Cybersecurity

CISA: SolarWinds Hackers Got Into Networks by Guessing Passwords

The agency also highlighted new indicators of compromise and recommendations for mitigating follow on activity involving Microsoft Cloud users.

Cybersecurity

The Hack Roundup: Justice Department Confirms Email Breach

During an extraordinary day of unrest in the Capitol, here are the news and updates you may have missed.

Cybersecurity

Russia ‘Likely’ Behind Widespread Hack, Cyber Response Agencies Say

The Cyber Unified Coordination Group believes fewer than ten government agencies were compromised in what is an ongoing intelligence operation.

Cybersecurity

Hack Spurs Call for Greater—but Measured—Supply Chain Scrutiny 

Operational cybersecurity hygiene is one thing, criteria for using open-source code is another, one expert says. 

Cybersecurity

Former Presidential Adviser Advocates Tougher Software Vendor Standards After Breach

The environment where updates for the company’s software were developed was reportedly protected by a password anyone could guess.

Cybersecurity

Biden Disputes Trump’s Claim that Hack is Under Control

The president-elect called for an official attribution to Russia but said a damage assessment is necessary before discussing the appropriate response.

Cybersecurity

Massive Hack Roundup: Microsoft Says Breach 'Not Espionage as Usual'

Here are the news and updates you may have missed.

Cybersecurity

Amid Massive Hack, Lawmakers Urge Trump to Sign Defense Bill with New Cybersecurity Legislation

As the government scrambles to understand the widening compromise, legislation to shore up the nation’s cyber defenses sits unsigned on the President’s desk.

Cybersecurity

House Committees Launch Investigation into Alleged Russian Hack of Federal Agencies

President-elect Joe Biden also promised to elevate cybersecurity “as an imperative” across government.

Cybersecurity

CISA: SolarWinds Is Not the Only Way Hackers Got Into Networks

The agency also warned that getting attackers out of networks will be complex—especially because they are monitoring IT and cybersecurity employees’ emails.

Cybersecurity

What We Know About the SolarWinds Breach

The White House invoked Presidential Policy Directive-41 to coordinate a "whole of government" response.

Cybersecurity

CISA Orders Federal Agencies to Turn Off SolarWinds Products 

A critical flaw in software used throughout government was reportedly used to breach a major security company and at least two federal agencies.

Cybersecurity

Reports: Suspected Russian Hackers Breach Commerce, Treasury Departments 

U.S. officials are investigating what data may have been stolen and whether the hack is more widespread.