Trump signed the NDAA today. Here’s what it means for cybersecurity.

President Donald Trump signed the $700 billion National Defense Authorization Act (NDAA) on Tuesday, a law that sets policies and budget guidelines for the U.S. military for fiscal 2018, including its various cybersecurity-focused initiatives. The mammoth piece of annual legislation often includes brand-new projects and policy provisions. This year’s NDAA advances several important cybersecurity efforts while also establishing new rules and programs related to information security. Here’s a closer look at some key cybersecurity provisions: The ban on Kaspersky Lab software becomes official (SEC. 1634) While the Homeland Security Department has already taken concrete steps to push Kaspersky Lab products out of the federal government, Sec. 1634 makes the ban official across the Defense Department and sets a deadline of October 2018 for total removal. The ban specifically mentions any and all products owned by Kaspersky Lab, including both services and software produced by subsidiaries. Trump will define what “cyberwar” means (SEC. 1633) The […]

The post Trump signed the NDAA today. Here’s what it means for cybersecurity. appeared first on Cyberscoop.

Continue reading Trump signed the NDAA today. Here’s what it means for cybersecurity.

Lawmakers demand answers from Uber after massive data breach

Five U.S. senators sent letters to Uber Monday, pressing the company’s leadership for information on a data breach affecting millions of its consumers and the subsequent attempt to cover up the incident. The breach — which took place in October 2016 — provided hackers with the names and driver’s license numbers of roughly 600,000 drivers as well as the personal phone numbers and email addresses of 57 million riders. Instead of disclosing the breach, Uber paid a fee of $100,000 to the hackers, asking them to delete the stolen data. A letter co-authored by Sens. John Thune, R-S.D., Orrin Hatch, R-Utah, Jerry Moran, R-Kansas, and Bill Cassidy, R-La., presented a series of questions to Uber’s CEO, Dara Khosrowshahi, regarding the company’s past conduct and its plans to protect user data in the future. “Our goal is to understand what steps Uber has taken to investigate what occurred, restore and maintain the […]

The post Lawmakers demand answers from Uber after massive data breach appeared first on Cyberscoop.

Continue reading Lawmakers demand answers from Uber after massive data breach

Senators urged to question DHS nominee Nielsen’s management experience

Senators of both parties were tight-lipped Tuesday about their plans for Homeland Security Secretary nominee Kirstjen Nielsen’s confirmation hearing — but there’s one topic many observers are hoping they’ll ask about: Her experience. The issue of leadership is key one for the department — a sprawling government behemoth which encompasses two of the largest federal law enforcement agencies and is responsible for a bewildering variety of missions. In particular, observers say, its cyber mission has been handicapped by the absence of an operational agency responsible for securing government computer networks and helping vital U.S. businesses harden their IT systems against online attacks. Nielsen’s defenders point to a career in emergency preparedness, first as a junior White House official and later as a consultant and think-tank fellow, culminating in her brief stint this year as chief of staff at DHS under then-Secretary John Kelly. But critics point out that, until this year, she’d never managed […]

The post Senators urged to question DHS nominee Nielsen’s management experience appeared first on Cyberscoop.

Continue reading Senators urged to question DHS nominee Nielsen’s management experience

‘Sherpa’ leading Nielsen DHS confirmation effort is lobbyist tied to agency contractors

A former lobbyist representing companies with business before the Department of Homeland Security is leading the confirmation preparation for DHS secretary nominee Kirstjen Nielsen, assigning government staffers to prepare policy memos and coordinating her paperwork submissions to the Senate  — an unprecedented role that’s causing consternation among some administration officials. “I’ve never seen someone from outside the government play that role,” said one senior official, who was granted anonymity since they were not authorized to talk to the press. “It’s shocking that someone with business before the department would be in that role.” “That is highly unusual,” agreed Chris Lu, a former Senate-confirmed official at the Department of Labor who is now a senior fellow at Virginia University’s Miller Center for Public Affairs. “Has this been cleared by the DHS ethics counsel?” Lu asked. “What procedures were followed to ensure that he doesn’t get access to non-public information that might benefit his clients?” Thad Bingel, a consultant with the Command Group, […]

The post ‘Sherpa’ leading Nielsen DHS confirmation effort is lobbyist tied to agency contractors appeared first on Cyberscoop.

Continue reading ‘Sherpa’ leading Nielsen DHS confirmation effort is lobbyist tied to agency contractors

Wyden demands answers from telecom giants, NSA over SS7 vulnerabilities

Democratic Sen. Ron Wyden is demanding to know how America’s largest telecommunications companies plan to stop hackers from exploiting vulnerabilities in an outdated mobile-data transfer framework that remains fundamental to how cellphones function. Wyden sent a series of letters Thursday to the chief executives of AT&T, Sprint, Verizon and T-Mobile to learn about their efforts to mitigate risks associated with weak points in Signaling System No 7, or SS7, a set of protocols that allow for different mobile phone networks to connect to one another. In addition, the Oregon senator sent a letter to the NSA director, Adm. Michael Rogers, requesting information about past attempts by adversaries to hack into SS7 for the purpose of spying on Americans, including military personnel, civilians and companies. The Daily Beast was the first to report on Wyden’s multiple letters. There are well-known security issues with SS7, including reported cases of intelligence agencies exploiting vulnerabilities in […]

The post Wyden demands answers from telecom giants, NSA over SS7 vulnerabilities appeared first on Cyberscoop.

Continue reading Wyden demands answers from telecom giants, NSA over SS7 vulnerabilities

Equifax CEO called to testify before Congress about breach

Equifax’s chief executive was formally invited Wednesday to testify Oct. 3 before Congress by top members of the House Energy and Commerce Committee. The invitation to Chairman and CEO Richard F. Smith comes less than a week after Equifax, a massive multinational credit reporting company, announced a data breach affecting up to 143 million Americans. “We look forward to hearing directly from Mr. Smith on this unprecedented breach that has raised serious questions about the security of consumers’ personal information,” full committee Chairman Greg Walden, R-Ore., and Digital Commerce and Consumer Protection Subcommittee Chairman Bob Latta, R-Ohio, said in a statement. “We know members on both sides of the aisle appreciate Mr. Smith’s willingness to come before the committee and explain how our constituents might be impacted and what steps are being taken to rectify this situation.” The committee has jurisdiction over the Federal Trade Commission and Consumer Financial Protection Bureau, two of the agencies […]

The post Equifax CEO called to testify before Congress about breach appeared first on Cyberscoop.

Continue reading Equifax CEO called to testify before Congress about breach