DHS’s top cyber office is about to get a name that reflects its mission

The point office on cybersecurity in the Department of Homeland Security is on track for a rebrand. The Senate on Wednesday passed the Cybersecurity and Infrastructure Security Agency Act, which would both codify the office into law and give it a more relevant name. Under the bill, DHS’s National Protection and Programs Directorate (NPPD) would become the Cybersecurity and Infrastructure Security Agency (CISA). DHS established the NPPD in 2007; the legislation is essentially Congress’ official seal of approval. The House is expected to hold a final vote soon, sending the bill to President Donald Trump. NPPD leads the U.S. government’s efforts to secure federal networks and critical infrastructure. The office has also been spearheading the federal government’s election security efforts since the threats that became apparent in 2016. The office coordinates with state and local election offices on information sharing and cybersecurity best practices. “It is ridiculous that DHS needs an act of […]

The post DHS’s top cyber office is about to get a name that reflects its mission appeared first on Cyberscoop.

Continue reading DHS’s top cyber office is about to get a name that reflects its mission

Microsoft: Russians targeted conservative think tanks, U.S. Senate

The Russian intelligence office that breached the Democratic National Committee in 2016 has spoofed websites associated with the U.S. Senate and conservative think tanks in a further attempt to sow discord, according to new research from Microsoft. The tech giant last week executed a court order and shut down six internet domains set up by the Kremlin-linked hacking group known as Fancy Bear or APT 28, Microsoft President Brad Smith said. “We have now used this approach 12 times in two years to shut down 84 fake websites associated with this group,” Smith wrote in a blog post. “We’re concerned that these and other attempts pose security threats to a broadening array of groups connected with both American political parties in the run-up to the 2018 elections.” The domains were constructed to look like they belonged to the Hudson Institute and International Republican Institute, but were in fact phishing websites […]

The post Microsoft: Russians targeted conservative think tanks, U.S. Senate appeared first on Cyberscoop.

Continue reading Microsoft: Russians targeted conservative think tanks, U.S. Senate

Trump chairs election-security meeting as Democrats call for strategy

President Donald Trump chaired an election-security meeting Friday afternoon with his top advisers as Democrats called on the White House to delineate a clear strategy to counter foreign attempts to meddle in the U.S. electoral process. The National Security Council meeting “addressed threats posed to our elections from malign foreign actors, efforts underway to provide cybersecurity assistance to state and local authorities, and actions to investigate, prosecute, and hold accountable those who illegally attempt to interfere in our political and electoral processes,” White House Press Secretary Sarah Huckabee Sanders said in a statement. Director of National Intelligence Dan Coats, National Security Agency Director Paul Nakasone, CIA Director Gina Haspel and FBI Director Christopher Wray were among the officials at the meeting, according to the White House. “The president has made it clear that his administration will not tolerate foreign interference in our elections from any nation-state or other malicious actors,” Sanders […]

The post Trump chairs election-security meeting as Democrats call for strategy appeared first on Cyberscoop.

Continue reading Trump chairs election-security meeting as Democrats call for strategy

Russian hackers targeted 2018 reelection campaign of vulnerable Democrat

The same outfit of Russian hackers that launched cyberattacks against U.S. targets in the 2016 presidential election appears to have targeted Sen. Claire McCaskill, a critic of Moscow and red-state Democrat who faces a tough reelection bid. The news, first reported by the Daily Beast, makes the Missouri senator the first to be named in 2018 as a target of Russian hackers. There are at least two others. Last week, Microsoft executive Tom Burt said that earlier this year, hackers associated with the GRU, the Russian intelligence agency behind cyberattacks and disinformation campaigns during the 2016 presidential election, used spearphishing and fake Microsoft domains to target three candidates in the 2018 midterm elections. Burt said that the unnamed candidates “might have been interesting targets from an espionage standpoint as well as from an election standpoint.” McCaskill fits the bill on both counts. She serves as the ranking Democrat on the Homeland Security and Government […]

The post Russian hackers targeted 2018 reelection campaign of vulnerable Democrat appeared first on Cyberscoop.

Continue reading Russian hackers targeted 2018 reelection campaign of vulnerable Democrat

White House floats law to shore up agencies’ digital supply chain

The Trump administration is proposing a law to tighten up the security of computer systems that the federal government buys and uses. Thursday, the White House publicly released the draft of legislation it had sent to Capitol Hill two days earlier. The proposal would shore up supply-chain cybersecurity for civilian federal agencies, which is currently being considered in piecemeal fashion across multiple different bills in the House and Senate. The news was first reported by Inside Cybersecurity. The White House’s proposal, titled “Federal Information Technology Supply Chain Risk Management Improvement Act of 2018,” would create two bodies – a Federal IT Acquisition Security Council and a Critical IT Supply Chain Risk Evaluation Board – that offer agencies advice and guidance on how to cut down on supply chain security risks when procuring their technology. If passed, the bill would give civilian agencies more authorities and tools to mitigate supply chain […]

The post White House floats law to shore up agencies’ digital supply chain appeared first on Cyberscoop.

