U.S. officials release framework for notifying public of foreign interference in elections

The Trump administration on Friday released a framework describing the process by which it would notify Congress, state and local officials, the private sector, and the public about foreign interference in U.S. elections. The framework supplements existing laws, under which the FBI and the Department of Homeland Security alert victims of cyber intrusions and other malicious activity. The document is recognition that, in cases of foreign attempts to disrupt the electoral process, more communication with the public is needed. One key factor in the notification process, according to a one-page summary released by the Office of the Director of National Intelligence, is whether public disclosure of a foreign interference operation will deter the activity and protect the public, or instead re-amplify the adversary’s message. If DHS’s cybersecurity agency or a member of the intelligence community wants to disclose foreign interference activity beyond what is required by law, an interagency group of intelligence officials will […]

The post U.S. officials release framework for notifying public of foreign interference in elections appeared first on CyberScoop.

Continue reading U.S. officials release framework for notifying public of foreign interference in elections

Cybersecurity has done more to drive government cloud use than any other feature, intel official says

The cybersecurity features built into cloud computing have allowed the CIA to quickly achieve its technological goals, a top U.S. intelligence official said Tuesday. Sue Gordon, principal deputy director of national intelligence, said that of all the improvements that the cloud has brought to the intelligence community, the protections built into the technology provide the trust needed to handle some of the most sensitive work done by the U.S. government. “The advances we’ve made in security are probably what have allowed the greatest movement of mission,” Gordon said Tuesday at the Amazon Web Services Public Sector Summit in Washington, D.C. “Because of our insistence in the confidence of our processes and our data, and our commitment to the trust the American people place in us, we now have an environment that we trust.” It was a watershed moment for cloud computing when the CIA announced in 2013 that it would […]

The post Cybersecurity has done more to drive government cloud use than any other feature, intel official says appeared first on CyberScoop.

Continue reading Cybersecurity has done more to drive government cloud use than any other feature, intel official says

Mueller report confirms Trump lobbied top intel officials to refute Russia stories

President Donald Trump pushed top intelligence officials to refute information tied to the investigations into links between his 2016 presidential campaign and Russia, according to information publicly released Thursday in Special Counsel Robert Mueller’s report. According to the report, Trump phoned then-NSA Director Adm. Mike Rogers on March 26, 2017 to complain the investigation was “messing up” his ability to get things done with Russia, as far as Rogers recalls. The president also asked Rogers if there was anything he could do to refute news stories linking him to Russia. Richard Ledgett, former NSA deputy director who was reportedly present for the exchange, drafted a memo about the substance of the call. He and Rogers both signed it and locked it in a safe. Ledgett “said it was the most unusual thing he had experienced in 40 years of government service,” the report states. By the time the phone call […]

The post Mueller report confirms Trump lobbied top intel officials to refute Russia stories appeared first on CyberScoop.

Continue reading Mueller report confirms Trump lobbied top intel officials to refute Russia stories

Another FBI veteran tapped to lead DNI’s Cyber Threat Intelligence Integration Center

The U.S. intelligence community’s center for analyzing cyberthreat data got a new director Wednesday in Erin Joe, a career FBI official with experience dealing with nation-state-level threats. Joe becomes the second director of the four-year-old Cyber Threat Intelligence Integration Center at a time when nation-state hacking threats to U.S. organizations have been steady. She most recently served as a senior FBI executive focusing on nation-state hacking and “cyberterrorism” threats, the Office of the Director of National Intelligence said in announcing her appointment. As part of a 22-year career as an FBI field officer, Joe investigated the perpetrators of the September 11, 2001 attacks and led terrorism investigations across the Middle East, according to a biography on the RSA Conference website. CTIIC is a small agency comprised of officials from intelligence, law enforcement, and other agencies whose task is to quickly get cyberthreat intelligence into the hands of federal officials. President Barack […]

The post Another FBI veteran tapped to lead DNI’s Cyber Threat Intelligence Integration Center appeared first on CyberScoop.

Continue reading Another FBI veteran tapped to lead DNI’s Cyber Threat Intelligence Integration Center

National intelligence strategy seeks better insight into adversaries’ cyber capabilities

A national intelligence strategy released Tuesday calls on U.S. spy agencies to improve their understanding of what is driving foreign adversaries’ growing cyber capabilities. The strategy, published by the Office of the Director of National Intelligence, pledges that intelligence agencies will “increase our awareness and understanding of adversaries’ use of cyber operations—including leadership plans, intentions, capabilities, and operations— to inform decisions and enable action.” The stakes are high; America’s spies must keep pace with growing list of hacking capabilities at adversaries’ disposal, according to the ODNI. “As the cyber capabilities of our adversaries grow, they will pose increasing threats to U.S. security, including critical infrastructure, public health and safety, economic prosperity, and stability,” the document says. There has been no shortage of recent foreign hacking threats to U.S. public and private organizations, from suspected Iranian targeting of domain name systems to alleged Chinese economic espionage. The new strategy recognizes that the […]

The post National intelligence strategy seeks better insight into adversaries’ cyber capabilities appeared first on CyberScoop.

