Cybersecurity

CISA Issues Vulnerability-Management Tools Dependent on Industry Action

Federal agencies are under a binding operational directive to address exploitable security vulnerabilities in their software, but the success of CISA’s effort relies on the cooperation of software vendors.

Cybersecurity

NATO Allies Double Down on Cybersecurity in Warfighting Ops

U.S. and Italian officials convened the 2022 Cyber Defence Pledge Conference, focused on supporting Ukraine and investing in new technology for all member nations.

Cybersecurity

How Federal Agencies are Using Innovative Tech to Protect Critical Infrastructure Cybersecurity

Officials from CISA and DARPA spoke about their initiatives to support cybersecurity operations across critical infrastructure networks.

Cybersecurity

NIST Official Warns Against Device-only Approach to Securing IoT

Federal agencies’ implementation of NIST’s guidelines on the issue—under direction from Congress—is coinciding with industry resistance to the comprehensive approach stakeholders agree is necessary.

Cybersecurity

No ‘Specific or Credible’ Cyber Threats Affected Integrity of Midterms, CISA Says

Despite “a handful” of DDoS attacks targeting state and local election websites and some technical glitches affecting voting equipment, CISA says it saw “no activity” that should undermine faith in the results of the midterm elections.

Digital Government

What a Divided Government Could Mean for Tech Policy

Here’s what a split Congress might mean for tech, cybersecurity and governance.

Cybersecurity

Former CISA Head Calls for Renewed Action to Combat Election Lies

Inaugural CISA director Chris Krebs expressed concern about the spread of election misinformation as Twitter changes up its user verification process.

Cybersecurity

CISA, NSA and Industry Outline Security Responsibilities of Software Suppliers

New guidance from the federal agencies—and major companies serving the government—tries to distinguish between the security duties of software developers, suppliers and consumers.

Cybersecurity

Voting Machine Myths Likely to Increase During and After Midterms, Report Finds

Cybersecurity firm Recorded Future identified mis- and disinformation campaigns suggesting that voting machines from three major companies “will be used to falsify the results of the midterms.”

Cybersecurity

Former CISA chief warns of ‘very chaotic environment’ ahead of midterms

Chris Krebs said those hoping to undermine confidence in U.S. elections may have their best shot yet during this week’s midterm vote.

Cybersecurity

Almost half of phishing attacks target gov employees, research says

Traditionally aimed at stealing credentials, phishing attacks are growing increasingly sophisticated.

Cybersecurity

NIST on tap to improve cybersecurity of water systems

The National Institute of Standards and Technology (NIST) hopes a new project will create a set of best practices to help the nation’s complex water and wastewater systems bolster their cybersecurity posture.

Cybersecurity

CISA Leaning Toward Lower Threshold for Mandatory Cyber Incident Reporting

The agency has started to receive feedback from some key stakeholders for its rulemaking process on the issue.

Cybersecurity

FCC Proposes to Strengthen Cybersecurity of Emergency Alert Systems

The notice of proposed rulemaking would require emergency alert system participants to disclose cyber breaches within 72 hours of discovery.

Cybersecurity

NDAA Negotiations Will Determine Success of Several Cyber Solarium Goals

Influence from major industry threatens once again to thwart lawmakers’ attempts to realize their policymaking goals through the annual defense authorization bill.

Cybersecurity

Energy official urges CISA to develop storehouse for software bills of materials

A senior cybersecurity advisor for the Department of Energy said a central repository of widely used Software Bills of Material would significantly reduce the burden on federal agencies.

Cybersecurity

CDM team helped define cyber directives

Governmentwide cyber hygiene orders are increasingly taking into account the capabilities of Continuous Diagnostics and Mitigation tools.

Cybersecurity

CISA promises bespoke cyber advice for agencies

A new engagement arm of the Cybersecurity and Infrastructure Security Agency is designed to help agencies navigate the crush of cybersecurity requirements.

Cybersecurity

Russia Linked to Nearly 75% of Late 2021 Ransomware Attacks, Per Analysis

The analyzed ransomware variants—from July to December 2021—amounted to millions of dollars in damages.