Cybersecurity

White House announces new program to designate cyber-secure IoT devices

The Biden administration announced its Cyber Trust Mark labeling program to ensure commercial smart home devices have sufficient cybersecurity tech in place.

Cybersecurity

Experts warn of financial challenges and gaps in cyber implementation plan 

From a crucial lack of federal funding to longstanding issues with the cyber workforce, experts told Nextgov/FCW that the new cybersecurity implementation plan features major “financial potholes.”

Cybersecurity

Bipartisan FISMA update looks to tweak cyber incident reporting rules for agencies

The legislation proposes new requirements for disclosing cyberattacks, assigns guidance for A.I.-enabled cyber, codifies the Federal CISO role and more.

Cybersecurity

New White House cyber plan leaves digital identity action items out

Officials noted that identity action items could still be included in later iterations of the national cybersecurity strategy implementation plan. 

Cybersecurity

New White House cyber implementation plan looks to ramp up resilience

The plan, released Thursday morning, includes more than 65 “high-impact initiatives” that federal agencies will be tasked with executing to achieve the objectives outlined in the national cybersecurity strategy.

Cybersecurity

State Department email accounts hit in China-linked cyberattack

A China-based cybercriminal known as Storm-0558 gained access to unclassified U.S. government email accounts using forged authentication tokens according to a report released by Microsoft.

Cybersecurity

Trade groups press White House for national cyber director nomination

A coalition of industry stakeholders is urging the Biden administration to nominate a national cyber director by the end of the month in a new letter sent to the White House Wednesday. 

Cybersecurity

Cloud poses special cyber risks for critical infrastructure, report warns

Federal agencies and organizations that oversee critical infrastructure sectors and fail to adapt to the cloud paradigm risk major cybersecurity threats to their systems and networks, according to recent findings.

Cybersecurity

NDAA amendment calls for DOD, DHS to assess cyber threats to border security

Rep. Vicente Gonzalez, D-Texas, said his proposal “sets a plan to prevent cyber incidents by reducing the risk of future cyber vulnerabilities” in key border technologies.

Cybersecurity

New court ruling may hinder federal information sharing efforts, experts warn

Security experts warned that a federal ruling barring the Cybersecurity and Infrastructure Security Agency and others from contacting social media sites about key issues may have implications that go far beyond First Amendment-protected speech.

Cybersecurity

Resource constraints led to EPA’s failure to address critical vulnerabilities in air and radiation data

The Environmental Protection Agency cited a lack of resources and the sheer volume of critical vulnerabilities as the reasons for its inability to patch its systems under federally required timeframes. 

Cybersecurity

Third-party contractor software exploited in attack on HHS data

An official with the Department of Health and Human Services said attackers gained access to data by exploiting a major vulnerability found in the popular MOVEit file transfer service.

Cybersecurity

Navy gets new cyber categories

The move will make it so cryptologists and IT professionals no longer have additional duties in cyberspace operations.

Cybersecurity

Critical cyber threats persist on federal networks despite recent directives

Hundreds of devices on federal networks remain in apparent violation of a recent Binding Operational Directive from the Cybersecurity and Infrastructure Security Agency, according to a new report. 

Cybersecurity

White House unveils fiscal 2025 cybersecurity investment priorities

The administration is urging agencies to align their fiscal 2025 budget requests with recent guidance that prioritizes strengthening federal networks and systems against cyber intrusions.

Cybersecurity

CISA to launch new cyber supply chain resource hub

The new resource center will allow federal agencies and industry stakeholders to get their hands on practical tools to help meet new cyber supply chain risk management.

Cybersecurity

Congress needs ‘private sector buy-in’ to address cyber workforce shortage

Organizations are working to educate and train the next generation of professionals to fill critical cybersecurity vacancies, but private sector firms need to change their hiring practices to integrate this pool of talent into the workforce. 

Cybersecurity

US ‘can’t PSA our way out’ of cyber vulnerability, CISA director says

Speaking during a Cybersecurity Advisory Committee meeting, CISA Director Jen Easterly noted that corporate responsibility for cyber must stand “as a matter of good governance.”

Cybersecurity

NIST wants to help prevent a major cyberattack on the water sector

The National Institute of Standards and Technology aims to provide a practical guide to address unique cyber challenges impacting America’s complex water systems.

Cybersecurity

Justice Department launches new unit to combat cyber threats

The National Security Cyber Section will work to "increase the scale and speed of disruption campaigns and prosecutions” against cybercriminals, an official said this week.