Continue reading National intelligence strategy seeks better insight into adversaries’ cyber capabilities

Federal insider-threat programs get a dose of ‘Maturity’

A government task force hopes to improve federal agencies’ ability to identify insider threats and avoid the leak of sensitive or classified information. The National Insider Threat Task Force (NITTF) — run by the FBI and the Office of the Director of National Intelligence — released the “ Insider Threat Program Maturity Framework” on Thursday. It complements a set of standards the task force released in 2012 that set the “minimum elements necessary to establish functional insider threat programs.” The aim with the new framework is to help federal agencies go beyond the minimum guidelines issued six years ago and be “more proactive, comprehensive, and better postured to deter, detect, and mitigate insider threat risk.” It can be used to start an insider threat program or augment an existing one. The framework comprises 19 “maturity elements,” such as the ability to adapt a program to comply with changing laws; educating employees […]

The post Federal insider-threat programs get a dose of ‘Maturity’ appeared first on Cyberscoop.

Continue reading Federal insider-threat programs get a dose of ‘Maturity’

Coats: ODNI has seen ‘no evidence’ of supply chain hack detailed in Bloomberg story

Director of National Intelligence Dan Coats told CyberScoop on Thursday that he’s seen no evidence of Chinese actors tampering with motherboards made by Super Micro Computer, becoming the latest national security official to question a Bloomberg report that stated the company was the victim of a supply chain hack. “We’ve seen no evidence of that, but we’re not taking anything for granted,” Coats told CyberScoop. “We’ve haven’t seen anything, but we’re always watching.” The comments came before a speech Coats delivered at CyberTalks, where the director touched on supply chain threats as one facet the administration is focused on when it comes to cybersecurity threats. “Be aware of supply chain threats,” Coats said in his speech. “Understand that cyberthreats to your supply chain are an insidious problem that can jeopardize the integrity of your products.” The remarks come after a cover story in Bloomberg Businessweek stated that Chinese intelligence agents […]

The post Coats: ODNI has seen ‘no evidence’ of supply chain hack detailed in Bloomberg story appeared first on Cyberscoop.

Continue reading Coats: ODNI has seen ‘no evidence’ of supply chain hack detailed in Bloomberg story

Economic cyber-espionage is here to stay, U.S. counterintelligence report says

A new report from a U.S. counterintelligence agency details persistent efforts by China, Iran, and Russia to steal U.S. trade secrets, warns that those campaigns are here to stay and raises concerns about the software supply chain as a vector for economic espionage. China, Iran, and Russia are “three of the most capable and active cyber actors tied to economic espionage,” and they will “remain aggressive and capable collectors of sensitive U.S. economic information and technologies, particularly in cyberspace,” the report from the National Counterintelligence and Security Center (NCSC) states. Last year was a “watershed” year in public reporting of big software supply-chain operations, with seven incidents reported compared to just four between 2014 and 2016, according to the NCSC, which is part of the Office of the Director of National Intelligence (ODNI). The counterintelligence agency cites the seminal NotPetya attack, which U.S. officials blamed on Moscow, and the CCleaner backdoor, which […]

The post Economic cyber-espionage is here to stay, U.S. counterintelligence report says appeared first on Cyberscoop.

Continue reading Economic cyber-espionage is here to stay, U.S. counterintelligence report says

Private sector played critical role in WannaCry attribution, ODNI official says

Private sector security companies had a key role in the U.S. government’s attribution of last year’s WannaCry ransomware epidemic to North Korea, an official at the Office of the Director of National Intelligence (ODNI) said on Friday. Speaking at a Washington Post Live event, Tonya Ugoretz, director of ODNI’s Cyber Threat Intelligence Integration Center (CTIIC), said that the small agency she leads acted as a liaison to get critical information about the global attack from the private sector to U.S. intelligence agencies. Ugoretz said that CTIIC learned of information about WannaCry that had been fed to Department of Homeland Security by its private sector partners. The information would play an important role in the attribution to North Korea months later, Ugoretz explained. CTIIC comprises staff from intelligence, law enforcement and other federal agencies with the goal of helping coordinate responses to cyberthreats. “DHS had that by virtue of their private sector relationships, and we asked […]

The post Private sector played critical role in WannaCry attribution, ODNI official says appeared first on Cyberscoop.

Continue reading Private sector played critical role in WannaCry attribution, ODNI official says

Trump’s refusal to call out Russian hacking provokes swift, sharp backlash

President Donald Trump drew sharp criticism Monday from former intelligence officials and lawmakers after refusing to acknowledge or condemn Russian interference in the 2016 presidential election while standing alongside Russian President Vladimir Putin. Following a closed-door tête-à-tête in Helsinki, Finland, the two leaders held a joint 45-minute press conference. During the wide-ranging session, among other things, the sitting U.S. president publicly declined to back the unanimous findings of his own U.S. intelligence community – that Russia interfered in the 2016 presidential election, through a series of cyberattacks and carefully orchestrated information campaigns. “They said they think it’s Russia; I have asked President Putin, he just said ‘It’s not Russia,” Trump said. “I have great confidence in my intelligence people, but I will tell you that President Putin was extremely strong and powerful in his denial today.” Within an hour, former intelligence chiefs were panning Trump and his statements at the press […]

The post Trump’s refusal to call out Russian hacking provokes swift, sharp backlash appeared first on Cyberscoop.

Continue reading Trump’s refusal to call out Russian hacking provokes swift, sharp backlash