White House rolls out pipeline, supply chain security initiatives as companies pledge billions in cyber spending

The Biden administration on Wednesday announced initiatives to bolster supply chain and natural gas pipeline security, following a White House private sector cybersecurity summit where major companies pledged billions of dollars in cyber spending. The National Institute of Standards and Technology will collaborate with industry to develop guidelines for building secure technology, in the first of two administration initiatives. In the other, the administration formally expanded its industrial control systems cybersecurity initiative — under which 150 electric utilities agreed to deploy control system security tech — to natural gas pipelines. Tech giants, insurance companies and educational organizations exit the summit with cybersecurity commitments large and small. Among those vowing the biggest dedication of dollars: Microsoft announced $20 billion over five years to integrate “cybersecurity by design,” which means incorporating security into products as they’re being built, while Google announced $10 billion over the same period to expand “zero trust” programs, […]

The post White House rolls out pipeline, supply chain security initiatives as companies pledge billions in cyber spending appeared first on CyberScoop.

Continue reading White House rolls out pipeline, supply chain security initiatives as companies pledge billions in cyber spending

Apple, JPMorgan Chase bosses among industry heads set to gather at White House for cyber ‘call to action’

President Joe Biden will huddle Wednesday with industry leaders to issue a “call to action” on cybersecurity and make “concrete announcements” to counter the fundamental causes of cyberattacks, according to a senior administration official. It’s a star-studded afternoon gathering scheduled to include the likes of Apple CEO Tim Cook and JPMorgan Chase CEO Jamie Dimon from the financial, technology, energy, insurance and education sectors, then feature discussions led by top administration officials. The White House has been working to secure commitments from industry in advance of the meeting, mostly in the areas of “technology and talent,” the official said in a background call with reporters on Tuesday. Two points of emphasis, the official said, are building technology that is secure from the outset, and better defending critical infrastructure after the ransomware attack on Colonial Pipeline led to a fuel scare. “We need to bake in security by design into tech,” […]

The post Apple, JPMorgan Chase bosses among industry heads set to gather at White House for cyber ‘call to action’ appeared first on CyberScoop.

Continue reading Apple, JPMorgan Chase bosses among industry heads set to gather at White House for cyber ‘call to action’

Federal agencies are failing to protect sensitive data, Senate report finds

Of eight federal agencies audited for their cybersecurity programs, only the Department of Homeland Security showed improvements in 2020, according to a report from the Senate Homeland Security and Governmental Affairs Committee. Released by the panel on Tuesday, the report expresses concerns about the state of federal agencies’ cyber posture during an overall 8% rise in security incidents across agencies. The report underscores the increased scrutiny of federal cybersecurity by lawmakers in the aftermath of a months-long alleged Russian cyber-espionage campaign the private sector first uncovered uncovered in December 2020. Russian hackers used a flaw in network management software SolarWinds to infiltrate nine government agencies. The report found that seven of the eight agencies reviewed still use legacy systems that no longer have security updates supported by their vendor. The practice can leave agencies vulnerable to foreign hacking, the report notes. “It is clear that the data entrusted to these […]

The post Federal agencies are failing to protect sensitive data, Senate report finds appeared first on CyberScoop.

Continue reading Federal agencies are failing to protect sensitive data, Senate report finds

Biden says ‘shooting war’ could break out with foreign heavyweights over cyberattacks

The U.S. is “more likely” to end up in a “real shooting war with a major power” over a cyber incident than other kinds of conflict, President Joe Biden suggested on Tuesday. “We’ve seen how cyber threats, including ransomware attacks, increasingly are able to cause damage and disruption to the real world,” he said at a speech at the Office of the Director of National Intelligence’s National Counterterrorism Center in McLean, Virginia. “And it’s increasing exponentially — the capabilities.” While Biden delivered his speech before intelligence personnel, at least one of his intended recipients appeared to be Russian President Vladimir Putin. The Biden administration has been talking tough about Russia providing safe haven for ransomware gangs believed to be responsible for headline-making attacks on Colonial Pipeline, JBS and Kaseya. Biden has pressed that message to Putin directly as recently as July. Russia has rejected U.S. suggestions of wrongdoing. “I can’t […]

The post Biden says ‘shooting war’ could break out with foreign heavyweights over cyberattacks appeared first on CyberScoop.

Continue reading Biden says ‘shooting war’ could break out with foreign heavyweights over cyberattacks

Biden says he gave Putin list of 16 sectors that should be off limits to hacking

President Joe Biden said he gave Russian President Vladimir Putin a list of 16 critical infrastructure sectors, from energy to water, that should not be the subject of malicious cyber activity during a meeting between the two men in Geneva on Wednesday. The two heads of state also agreed to task cybersecurity experts from each government “to work on specific understandings about what’s off limits and to follow up on specific [cyber incidents] that originate in either of our countries,” Biden said at press conference after a roughly four-hour meeting with Putin. “I talked about the proposition that certain critical infrastructure should be off limits to attack, period, by cyber or any other means,” Biden said. It was not immediately clear if the list of critical infrastructure sectors that Biden referenced corresponds with the 16 sectors designated by the U.S. government. A White House spokesperson did not immediately respond to […]

The post Biden says he gave Putin list of 16 sectors that should be off limits to hacking appeared first on CyberScoop.

