the phishing campaign’s targets would even be eligible for the infrastructure projects that bill would fund. It’s the […]

The post Email scammers posed as DOT officials in phishing messages focused on $1 trillion bill appeared first on CyberScoop.

Continue reading Email scammers posed as DOT officials in phishing messages focused on $1 trillion bill

CISA hires long-time cyber pro Kiersten Todt as chief of staff

The Cybersecurity and Infrastructure Security Agency is getting Kiersten Todt — a veteran of cyber-focused roles in the executive branch, on Capitol Hill and the private sector — as its chief of staff. Todt has been heading up the Cyber Readiness Institute, a non-profit focused on developing cybersecurity tools for small businesses. She now returns to the public sector at CISA, housed within the Department of Homeland Security. When she last worked for the federal government, it was as executive director of President Barack Obama’s Commission on Enhancing National Cybersecurity. Among the recommendations in its 2016 final report: creation of an agency just like CISA. Now, at CISA, Todt will focus on long-range objectives, allocating resources and the CISA workforce. “I look forward to shaping CISA’s long-term planning and working with industry, federal agencies, and state, local, tribal, and territorial government partners to chart the path forward for a more […]

The post CISA hires long-time cyber pro Kiersten Todt as chief of staff appeared first on CyberScoop.

Continue reading CISA hires long-time cyber pro Kiersten Todt as chief of staff