U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

Communications at the U.S. Treasury and Commerce Departments were reportedly compromised by a supply chain attack on SolarWinds, a security vendor that helps the federal government and a range of Fortune 500 companies monitor the health of their IT networks. Given the breadth of the company’s customer base, experts say the incident may be just the first of many such disclosures. Continue reading U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

Commerce Bureau Pegs More National Security Risks

The Department of Commerce’s U.S. Bureau of Industry and Commerce (BIC) has added 17 organizations from 11 countries to its “entity list,” citing national security concerns. Presence on the list means the organization or enterprise i… Continue reading Commerce Bureau Pegs More National Security Risks

California bill regulates IoT for first time in US

California looks set to regulate IoT devices, becoming the first US state to do so and beating the Federal Government to the post. Continue reading California bill regulates IoT for first time in US

Former U.S. officials call for transparency in cybersecurity of 2020 Census

Nearly a dozen former U.S. officials with cybersecurity and intelligence backgrounds are calling on the Census Bureau to be open about how it plans to protect the troves of sensitive information it will collect in the 2020 Census. In a letter released Monday by the Georgetown University Law Center, 11 officials write that Americans deserve to know that the systems and technical protocols the bureau is using will not put collected information at risk. “This is especially important in an age in which new types and sources of cybersecurity threats seem to emerge almost weekly,” the officials say, addressing Commerce Secretary Wilbur Ross and acting Census Bureau Director Ron Jarmin. Signatories on the letter include former White House Cybersecurity Coordinator Michael Daniel, former National Counterterrorism Center Director Matthew Olsen and other Obama administration officials. Cybersecurity is especially pertinent for the upcoming census because it will be the first to allow […]

The post Former U.S. officials call for transparency in cybersecurity of 2020 Census appeared first on Cyberscoop.

Continue reading Former U.S. officials call for transparency in cybersecurity of 2020 Census

In war against botnets, manufacturers need to step up, report says

The problem of botnets — the legions of computers used to carry out distributed denial-of-service attacks — is exacerbated by the fact that developers do not have the cost incentives to build more security into their products, according to a new report from the departments of Commerce and Homeland Security. “Product developers, manufacturers, and vendors are motivated to minimize cost and time to market, rather than to build in security or offer efficient security updates,” states the report mandated by a White House executive order last year. “Market incentives must be realigned to promote a better balance between security and convenience when developing products.” The report says the government should give companies some help by prioritizing research and development funding for botnet-thwarting products, and it suggests the private sector should expedite its own work on those technologies. The R&D — in techniques like data analytics, machine learning, and artificial intelligence is — “urgently needed to get […]

The post In war against botnets, manufacturers need to step up, report says appeared first on Cyberscoop.

Continue reading In war against botnets, manufacturers need to step up, report says

McAfee pushes government to craft improved cybersecurity game plans

In the face of malware’s growth in both category and character, government experts joined private sector leaders Thursday to formulate better ways to tackle cybersecurity challenges. During McAfee’s 2017 Security Through Innovation Summit, both sides of the public and private sector relationship talked about changes needed at every aspect of the security ecosystem, from better information sharing to more automation to a total revamp of the government acquisition process. “We as an industry have been tackling this cybersecurity problem in the fundamentally wrong way,” said Brian Dye, McAfee’s executive vice president of products, at the event hosted by CyberScoop and FedScoop. Automation was a continuing theme Thursday, promoted not only as a way to address cybersecurity workforce shortages but also improve the consistency and reliability of network defenses. A panel of government speakers drew a distinction between tasks that could be made “automatic” — where no input was required — and […]

The post McAfee pushes government to craft improved cybersecurity game plans appeared first on Cyberscoop.

Continue reading McAfee pushes government to craft improved cybersecurity game plans

Wassenaar Renegotiation Will Be in Trump Administration’s Hands

Now that a proposed revision to the Wassenaar Arrangement has been rejected, it will be up to the Trump administration to decide whether to attempt to renegotiate again. Continue reading Wassenaar Renegotiation Will Be in Trump Administration’s Hands