Cybersecurity

EU signs on to IoT safety label plan

A U.S.-led effort to offer cyber-safe labels for connected devices is gaining momentum internationally.

Cybersecurity

Agencies’ FISMA implementation is still ‘mostly ineffective,’ watchdog says

The Government Accountability Office found that less than half of surveyed federal agencies had compliant security programs and called for improved performance metrics.

Cybersecurity

Think tank report envisions a cyber ‘good place’ for AI and how to get there

Amid the ongoing rise of artificial intelligence technologies and their integration into digital networks, the Aspen Institute compiled a new list of cybersecurity recommendations for government and industry.

Cybersecurity

Watchdog finds ‘sufficient’ cyber threat sharing at agencies, but barriers remain

The Intelligence Community Inspector General’s biennial update on cybersecurity information sharing noted that progress has been made over the past two years, but some agencies reported running up against roadblocks.

Cybersecurity

Space Force is crafting in-house cyber teams but sees need for closer work with USCYBERCOM

U.S. Cyber Command has been “an incredible partner” to the Space Force but does not currently have any personnel from the military branch within its ranks, a top official said.

Artificial Intelligence

How hackers can 'poison' AI

A new paper from NIST offers a standard taxonomy of cyber attacks dedicated to contaminating the data AI models use to learn.

Cybersecurity

FDA and CISA need to update cyber agreement for medical devices, watchdog says

The Government Accountability Office said medical devices are not commonly hacked but still called them “a source of cybersecurity concern warranting significant attention.”

Cybersecurity

Pentagon issues proposed CMMC rule

The long-anticipated draft rule, which will be officially published on Dec. 26, outlines proposed updates to DOD’s cybersecurity requirements for defense contractors and subcontractors who handle sensitive military data.

Cybersecurity

NIST releases 2 draft guides to prepare for post-quantum migration

The guidelines aim to help organizations incorporate quantum-resistant algorithms into their existing security infrastructures.

Cybersecurity

NDAA provision looks to close cybersecurity gaps in nuclear weapons systems

The requirement included in the fiscal year 2024 defense policy bill follows a 2022 GAO report that found the National Nuclear Security Administration did not fully implement “foundational cybersecurity risk practices.”

Cybersecurity

NIST issues guidance on a mathematical approach to data privacy

The draft document provides a system for adopting a differential privacy framework, and the agency is currently seeking feedback to ensure quality.

Cybersecurity

The 2024 defense policy bill has a lot of cyber

Other provisions touch on diplomacy and nuclear command and control, among other things.

People

Coker confirmed as cyber director

On a bipartisan vote, the Senate confirmed Harry Coker to lead the Office of the National Cyber Director at the White House.

Cybersecurity

U.S., global partners, ask software companies to focus on memory-safe code

New guidance for software developers from Five Eyes countries implores software developers to patch memory safety vulnerabilities and rethink the use of risky programming languages.

Cybersecurity

20 federal agencies miss deadline for implementing cyber incident tracking requirements, watchdog says

The Government Accountability Office found that just three federal agencies were in compliance with the Office of Management and Budget’s advanced cyber event logging requirements.

Cybersecurity

OMB takes aim at internet of things cybersecurity

The Office of Management and Budget’s recent FISMA guidance notes the importance of the Cybersecurity and Infrastructure Security Agency’s ability to scan agencies for vulnerabilities on an ongoing basis.

Cybersecurity

House bill looks to shore up federal cyber workforce

The bill, a companion to a Senate bill introduced in July, looks to fortify the U.S.’s domestic cybersecurity workforce and training programs.

Cybersecurity

CISA, FBI warn on Iran-backed infrastructure hacks

The hacking group CyberAv3ngers is actively targeting an Israeli-made automation system in wide use in the water and wastewater sector.

Cybersecurity

OPM launches cyber rotational program for feds

The new rotational program is an outgrowth of 2022 legislation backed by Sen. Gary Peters, D-Mich., who chairs the Homeland Security and Governmental Affairs Committee.