Continue reading Biden says he gave Putin list of 16 sectors that should be off limits to hacking

DOJ didn’t ask for Russia’s help tracking down Colonial Pipeline hackers, senior official says

The U.S. Justice Department did not ask Russian law enforcement for help in tracking down the perpetrators of the Colonial Pipeline ransomware attack because Moscow’s history of harboring cybercriminals essentially makes it a waste of time, according to a senior department official. “I think we’ve reached the stage, today, where there’s very little point in doing so,” said John Demers, the assistant attorney general for national security. “We have made those requests in the past.” The Russian government is “not just tolerating this,” Demers said at CyberTalks, presented by CyberScoop. “They’re actively getting in the way of U.S. law enforcement efforts to combat this type of hacking,” he added, referring to previous Russian efforts to block U.S. requests to extradite accused hackers from other countries. The remarks were pre-recorded on June 3. The Justice Department did not answer follow-up questions about possible Russian cooperation in the weeks since. The Russian […]

The post DOJ didn’t ask for Russia’s help tracking down Colonial Pipeline hackers, senior official says appeared first on CyberScoop.

Continue reading DOJ didn’t ask for Russia’s help tracking down Colonial Pipeline hackers, senior official says

Biden, Putin conduct diplomatic dance over hypothetical hacker exchange

A discussion over an exchange of accused hackers from Russia and the U.S. could be on the agenda this week when President Joe Biden meets with his Russian counterpart on the shores of Lake Geneva in Switzerland. Vladimir Putin, in an interview with Russian state media Sunday, said his government would consider the possibility of extraditing accused hackers from Russia to America under the condition that the U.S. would do the same. During a news conference at a Group of Seven (G7) summit, Biden said he would be “open” to the idea of holding accused hackers in the U.S. accountable for violating the law. The two world leaders are scheduled to meet on Wednesday amid a spate of high profile ransomware attacks in which alleged Russian-based hacking gangs disrupted operations at Colonial Pipeline, a U.S. fuel carrier, and the meat processing firm JBS. “If there’s crimes committed against Russia that, […]

The post Biden, Putin conduct diplomatic dance over hypothetical hacker exchange appeared first on CyberScoop.

Continue reading Biden, Putin conduct diplomatic dance over hypothetical hacker exchange

Biden revokes TikTok ban, issues new guidance for evaluating foreign apps

President Joe Biden on Wednesday issued an executive order that overturns Trump-era efforts to ban Chinese applications TikTok and WeChat while offering new guidelines for federal agencies to assess the national security risks of such software. The order emphasizes additional criteria for the Commerce Department to use in assessing whether to restrict U.S. use of foreign software apps. Those criteria include whether the technology is connected to foreign military or intelligence agencies, or involved in malicious cyber activity or the collection of sensitive personal data. The order is a reprieve for TikTok, a popular video-sharing app owned by Beijing-based firm ByteDance. Then-President Donald Trump issued an order that sought to ban U.S. companies from providing internet and content delivery services to TikTok, citing concerns that Chinese spies could exploit that data. But implementation of that order has been held up by legal challenges waged by TikTok, which has denied improper […]

The post Biden revokes TikTok ban, issues new guidance for evaluating foreign apps appeared first on CyberScoop.

Continue reading Biden revokes TikTok ban, issues new guidance for evaluating foreign apps

Chinese hackers implicated in breach of Russian government agencies

Chinese hackers were likely behind a series of intrusions at Russian government agencies last year, security firm SentinelOne said Tuesday. Malicious code used in the breaches is similar to hacking tools associated with a broad set of suspected Chinese spies that have also targeted Asian governments in recent years, SentinelOne researchers said. SentinelOne’s research builds on a report released last month by the Federal Security Service (FSB), one of Russia’s main spy agencies, and the cyber unit of telecom firm Rostelecom. It said Russian government agencies had been targeted by “cyber mercenaries pursuing the interests of the foreign state.” The attackers collected stolen data using top Russian technology providers Yandex and Mail.Ru, according to the report, which did not name a culprit in the breaches. SentinelOne’s findings point to an often overlooked reality in U.S.-centric cybersecurity discussions: that the Russian and Chinese governments conduct plenty of cyber-espionage against each other. Last […]

The post Chinese hackers implicated in breach of Russian government agencies appeared first on CyberScoop.

Continue reading Chinese hackers implicated in breach of Russian government agencies

Meat chain JBS says US production is returning after ransomware attack

The U.S. division of JBS, which accounts for an estimated one-fifth of the country’s beef production, said it expects the “vast majority” of its meat plants to be operational on Wednesday after a ransomware attack ground work to a halt. “Our systems are coming back online and we are not sparing any resources to fight this threat,” JBS USA CEO Andre Nogueira said in a statement Tuesday evening. The breach at JBS, the world’s largest meat supplier, has caused disruptions to the company’s facilities in Colorado, to Canada and Australia. Workers were sent home from some plants in an industry that has already faced disruptions because of the coronavirus pandemic. Nogueira said that JBS USA and Pilgrim’s, one of the company’s brands, were able to ship product from nearly all facilities in the U.S. on Tuesday. “The company also continues to make progress in resuming plant operations in the U.S. […]

The post Meat chain JBS says US production is returning after ransomware attack appeared first on CyberScoop.

Continue reading Meat chain JBS says US production is returning after ransomware attack