NSA puts ‘Ghidra,’ its reverse-engineering tool for malware, in the hands of the public

After years lurking in the shadows, the National Security Agency’s tool for reverse-engineering malware is now out in the open. The software framework has moved from classified status into use by military analysts and contractors in sensitive-but-unclassified settings, and now it’s available to anyone with an internet connection. In a bid to help private and public-sector analysts track how malicious code evolves and morphs, the agency announced the release of the tool at the RSA Conference in San Francisco on Tuesday. “As we open-source it, I think the creative folks on the outside are going to build modules and capabilities and they’re going to be able to collaborate with us on improving it even further,” Rob Joyce, senior cybersecurity adviser at NSA, said at an interview. The gist of the software framework, called Ghidra, is that it allows analysts to compare different versions of malicious code to understand what each is doing differently, including […]

The post NSA puts ‘Ghidra,’ its reverse-engineering tool for malware, in the hands of the public appeared first on CyberScoop.

Continue reading NSA puts ‘Ghidra,’ its reverse-engineering tool for malware, in the hands of the public

NSA’s Joyce outlines how U.S. can disrupt and deter foreign hacking

The United States will do more to disrupt the malicious cyber-activity that foreign adversaries are aggressively using to advance their interests, a National Security Agency official said Thursday. “We have to impose costs in a visible way to start deterrence,” said Rob Joyce, senior cybersecurity adviser at NSA. “We have to go out and try to make those operations less successful and harder to do.” Speaking to an industry association in Hanover, Maryland, Joyce cited the 2017 WannaCry and NotPetya malware outbreaks — and Russia’s use of information operations in the 2016 U.S. election — as examples of nation-states moving from “exploitation to disruption” to impose their will in cyberspace. Washington has blamed North Korea and Russia, respectively, for the devastating WannaCry and NotPetya attacks, which cost billions of dollars in economic damage. Some foreign governments have less legal constraints on their activities in cyberspace than the U.S., Joyce told a local […]

The post NSA’s Joyce outlines how U.S. can disrupt and deter foreign hacking appeared first on CyberScoop.

Continue reading NSA’s Joyce outlines how U.S. can disrupt and deter foreign hacking

China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

The U.S. government again is concerned about Chinese cyber-operations, a senior National Security Agency official said Tuesday amid ongoing news about possible vulnerabilities in widely used technology. “We have to worry about national security,” Rob Joyce, a senior adviser for cybersecurity strategy at NSA, said Tuesday at a Wall Street Journal event in New York. “We’ve been strong and consistent in saying we have some specific concerns about supply chain risks and ways nations may take advantage of that.” Joyce was referring to heightened international scrutiny around the Chinese technology giant Huawei. Canadian authorities this month arrested Meng Wangzhou, Huawei’s chief financial officer, on suspicion of violation U.S. sanctions. Officials in the U.S., U.K., Australia and elsewhere have warned that Huawei’s ties with the Chinese government, combined with widespread adoption of the company’s technology, could result in espionage opportunities for Beijing. Western officials have not revealed any evidence proving such […]

The post China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap appeared first on CyberScoop.

Continue reading China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence

A news report claiming a compromise of U.S. companies’ supply chains by Chinese spies has triggered a thorough search in government and industry for evidence of the breach that has so far turned up nothing, according to a senior National Security Agency official, who expressed concern that the search was a distraction and potentially a waste of resources. “I have grave concerns about where this has taken us,” Rob Joyce said Wednesday at the U.S. Chamber of Commerce. “I worry that we’re chasing shadows right now.” The story in question is an explosive, anonymously-sourced report published last week by Bloomberg Businessweek. The report alleges Chinese intelligence agents placed malicious microchips on server motherboards supplied by Super Micro Computing Inc., setting up a backdoor to some 30 companies, including Apple and Amazon Web Services. While supply-chain threats emanating from China are certainly a concern, Joyce said, “what I can’t find are any ties to […]

The post NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence appeared first on Cyberscoop.

Continue reading NSA official: Bloomberg story created a frenzied, fruitless search for supporting evidence

White House announces federal cyber strategy, vows to go on offensive

The White House announced a new national cybersecurity strategy Thursday in an effort raise federal network defenses and more aggressively deter foreign adversaries from threatening U.S. interests. “We’re going to do a lot of things offensively and I think our adversaries need to know that,” White House national security adviser John Bolton told reporters. Defensive measures are central to the document, but Bolton’s call with reporters emphasized offense. “We will identify, counter, disrupt, degrade, and deter behavior in cyberspace that is destabilizing and contrary to national interests, while preserving the United States’ overmatch in and through cyberspace,” Bolton said. The strategy is a template through which federal agencies can carry out their own cybersecurity mandates, according to Bolton. “I’m satisfied that this allows us the comprehensive look at strategy across the entire government,” he said. “Each agency knows its lane and is pursuing it vigorously. That’s true in the unclassified world; it’s […]

The post White House announces federal cyber strategy, vows to go on offensive appeared first on Cyberscoop.

