China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

The U.S. government again is concerned about Chinese cyber-operations, a senior National Security Agency official said Tuesday amid ongoing news about possible vulnerabilities in widely used technology. “We have to worry about national security,” Rob Joyce, a senior adviser for cybersecurity strategy at NSA, said Tuesday at a Wall Street Journal event in New York. “We’ve been strong and consistent in saying we have some specific concerns about supply chain risks and ways nations may take advantage of that.” Joyce was referring to heightened international scrutiny around the Chinese technology giant Huawei. Canadian authorities this month arrested Meng Wangzhou, Huawei’s chief financial officer, on suspicion of violation U.S. sanctions. Officials in the U.S., U.K., Australia and elsewhere have warned that Huawei’s ties with the Chinese government, combined with widespread adoption of the company’s technology, could result in espionage opportunities for Beijing. Western officials have not revealed any evidence proving such […]

The post China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap appeared first on CyberScoop.

Continue reading China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence

A news report claiming a compromise of U.S. companies’ supply chains by Chinese spies has triggered a thorough search in government and industry for evidence of the breach that has so far turned up nothing, according to a senior National Security Agency official, who expressed concern that the search was a distraction and potentially a waste of resources. “I have grave concerns about where this has taken us,” Rob Joyce said Wednesday at the U.S. Chamber of Commerce. “I worry that we’re chasing shadows right now.” The story in question is an explosive, anonymously-sourced report published last week by Bloomberg Businessweek. The report alleges Chinese intelligence agents placed malicious microchips on server motherboards supplied by Super Micro Computing Inc., setting up a backdoor to some 30 companies, including Apple and Amazon Web Services. While supply-chain threats emanating from China are certainly a concern, Joyce said, “what I can’t find are any ties to […]

The post NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence appeared first on Cyberscoop.

Continue reading NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence

White House announces federal cyber strategy, vows to go on offensive

The White House announced a new national cybersecurity strategy Thursday in an effort raise federal network defenses and more aggressively deter foreign adversaries from threatening U.S. interests. “We’re going to do a lot of things offensively and I think our adversaries need to know that,” White House national security adviser John Bolton told reporters. Defensive measures are central to the document, but Bolton’s call with reporters emphasized offense. “We will identify, counter, disrupt, degrade, and deter behavior in cyberspace that is destabilizing and contrary to national interests, while preserving the United States’ overmatch in and through cyberspace,” Bolton said. The strategy is a template through which federal agencies can carry out their own cybersecurity mandates, according to Bolton. “I’m satisfied that this allows us the comprehensive look at strategy across the entire government,” he said. “Each agency knows its lane and is pursuing it vigorously. That’s true in the unclassified world; it’s […]

The post White House announces federal cyber strategy, vows to go on offensive appeared first on Cyberscoop.

Continue reading White House announces federal cyber strategy, vows to go on offensive

With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

In the wake of the White House’s decision to eliminate its top cybersecurity position, a Department of Homeland Security official has called on the U.S. government to robustly engage on cyber policy issues on the world stage. The Trump administration should have a “strong voice” at internet standards bodies and other global forums, working with allies and non-allies alike, said Jeanette Manfra, assistant secretary for DHS’s Office of Cybersecurity and Communications. “We have to figure out a way to continue to work together to ensure that the stability of the global system is maintained,” Manfra said Tuesday at the Security Through Innovation Summit, presented by McAfee and produced by CyberScoop. Manfra did not mention the recently-nixed White House cybersecurity coordinator in her remarks, but that position has traditionally been key to the United States’ international cybersecurity work. At a February conference in Germany, for example, then-White House cybersecurity coordinator Rob […]

The post With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity appeared first on Cyberscoop.

Continue reading With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

Bolton eliminates White House Cybersecurity Coordinator position

The National Security Council has officially decided to eliminate the White House Cybersecurity Coordinator role, a current U.S. official told CyberScoop. Until today, the position had an important role in synchronizing cybersecurity efforts across the federal government, including managing the execution of defensive and offensive cyber operations conducted by the Pentagon. The position was first created under the George W. Bush administration. The move follows the departure of former coordinator Rob Joyce on Friday. Joyce’s planned departure followed a 14-month stint where he pioneered the creation of several new cybersecurity policies and helped shed light on a secretive government disclosure framework, known as the Vulnerabilities Equities Process. The news was first reported by Politico and independently confirmed by CyberScoop. An email sent Tuesday to NSC staffers by an aide of national security adviser John Bolton described that the decision would help cut “another layer of bureaucracy.” The NSC currently employs […]

The post Bolton eliminates White House Cybersecurity Coordinator position appeared first on Cyberscoop.

