Biden’s Cybersecurity Executive Order, Apple’s AirTag, Cyber Insurance

Details about Biden’s cybersecurity executive order, privacy and stalking concerns with Apple’s new AirTag technology, and why some cyber insurance companies may not pay out for ransomware in the future. ** Links mentioned on the show ** New Cybersecur… Continue reading Biden’s Cybersecurity Executive Order, Apple’s AirTag, Cyber Insurance

US government plans to disrupt hackers behind Colonial Pipeline ransomware, Biden says

President Joe Biden suggested the U.S. intends to pursue hackers who last week infected the largest pipeline in the country with ransomware. The incident led Colonial Pipeline to shut down operations for days in an effort to prevent the ransomware, which the FBI has traced back to criminal operators known as DarkSide, from spreading to its operational technology. Now, following a spike in demand for fuel, the U.S. government is going to disrupt the hackers, who are believed to reside in Russia, Biden said. “We have been in direct communication with Moscow for the imperative for responsible countries to take decisive action against these ransomware networks,” Biden said in remarks Thursday. “We’re also going to pursue a measure to disrupt their ability to operate.” The president did not rule out carrying out a retaliatory cyberattack targeting the criminals, clarifying that the U.S. does not believe the Russian government was behind […]

The post US government plans to disrupt hackers behind Colonial Pipeline ransomware, Biden says appeared first on CyberScoop.

Continue reading US government plans to disrupt hackers behind Colonial Pipeline ransomware, Biden says

Biden signs security-focused executive order meant to accelerate breach reporting, boost software standards

President Joe Biden on Wednesday signed an executive order that will significantly tighten cybersecurity rules for government contractors and set up an incident review board to try to blunt the impact of major hacks. The directive comes as the U.S. government continues to grapple with the fallout from breaches at key software suppliers and the disruption of a national pipeline operator by ransomware. The executive order requires federal contractors to promptly report cyber incidents to agencies, and it establishes a new government entity modeled after the National Transportation Safety Board to review major breaches. It will also require software that the government buys to meet a baseline set of security standards — an effort to make it harder for hackers to tamper with code that ends up on federal networks. “The current market development of build, sell and maybe patch later means we routinely install software with significant vulnerabilities into […]

The post Biden signs security-focused executive order meant to accelerate breach reporting, boost software standards appeared first on CyberScoop.

Continue reading Biden signs security-focused executive order meant to accelerate breach reporting, boost software standards

White House slaps sanctions on Russian cyber activities while blaming SVR for SolarWinds campaign

The Biden administration on Thursday imposed sweeping sanctions on Russian intelligence operatives for their alleged interference in the 2020 U.S. election, and on Russian companies for allegedly supporting Moscow’s extensive cyber-espionage operations. The Treasury Department sanctioned 32 organizations and individuals for their alleged influence operations aimed at the U.S. election. The White House said it was part of an effort to “disrupt the coordinated efforts of Russian officials, proxies, and intelligence agencies to delegitimize our electoral process.” As part of the crackdown, Treasury sanctioned six Russian tech firms for allegedly providing support to Russian intelligence services’ hacking operations by developing malicious software or setting up IT infrastructure. U.S. officials also made official what had long been rumored: They believe with “high confidence” that Russia’s foreign intelligence agency, the SVR, carried out the hacking campaign that has exploited software made by contractor SolarWinds and other vendors to infiltrate nine U.S. agencies […]

The post White House slaps sanctions on Russian cyber activities while blaming SVR for SolarWinds campaign appeared first on CyberScoop.

Continue reading White House slaps sanctions on Russian cyber activities while blaming SVR for SolarWinds campaign

Biden signs executive order demanding supply chain security review

President Joe Biden signed an executive order on Wednesday directing federal agencies to conduct a review of supply chain security risks in industries including information technology. While a significant goal of the order is to address shortages of a wide assortment of critical imported components such as electric batteries and pharmaceuticals, it does include a mandated review of the information and communications technology sector. A prominent justification for the review is a desire to rely less on semiconductors manufactured overseas. Biden, at a news conference to herald his signing of the executive order, said “we need to make sure these supply chains are secure and reliable.” It’s an issue, he said, “of both concern for economic security as well as our national security.” Espionage remains a significant concern, as well, after hackers leveraged access in a federal contractor to gather sensitive from throughout the U.S. government. The supply chain danger […]

The post Biden signs executive order demanding supply chain security review appeared first on CyberScoop.

