CISA’s Krebs: Request for border volunteers won’t have operational impact on agency

A call for volunteers to help at the U.S.-Mexico border will not have an impact on the Department of Homeland Security’s Cybersecurity and Infrastructure Agency’s (CISA) operational activities, the agency’s director said Wednesday. “We will ensure that we don’t have operational impact,” particularly on top priority items like election security, CISA Director Chris Krebs said after remarks at a conference hosted by the Georgetown University Law Center. Ten CISA employees that have volunteered are already at the border, and another 10 will soon join them, Krebs told members of the House Oversight and Reform subcommittee. Only one or two of the volunteers who have deployed actually focus on cybersecurity, Krebs told reporters after the hearing. CISA as a whole has roughly 3,500 employees, according to a November estimate. Last week, CISA Deputy Director Matt Travis emailed employees asking them to consider volunteering for 30 to 45 days at the border in response […]

The post CISA’s Krebs: Request for border volunteers won’t have operational impact on agency appeared first on CyberScoop.

Continue reading CISA’s Krebs: Request for border volunteers won’t have operational impact on agency

White House executive order sets path for ban on Huawei

President Donald Trump issued an executive order Wednesday that is intended to prevent U.S. companies from using telecommunications technology made by firms that are beholden to foreign adversaries. The goal of the order is to protect the security, economy, and critical infrastructure of the U.S., a senior administration official told reporters Wednesday. The intent is to prevent economic and industrial espionage, especially those activities that pose “undue risk of sabotage” through technologies that are “owned by, controlled by, or subject to the jurisdiction or direction” of foreign adversaries. Although the order, which invokes the International Emergency Economic Powers Act and the National Emergencies Act, does not name any country or company in particular, the order is thought to impinge on business with China-based Huawei. The order comes as tension has risen over the U.S.-China trade war. Earlier this week, the Chinese government said it will impose tariffs on $60 billion worth of U.S. […]

The post White House executive order sets path for ban on Huawei appeared first on CyberScoop.

Continue reading White House executive order sets path for ban on Huawei

DHS official sounds alarm on authoritarian states ‘operationalizing their tech sectors’

The willingness of authoritarian governments to leverage native tech companies to achieve their national goals has forced U.S. officials to adapt in how they view risk from those companies, according to a senior Department of Homeland Security official. “Our focus is not on the country of origin, or the company, but it’s about what is the rule of law under which that product is potentially subject to,” Chris Krebs, head of DHS’s Cybersecurity and Infrastructure Security Agency, said Thursday at the Cybersecurity Leadership Forum presented by Forcepoint and produced by CyberScoop and FedScoop. The problem lies with foreign tech companies that are subject to government demands without the visibility or appeal process that exists in the United States, he said. “It’s the rise of authoritarian states and how they’re operationalizing their tech sectors,” Krebs said, summing up how U.S. officials view products made by Chinese telecommunications giant Huawei and Russian […]

The post DHS official sounds alarm on authoritarian states ‘operationalizing their tech sectors’ appeared first on CyberScoop.

Continue reading DHS official sounds alarm on authoritarian states ‘operationalizing their tech sectors’

DHS officials plan Europe trip to brief allies on election security, gather intel for 2020

Department of Homeland Security officials plan to visit European allies to share lessons learned from defending the 2018 U.S. midterm elections, a top DHS official said Tuesday. “What we’re doing is taking some of the ’16 and ’18 lessons learned, packaging them together, and then doing a bit of a roadshow,” Chris Krebs, head of DHS’s Cybersecurity and Infrastructure Security Agency, told reporters. Details of the trip are still being finalized, but Krebs said it also would offer CISA officials an update from the field on adversary activity ahead of the 2020 U.S. presidential election. Many millions of Europeans are expected to head to the polls in late May to choose new representatives in the European Union parliament. European officials have issued a series of warnings that Russia is likely to interfere in the vote, including an assessment last week from Estonia’s foreign intelligence agency. In another key election, Ukrainians will choose a […]

The post DHS officials plan Europe trip to brief allies on election security, gather intel for 2020 appeared first on CyberScoop.

Continue reading DHS officials plan Europe trip to brief allies on election security, gather intel for 2020

No ‘smoking gun’ evidence coming on Huawei, NSA official says

Don’t expect U.S. officials to produce a “smoking gun” of public evidence that the Chinese government might be using telecommunications giant Huawei to further its interests in cyberspace, a senior National Security Agency official told CyberScoop. “Everybody is anxious for that smoking gun,” Rob Joyce, senior cybersecurity adviser at NSA, said in an interview. “It is not the case that you’re going to see people bring out and drop that smoking gun on the table … for all sorts of reasons about the way we understand the threat, the way we deal with the Chinese, the way we have to protect the ability to see and maybe defeat or deny that capability going forward.” U.S. officials have long accused Chinese tech companies Huawei and ZTE of being potential vessels for spying. One reason is that under Chinese law, companies are required to cooperate with national intelligence activities. Huawei and ZTE strenuously […]

The post No ‘smoking gun’ evidence coming on Huawei, NSA official says appeared first on CyberScoop.

