Cybersecurity

CISA Issues Mitigation Tips for Common Attack Tactics

The agency assessed 37 federal agencies, and state, local and tribal governments last year to see how they are typically exploited.

Cybersecurity

Official Suggests Consequences Coming to Russia for Ransomware

A senior administration official said the U.S. has made specific requests through official channels regarding cyber criminals.

Cybersecurity

Report: COVID-19 Increased Acquisition Activity in Cyber Industry

The pandemic contributed to more than 120 publicly announced cybersecurity acquisitions in 2020 as the need for cybersecurity tools grew.

Cybersecurity

VA’s Cybersecurity Still Missing Critical Zero-Trust Element, Watchdog Says

An official from the Government Accountability Office said she is encouraged by the formation of an investment review board at the department and intends to monitor it closely.

Cybersecurity

IG: SBA’s Cybersecurity ‘Not Effective,’ In Part Due to COVID

The pandemic created new cybersecurity problems for the Small Business Administration, according to the agency’s annual FISMA report.

Cybersecurity

U.S., Russian Officials to Meet Following Kaseya Ransomware Attack

President Joe Biden also plans to meet with U.S. officials on measures to address ransomware.

Cybersecurity

Debate Heats Up as Senator Prepares to Introduce Incident-Reporting Legislation

Reviews are in on draft legislation Sen. Mark Warner’s office has circulated and plans to update for introduction after the holiday break.

Cybersecurity

US, UK Officials: Russian Military Leveraging Containers in Active Hacking Campaign

Cybersecurity agencies issued an advisory with indicators of compromise and mitigation measures. 

Ideas

People Don't Realize They're Data Breach Victims

The researchers found participants were not aware of 74% of the breaches.

Cybersecurity

Lawmakers Look to Give NTIA More Cybersecurity Responsibilities

During a hearing of the House Energy and Commerce Committee, witnesses drew attention to the absence of a permanent leader at the National Telecommunications and Information Administration.

Cybersecurity

CISA Starts Cataloging Bad Practices in Cybersecurity

The agency plans to keep updating the narrow list based on feedback from cybersecurity professionals.

Cybersecurity

White House Plans to Attribute the Microsoft Exchange Hack Soon

Microsoft has already attributed the broad-scale compromise of its on-premises mail servers to Chinese nation-state actors.

Cybersecurity

Lawmaker, Tech Companies Clash on Software Transparency Requirements

The National Institute of Standards and Technology has defined "critical software" in accordance with an executive order to institute procurement standards federal agencies must follow.    

Ideas

What I Learned Helping Lead Oversight of $5 Trillion in Pandemic Relief

Large scale identity theft-based fraud in unemployment assistance stunned many, even those who fight fraud for a living.

Ideas

Leveraging Encryption Keys to Better Secure the Federal Cloud 

In the same way we use a key to lock valuable assets in a safe deposit box, agencies can lock up encryption keys.

Cybersecurity

DOD Offering Defense Industrial Base a ‘Krystal Ball’ Into Adversary Insights

A pilot program is being run out of the Defense Department’s Cyber Crime Center, which is a key part of a strategy to secure the defense industrial base as the scope and severity of cyberattacks increase.