Congress is starting to move on more cyber bills, even if few become law

Congress dramatically ratcheted up the number of cybersecurity bills introduced in the last two years compared to the prior session of Congress, but that didn’t equate to much more of it becoming law, according to a think tank study out today. And while cybersecurity legislation remained a relative oasis of bipartisanship, that tendency sharply dropped off when it came to election security, found the tally from Third Way — which CyberScoop is first reporting. The findings offer potential insights into how the issue is evolving, and where it might go next, even if the trends don’t lend themselves to a simple explanation. In all, lawmakers introduced 316 cybersecurity bills in the 116th Congress that ran from 2019 to 2020, a 40% increase from the 115th Congress. That continues a trend that took off in that session of Congress: The 114th Congress saw just 22 cybersecurity measures offered, the center-left think […]

The post Congress is starting to move on more cyber bills, even if few become law appeared first on CyberScoop.

Continue reading Congress is starting to move on more cyber bills, even if few become law

House Dems pressure tech giants over spread of COVID-19 vaccine misinformation

With reports of COVID-19 vaccine misinformation and disinformation proliferating on tech platforms, Democratic leaders of the House Energy and Commerce Committee on Tuesday said they want answers from the industry’s titans about what they’re doing to stop it. “As the country enters this next phase in its fight against the virus — the success of which is dependent on hundreds of millions of Americans trusting the science behind these vaccines — the Committee is deeply troubled by news reports of coronavirus vaccine misinformation on your platform,” wrote Democratic leaders of the panel, including Chairman Frank Pallone, D-N.J., to the CEOs of Facebook, Google and Twitter. It’s the latest application of pressure on tech companies from government officials to halt fake news about COVID-19. Just last week, the European Union said it expects Facebook, Google, Microsoft and Twitter to continue delivering monthly reports on the subject for another six months. There’s […]

The post House Dems pressure tech giants over spread of COVID-19 vaccine misinformation appeared first on CyberScoop.

Continue reading House Dems pressure tech giants over spread of COVID-19 vaccine misinformation

Amid military coup, Myanmar’s internet is partially blacked out

Internet connectivity dropped precipitously in Myanmar on Monday as the military seized power, likely the result of the government shutting down access in a move that drew condemnation from President Joe Biden and digital freedom activists. The Myanmar military detained senior civilian politicians, including President U Win Myint and Nobel laureate Aung San Suu Kyi, whose party won a majority of parliamentary seats in the November elections. A military-owned television network said Commander-in-Chief Senior Gen. Min Aung Hlaing would assume control of the nation for one year following the military’s allegations that the elections were fraudulent. NetBlocks, which tracks digital freedom, said connectivity fell in Myanmar by 50% at one point before later recovering to 75% of ordinary levels. The disruption pattern pointed to a centrally issued blackout order to telecommunications providers, NetBlocks said. The outage accompanied a reported Army order to shutdown state media and the disabling of phone […]

The post Amid military coup, Myanmar’s internet is partially blacked out appeared first on CyberScoop.

Continue reading Amid military coup, Myanmar’s internet is partially blacked out

Emotet, NetWalker and TrickBot have taken big blows, but will it be enough?

A trio of operations meant to disrupt ransomware outfits in recent months — two of which came to light this week — could have lasting impacts even if they stop short of ending the threat, security experts say. Researchers are still sizing up the effects of recent busts of the Emotet and NetWalker gangs, but those operations have the potential to be more potent than last fall’s maneuvers against the TrickBot ransomware. In research out Friday, Menlo Security — echoing similar conclusions from other cyber firms — said it saw signs of TrickBot recovering, but the rebound has amounted to just a “trickle.” U.S. Cyber Command and Microsoft had led separate efforts to disrupt the hacking infrastructure of TrickBot, a massive army of zombified computers. The fear was that the botnet could be used to carry out ransomware attacks afflicting the November elections. This week’s two operations might be more promising […]

The post Emotet, NetWalker and TrickBot have taken big blows, but will it be enough? appeared first on CyberScoop.

Continue reading Emotet, NetWalker and TrickBot have taken big blows, but will it be enough?

Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau

Government auditors concluded in a withering, deadpan report Thursday that the State Department should have used “data and evidence to justify its proposal” to establish a new cyber-focused bureau. Just before the Trump administration wound down, the State Department said it would create a Bureau of Cyberspace Security and Emerging Technologies, drawing fire from the chairman of the House Foreign Affairs Committee, Rep. Gregory Meeks, D-N.Y., who said he agreed that State needed a cyber bureau but that its last-minute proposal was “ill-suited” for the job. The Government Accountability Office reviewed the Jan. 7 proposal, and found that State “has not demonstrated that it used data and evidence to support its proposal, particularly for the bureau’s focus and organizational placement.” “Without developing evidence to support its proposal for the new bureau, State lacks needed assurance that the proposal will effectively set priorities and allocate appropriate resources for the bureau to […]

The post Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau appeared first on CyberScoop.