Continue reading No ‘smoking gun’ evidence coming on Huawei, NSA official says

Democrats ask Trump administration to publish 2018 election security report

Democratic lawmakers are calling on the Trump administration to release a public report on efforts to secure the 2018 midterm elections so the country can learn what worked and what didn’t. “It’s important for the public to have confidence in our election systems,” Rep. Jim Langevin, D-R.I., told CyberScoop Wednesday. “In order to have confidence, I think there has to be transparency.” The departments of Homeland Security and Justice on Feb. 4 sent a classified report to President Donald Trump assessing foreign attempts to interfere in the 2018 midterms. Officials found no evidence that foreign operatives had a “material impact on the integrity or security” of election or campaign infrastructure used in the midterms, according to a statement summarizing the report. That terse statement is insufficient for lawmakers like Langevin. In the interest of transparency and making improvements, they say, the administration should publish an assessment of security in the […]

The post Democrats ask Trump administration to publish 2018 election security report appeared first on CyberScoop.

Continue reading Democrats ask Trump administration to publish 2018 election security report

Foreign VPN apps need a close look from DHS, senators say

The Department of Homeland Security should assess the security threat posed by foreign VPN applications to U.S. government employees, a bipartisan pair of senators says. Some popular VPN apps send a phone’s web-browsing data to servers in countries interested in targeting federal personnel, raising “the risk that user data will be surveilled by those foreign governments,” Sens. Marco Rubio, R-Fla., and Ron Wyden, D-Ore., wrote in a letter to DHS Thursday. VPN providers promise to obfuscate the physical location of a web browser, but users are generally at the mercy of those companies’ decisions to collect and log data. The senators cite government warnings about products made by Chinese telecommunications companies and Russian antivirus vendor Kaspersky Lab as examples of the surveillance that certain foreign technology can enable. (Kaspersky and Chinese companies Huawei and ZTE have denied those allegations.) “If U.S. intelligence experts believe Beijing and Moscow are leveraging Chinese and Russian-made technology to surveil Americans, […]

The post Foreign VPN apps need a close look from DHS, senators say appeared first on CyberScoop.

Continue reading Foreign VPN apps need a close look from DHS, senators say

DHS briefs industry on shift in Chinese hacking that ‘increases the risk for all of us’

U.S. officials on Wednesday continued to warn industry about the threat posed by Chinese government-backed hackers by detailing how those teams have evolved and urging companies to better secure IT services that can be an avenue for stealing proprietary data. “Their strategies have shifted from labor-intensive, one-off compromises of individual targets to the use of the force-multiplier effects that enable them to compromise multiple targets through a single attack,” Rex Booth, a Department of Homeland Security cyber official, said during a webinar presentation to the private sector. “That shift in strategies increases the risk for all of us.” The public webinar focused on APT10, a group tied to China’s civilian intelligence agency, the Ministry of State Security. Analysts say the MSS has supplanted the People’s Liberation Army to become Beijing’s preferred arm for conducting economic espionage. U.S. officials and security researchers say APT10 has targeted the “managed service providers” that […]

The post DHS briefs industry on shift in Chinese hacking that ‘increases the risk for all of us’ appeared first on CyberScoop.

Continue reading DHS briefs industry on shift in Chinese hacking that ‘increases the risk for all of us’

Shutdown erodes feds’ ability to set cyber strategies, say lawmaker and ex-DHS officials

A top House lawmaker, along with former Department of Homeland Security officials, say the partial government shutdown is hampering federal officials’ ability to anticipate and proactively address cyberthreats. “We can kind of address things as they come, but we can’t look forward and do additional mitigation and other kinds of things that we normally do,” Rep. Bennie Thompson, D-Miss., told reporters Thursday at an event on Capitol Hill on the security implications of the shutdown. “So if somebody tells us about something or we identify it, we can go after it,” added Thompson, who is chairman of the Homeland Security Committee. “But we can’t plan for the next month or the next three months because we don’t have the capacity to do it with the shutdown.” Former DHS officials agreed that the partial shutdown, which began Dec. 22 and has 800,000 workers across all agencies furloughed or working without pay, […]

The post Shutdown erodes feds’ ability to set cyber strategies, say lawmaker and ex-DHS officials appeared first on CyberScoop.

Continue reading Shutdown erodes feds’ ability to set cyber strategies, say lawmaker and ex-DHS officials

DHS’s cybersecurity office is a presidential signature away from a new name

The House of Representatives unanimously passed a bill Tuesday that would codify the Department of Homeland Security’s National Protection and Programs Directorate into law and give it a more relevant name. The CISA Act, which passed the Senate in October and now heads to President Donald Trump’s desk to be signed into law, would now brand the office as the Cybersecurity and Infrastructure Security Agency. The National Protection and Programs Directorate (NPPD) is currently the point office responsible for securing federal networks and safeguarding critical infrastructure from cyberthreats. “[Tuesday’s] vote is a significant step to stand up a federal government cybersecurity agency,” said Secretary Kirstjen M. Nielsen. “The cyber threat landscape is constantly evolving, and we need to ensure we’re properly positioned to defend America’s infrastructure from threats digital and physical. It was time to reorganize and operationalize NPPD into the Cybersecurity and Infrastructure Security Agency.” Chris Krebs, currently the DHS […]

The post DHS’s cybersecurity office is a presidential signature away from a new name appeared first on Cyberscoop.

Continue reading DHS’s cybersecurity office is a presidential signature away from a new name