Continue reading White House floats law to shore up agencies’ digital supply chain

Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama

A new bipartisan Senate bill would try to get to the bottom of supply chain risks by setting up a new federal acquisition council that would include representation from the intelligence community and Defense Department. The goal of the bill is to help streamline coordination between agencies so that the government can avoid buying technology that’s bugged by foreign spies. The “Federal Acquisition Supply Chain Security Act” was introduced Tuesday by Sens. James Lankford, R-Okla., and Claire McCaskill, D-Mo. It tasks agencies across the government with creating a strategy to tackle supply chain threats embedded in federally procured technology systems. If a malicious piece of equipment enters the supply chain of government agencies, experts say it could be used for espionage or more destructive purposes. The announcement comes after a year in which top officials have repeatedly grappled with national security concerns surrounding Moscow-based Kaspersky Lab, an anti-virus software maker that […]

The post Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama appeared first on Cyberscoop.

Continue reading Senate bill hopes to sort out supply-chain cybersecurity risks, prevent next Kaspersky drama

‘Aggressive posture’ defines election security work, DHS official tells senators

A senior Department of Homeland Security official on Tuesday defended its work to help secure voting systems before midterm elections, but a top Democratic lawmaker worried those efforts were insufficient. DHS has “adopted an aggressive posture” to help state officials secure their voting infrastructure and will do all it can ahead of Election Day, DHS’s Jeanette Manfra told the Senate Homeland Security and Governmental Affairs Committee. At the same time, she said, the department has yet to detect Russian cyber-activity on state systems this election season. DHS will use the $26 million in additional election-security funding provided by the March omnibus to increase vulnerability assessments and other services it offers states, Manfra told CyberScoop after the hearing. That money is separate from the $380 million the bill allocated directly to individual states to do things like upgrade their computer systems and train officials in cybersecurity. But Sen. Claire McCaskill, D-Mo., the committee’s […]

The post ‘Aggressive posture’ defines election security work, DHS official tells senators appeared first on Cyberscoop.

Continue reading ‘Aggressive posture’ defines election security work, DHS official tells senators

Senate panel gives go-ahead to bill that would hit reset on DHS

Congress is moving forward with a plan to reauthorize the Department of Homeland Security for the first time since its 2002 creation and establish a permanent, dedicated cyber office within the agency. The Senate Committee on Homeland Security and Government Affairs approved the legislation Wednesday. The current bill is a version of what the House passed in July. If it passes in the full Senate, it would still need to see action in the House, even though that side of Congress already passed two attempts to reauthorize DHS last year. The Senate bill would reorganize DHS’s National Protection and Programs Directorate into a dedicated cyber agency, called the Cybersecurity and Infrastructure Security Agency. NPPD was established in 2007 by DHS and therefore isn’t officially deputized by Congress. The new office would be headed by an department undersecretary. “Passing the Department of Homeland Security Authorization Act is an important step to strengthen DHS and to establish a process […]

The post Senate panel gives go-ahead to bill that would hit reset on DHS appeared first on Cyberscoop.

Continue reading Senate panel gives go-ahead to bill that would hit reset on DHS

Lawmakers fret over proposed budget cuts to some DHS cyber programs

During two days of hearings on Capitol Hill, lawmakers generally said they were pleased so far with Homeland Security Secretary John Kelly, but several from both parties expressed concern about the impact of budget cuts on some DHS cybersecurity programs — and Kelly indicated the cuts weren’t final. Proposed cuts to the department’s Science and Technology Directorate and the planned closure of a cybercrime training college for state and local law enforcement and prosecutors were highlighted by Republican congressmen Wednesday, while Democratic Sen. Claire McCaskill of Missouri complained Tuesday about the proposed reduction of grant programs that helped fund port and airport security. “Why have you cut the science and technology budget … by 20 percent?” asked Rep. John Rutherford, R-Fla., noting that the budget reductions would cause several of the department’s research laboratories and centers of scientific excellence to close. Kelly hedged. “This is obviously a work in progress, congressman,” he […]

The post Lawmakers fret over proposed budget cuts to some DHS cyber programs appeared first on Cyberscoop.

Continue reading Lawmakers fret over proposed budget cuts to some DHS cyber programs