Continue reading Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau

For Microsoft, cybersecurity has become bigger than business

Since the cybersecurity firm FireEye hired Microsoft to help investigate a hack at the federal contractor SolarWinds, Microsoft has helped clean up the mess, alerted victims and distributed other details meant to fend off alleged Russian spies. Microsoft did all of that as it wrestled with its own probe of how hackers infiltrated its systems. Yet the company’s role in the SolarWinds investigation, while significant, represents a fraction of the cybersecurity-focused work Microsoft has done in recent years, including some behind the scenes and some in globe-spanning public relations campaigns. Once viewed as a traditional tech behemoth, Microsoft has evolved into a firm that fights cybersecurity battles in court, in election administration, in the international sphere, in the marketplace and elsewhere. The entirety of that perspective gives Microsoft a unique — if imperfect — place in the cybersecurity universe. The size of the company, and its level of visibility into […]

The post For Microsoft, cybersecurity has become bigger than business appeared first on CyberScoop.

Continue reading For Microsoft, cybersecurity has become bigger than business

NetWalker ransomware investigation yields arrest, big cryptocurrency seizure

In a coordinated, multi-part offensive against NetWalker ransomware attackers, law enforcement agencies announced Wednesday that they charged a Canadian national, seized nearly half a million dollars in cryptocurrency and disabled a dark web leak site. The NetWalker attackers have been part of a growing ransomware trend where the hackers hold stolen data hostage, leak a sample of it and threaten to release the rest in order to incentivize victims into paying. They’ve been gone after everyone from government agencies to hospitals to schools, and haven’t shied from exploiting the COVID-19 crisis. They’ve also sought to expand profits by offering their ransomware as a service to other cybercriminals, leading to reports of booming revenue in 2020. The number of overall ransomware attacks increased by 311% in 2020, according to recent research by Chainalysis, a cryptocurrency tracking firm. The charges against Sebastien Vachon-Desjardins, as well as the seizure of approximately $454,530.19 in […]

The post NetWalker ransomware investigation yields arrest, big cryptocurrency seizure appeared first on CyberScoop.

Continue reading NetWalker ransomware investigation yields arrest, big cryptocurrency seizure

Home security technician pleads guilty to spying on women, couples

A former ADT home security technician pleaded guilty on Thursday to logging into customers’ video feeds to watch naked women and couples having sex. Telesfloro Aviles faces up to five years in prison. Aviles’ Dallas-area snooping stretched over nearly five years and involved him accessing approximately 200 customer accounts more than 9,600 times, he admitted. “This defendant, entrusted with safeguarding customers’ homes, instead intruded on their most intimate moments,” said the acting U.S. Attorney for the Northern District of Texas, Prerak Shah. “We are glad to hold him accountable for this disgusting betrayal of trust.” ADT still faces civil suits over an incident it first disclosed in April, 2020. Aviles would gain improper access by claiming he needed to temporarily add himself to customers’ “ADT Pulse” accounts to conduct system tests. Other times he would add himself without permission, according to federal prosecutors. ADT says it fired Aviles after discovering […]

The post Home security technician pleads guilty to spying on women, couples appeared first on CyberScoop.

Continue reading Home security technician pleads guilty to spying on women, couples

Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig

Michael Sulmeyer, a senior adviser to National Security Agency and U.S. Cyber Command leader Gen. Paul Nakasone, will take the position of senior director for cyber in the Biden White House. Sulmeyer’s selection came with no formal announcement. Instead, the transition website posted his position Monday evening. Sulmeyer is a cybersecurity veteran with broad experience, one of many to join the Biden administration. He’s also one of several whose tenures have included roles in the Trump administration. Beyond serving under Nakasone, he also served in the Obama administration at the Defense Department, where he was director for plans and operations for cyber policy. Between roles in the Trump and Obama administrations, he was director of the Belfer Center’s Cyber Security Project at the Harvard Kennedy School. He also wrote extensively for Lawfare on subjects like election security, federal cybersecurity strategy and DOD-related cybersecurity issues. In the past, the National Security […]

The post Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig appeared first on CyberScoop.

Continue reading Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig

CISA tells agencies to consider ad blockers to fend off ‘malvertising’

The U.S. Cybersecurity and Infrastructure Security Agency urged federal agencies on Thursday to deploy ad-blocking software and standardize web browser usage across their workforces in order to fend off advertisements implanted with malware. “With many agencies greatly expanding telework options, agencies should increase attention on securing federal endpoints, including associated web browsing capabilities,” the Department of Homeland Security’s cyber arm said in a guide for agencies. With the alert, CISA joins the National Security Agency, which in 2018 likewise urged agencies to adopt ad blockers in response to the threat from “malvertising” that can spread malware. However, CISA cautioned that ad blockers aren’t a cure-all for the issue of malicious adversiting which in recent months has plagued TikTok and a slew of industries during the coronavirus. “Some browser extensions are known to accept payment from advertisers to ensure their ads are allowlisted from blocking,” the agency said, citing concerns that […]

The post CISA tells agencies to consider ad blockers to fend off ‘malvertising’ appeared first on CyberScoop.

Continue reading CISA tells agencies to consider ad blockers to fend off ‘malvertising’