Continue reading Bolton eliminates White House Cybersecurity Coordinator position

National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures

A public summary of the Trump administration’s cyber deterrence strategy has been delayed because of internal disputes over retaliatory hacking measures, two current U.S. officials familiar with the matter tell CyberScoop. According to sources, several National Security Council staffers are seeking edits that further set ground rules for repercussions if an adversary attacks either the U.S. government or a U.S.-based company in cyberspace. The strategy’s outline was supposed to be released last Friday, but was held up after an NSC member requested it be postponed. The summary, although not as comprehensive as the strategy itself, is important because it would broadly inform the public about the government’s secret plan of action and signal to adversaries what behaviors cross a red line. Originally, the Trump administration mandated the cyber deterrence framework through the cybersecurity executive order released in May 2017. The report, a classified document that defines response options for when the country comes under […]

The post National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures appeared first on Cyberscoop.

Continue reading National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures

A cybersecurity power struggle is brewing at the National Security Council

Senior government officials are worried about the outcome of an ongoing power struggle inside the National Security Council that will shape the fate of the nation’s cybersecurity posture. The arrival of newly appointed national security adviser John Bolton has prompted an attempted power grab by a member of the National Security Council, four current officials with knowledge of the matter told CyberScoop. This effort is causing anxiety across senior levels of government about the future of the cybersecurity coordinator role at the White House — a position that oversees a wide array of programs, including the management and coordination of defensive and offensive cyber-operations. Earlier this week, current Cybersecurity Coordinator Rob Joyce announced his intention to leave the position and return to the National Security Agency, where he spent more than two decades. He will remain in the White House position for another month to help with the transition process. The sources, who spoke […]

The post A cybersecurity power struggle is brewing at the National Security Council appeared first on Cyberscoop.

Continue reading A cybersecurity power struggle is brewing at the National Security Council

Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says

Newly appointed national security adviser John Bolton will lead the charge in finding a replacement for Cybersecurity Coordinator Rob Joyce, according to Secretary of Homeland Security Kirstjen Nielsen. Nielsen spoke to a small group of reporters Monday ahead of a public speaking appearance at the 2018 RSA Conference in San Francisco. The meeting occurred several hours after Joyce’s planned departure was first reported by Reuters and then independently confirmed by CyberScoop. “It’s within Ambassador Bolton’s prerogative [to select the next cybersecurity coordinator],” Nielsen said. “[Bolton] will take the time to work with Rob’s team and work with him, but that would be up to him.” While Joyce spends the next month transitioning out of his role, Bolton will coordinate with the White House National Security Council to find a replacement. It is also possible that Bolton will take this opportunity to restructure aspects of the existing position, a current U.S. […]

The post Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says appeared first on Cyberscoop.

Continue reading Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says

Cybersecurity adviser Rob Joyce to leave White House, return to NSA

Rob Joyce is planning to leave his post as White House cybersecurity coordinator and return to work at the National Security Agency, a U.S. official confirmed to CyberScoop on Monday. The news comes less than a week after Joyce’s boss, Thomas Bossert, resigned as White House homeland security adviser. Joyce has been filling Bossert’s role in an acting capacity. Bossert’s resignation was reportedly at the request of John Bolton, the newly appointed national security adviser. The departures of Joyce and Bossert leave big gaps in the Trump administration’s cybersecurity expertise. In his main role, Joyce has been involved in developing the framework surrounding how the U.S. responds to foreign cyberthreats. He participated in a call with reporters on Monday to issue an alert about Russian-backed hacking efforts targeting internet routers. Joyce has also been vocal to push for carveouts for security research in the impending European General Data Protection Regulation, which many say has a chilling effect on […]

The post Cybersecurity adviser Rob Joyce to leave White House, return to NSA appeared first on Cyberscoop.

Continue reading Cybersecurity adviser Rob Joyce to leave White House, return to NSA

White House pushing for research carveout in GDPR

The White House is hoping to convince European regulators to protect security researchers in their General Data Protection Regulation so they can continue to scrape data that’s relevant for data breach and botnet investigations, according to White House Cybersecurity Coordinator Rob Joyce. GDPR, which mandates companies with European customers to have numerous data protections in place, goes into effect May 25, 2018. The law will have a significant impact on the billion dollar cybersecurity industry, but some of its privacy provisions could have a negative effect on security researchers’ work. One of the more concerning developments revolves around access to data published by the Internet Corporation for Assigned Names and Numbers (ICANN). Whenever a domain name is registered, ICANN requires information like, a name, IP address and physical address to be submitted. While these details are sometimes forged, that information can provide clues about a cyberattack. ICANN stores all of […]

The post White House pushing for research carveout in GDPR appeared first on Cyberscoop.

Continue reading White House pushing for research carveout in GDPR