Continue reading Biden signs executive order demanding supply chain security review

Biden says US will ‘raise the cost’ for Russian hackers after espionage campaign

President Joe Biden on Thursday said the days of the U.S. “rolling over in the face of Russia’s aggressive actions” in cyberspace were over as he pledged to make the U.S. government more resilient in the face of hacking. “We’re launching an urgent initiative to improve our capability, readiness and resilience in cyberspace,” Biden said in his first major foreign policy address as president. “We’ve elevated the status of cyber issues within our government,” Biden added, citing his appointment of National Security Agency veteran Anne Neuberger as deputy national security adviser for cyber and emerging technology.   Biden has made responding to a suspected Russian hacking operation against multiple U.S. government agencies a priority in the early days of his presidency. He has tasked U.S. intelligence agencies with assessing the damage from computer intrusions in which suspected Russian attackers exploited key technology providers to breach numerous Fortune 500 firms and […]

The post Biden says US will ‘raise the cost’ for Russian hackers after espionage campaign appeared first on CyberScoop.

Continue reading Biden says US will ‘raise the cost’ for Russian hackers after espionage campaign

Amid military coup, Myanmar’s internet is partially blacked out

Internet connectivity dropped precipitously in Myanmar on Monday as the military seized power, likely the result of the government shutting down access in a move that drew condemnation from President Joe Biden and digital freedom activists. The Myanmar military detained senior civilian politicians, including President U Win Myint and Nobel laureate Aung San Suu Kyi, whose party won a majority of parliamentary seats in the November elections. A military-owned television network said Commander-in-Chief Senior Gen. Min Aung Hlaing would assume control of the nation for one year following the military’s allegations that the elections were fraudulent. NetBlocks, which tracks digital freedom, said connectivity fell in Myanmar by 50% at one point before later recovering to 75% of ordinary levels. The disruption pattern pointed to a centrally issued blackout order to telecommunications providers, NetBlocks said. The outage accompanied a reported Army order to shutdown state media and the disabling of phone […]

The post Amid military coup, Myanmar’s internet is partially blacked out appeared first on CyberScoop.

Continue reading Amid military coup, Myanmar’s internet is partially blacked out

Biden administration prepares for a different kind of Iranian cyber threat

As President Joe Biden wraps up his first week in the Oval Office, his national security team is still gearing up to face a myriad of looming digital security threats from Iran. Just over a year after the Trump administration used a drone strike to kill Qassem Soleimani, a top Iranian general, Iran is still weighing retaliatory action against the U.S., according to a recent Department of Defense assessment. That’s not the only threat the Biden administration may have to contend with — Iran carried out a number of online efforts meant to intimidate potential American voters prior to the presidential election, allegedly launched a hit list that identified U.S. election officials by name and was behind a reported effort to probe U.S. election websites. “From a geopolitical perspective — with the maximum pressure campaign, the assassination of Soleimani … they are a caged animal and I think they are very […]

The post Biden administration prepares for a different kind of Iranian cyber threat appeared first on CyberScoop.

Continue reading Biden administration prepares for a different kind of Iranian cyber threat

Chris DeRusha, who protected Biden campaign from hackers, says he is the Federal CISO

The former top cybersecurity official on Joe Biden’s presidential campaign said late Monday that he is now in charge of helping protect the federal government’s sprawling bureaucracy from hackers. Chris DeRusha, also a former White House cybersecurity official in the Obama administration, announced his appointment as the federal government’s new chief information security officer on LinkedIn. Maria Roat, the acting Federal CIO, confirmed DeRusha’s appointment early Tuesday. As Federal CISO, DeRusha will be responsible for coordinating cybersecurity policy across the federal bureaucracy and prodding agencies to fortify their networks in the wake of a suspected Russian hacking campaign that has infiltrated the departments of Justice, Energy and others. DeRusha is returning to familiar territory, having served as a White House cybersecurity adviser when Biden was vice president. DeRusha is also well-versed in election security issues, having worked as Michigan’s chief security officer before the Biden campaign hired him to prevent a repeat […]

The post Chris DeRusha, who protected Biden campaign from hackers, says he is the Federal CISO appeared first on CyberScoop.

Continue reading Chris DeRusha, who protected Biden campaign from hackers, says he is the Federal CISO

No decisions yet on any changes to TikTok or Huawei cases, White House says

The Biden administration is still reviewing how it will approach any national security challenges posed by Chinese-owned video-sharing app TikTok and telecommunications provider Huawei, the White House said Monday. “We need a comprehensive strategy … and a more systematic approach that actually addresses the full range of these issues,” White House Press Secretary Jen Psaki said of China-related technology and national security concerns that intensified during the Trump administration. That means “play[ing] a better defense” when it comes to preventing alleged Chinese theft of U.S. intellectual property, she said. President Joe Biden is “firmly committed to making sure that Chinese companies cannot misappropriate and misuse American data,” Psaki added. She was short on specifics, however, citing an “ongoing review” by the new administration of a range of China-related technology and national security issues. The press secretary did not address, for example, whether the Biden administration will continue an executive order […]

The post No decisions yet on any changes to TikTok or Huawei cases, White House says appeared first on CyberScoop.

Continue reading No decisions yet on any changes to TikTok or Huawei cases, White House says