Continue reading White House announces federal cyber strategy, vows to go on offensive

With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

In the wake of the White House’s decision to eliminate its top cybersecurity position, a Department of Homeland Security official has called on the U.S. government to robustly engage on cyber policy issues on the world stage. The Trump administration should have a “strong voice” at internet standards bodies and other global forums, working with allies and non-allies alike, said Jeanette Manfra, assistant secretary for DHS’s Office of Cybersecurity and Communications. “We have to figure out a way to continue to work together to ensure that the stability of the global system is maintained,” Manfra said Tuesday at the Security Through Innovation Summit, presented by McAfee and produced by CyberScoop. Manfra did not mention the recently-nixed White House cybersecurity coordinator in her remarks, but that position has traditionally been key to the United States’ international cybersecurity work. At a February conference in Germany, for example, then-White House cybersecurity coordinator Rob […]

The post With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity appeared first on Cyberscoop.

Continue reading With White House coordinator gone, DHS official calls for U.S. leadership on cybersecurity

Bolton eliminates White House Cybersecurity Coordinator position

The National Security Council has officially decided to eliminate the White House Cybersecurity Coordinator role, a current U.S. official told CyberScoop. Until today, the position had an important role in synchronizing cybersecurity efforts across the federal government, including managing the execution of defensive and offensive cyber operations conducted by the Pentagon. The position was first created under the George W. Bush administration. The move follows the departure of former coordinator Rob Joyce on Friday. Joyce’s planned departure followed a 14-month stint where he pioneered the creation of several new cybersecurity policies and helped shed light on a secretive government disclosure framework, known as the Vulnerabilities Equities Process. The news was first reported by Politico and independently confirmed by CyberScoop. An email sent Tuesday to NSC staffers by an aide of national security adviser John Bolton described that the decision would help cut “another layer of bureaucracy.” The NSC currently employs […]

The post Bolton eliminates White House Cybersecurity Coordinator position appeared first on Cyberscoop.

Continue reading Bolton eliminates White House Cybersecurity Coordinator position

National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures

A public summary of the Trump administration’s cyber deterrence strategy has been delayed because of internal disputes over retaliatory hacking measures, two current U.S. officials familiar with the matter tell CyberScoop. According to sources, several National Security Council staffers are seeking edits that further set ground rules for repercussions if an adversary attacks either the U.S. government or a U.S.-based company in cyberspace. The strategy’s outline was supposed to be released last Friday, but was held up after an NSC member requested it be postponed. The summary, although not as comprehensive as the strategy itself, is important because it would broadly inform the public about the government’s secret plan of action and signal to adversaries what behaviors cross a red line. Originally, the Trump administration mandated the cyber deterrence framework through the cybersecurity executive order released in May 2017. The report, a classified document that defines response options for when the country comes under […]

The post National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures appeared first on Cyberscoop.

Continue reading National Security Council delays publication of cyber strategy over inclusion of ‘offensive’ measures

A cybersecurity power struggle is brewing at the National Security Council

Senior government officials are worried about the outcome of an ongoing power struggle inside the National Security Council that will shape the fate of the nation’s cybersecurity posture. The arrival of newly appointed national security adviser John Bolton has prompted an attempted power grab by a member of the National Security Council, four current officials with knowledge of the matter told CyberScoop. This effort is causing anxiety across senior levels of government about the future of the cybersecurity coordinator role at the White House — a position that oversees a wide array of programs, including the management and coordination of defensive and offensive cyber-operations. Earlier this week, current Cybersecurity Coordinator Rob Joyce announced his intention to leave the position and return to the National Security Agency, where he spent more than two decades. He will remain in the White House position for another month to help with the transition process. The sources, who spoke […]

The post A cybersecurity power struggle is brewing at the National Security Council appeared first on Cyberscoop.

Continue reading A cybersecurity power struggle is brewing at the National Security Council

Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says

Newly appointed national security adviser John Bolton will lead the charge in finding a replacement for Cybersecurity Coordinator Rob Joyce, according to Secretary of Homeland Security Kirstjen Nielsen. Nielsen spoke to a small group of reporters Monday ahead of a public speaking appearance at the 2018 RSA Conference in San Francisco. The meeting occurred several hours after Joyce’s planned departure was first reported by Reuters and then independently confirmed by CyberScoop. “It’s within Ambassador Bolton’s prerogative [to select the next cybersecurity coordinator],” Nielsen said. “[Bolton] will take the time to work with Rob’s team and work with him, but that would be up to him.” While Joyce spends the next month transitioning out of his role, Bolton will coordinate with the White House National Security Council to find a replacement. It is also possible that Bolton will take this opportunity to restructure aspects of the existing position, a current U.S. […]

The post Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says appeared first on Cyberscoop.

Continue reading Bolton will lead charge to replace cybersecurity coordinator, DHS Secretary says