Cybersecurity

Federal Agencies Detail Russian Tactics Used in Recent Cyber Intrusions

The FBI, Homeland Security Department and Cybersecurity and Infrastructure Security Agency issued an alert on Russian government cyber tradecraft and mitigation techniques for targets.

Cybersecurity

Existing Agency Threat Hunters Welcome CISA’s New Authorities 

For the Department of Education, proactive threat hunting means not just taking down questionable URLs but buying them up.

Cybersecurity

CISA Issues Deadline for Federal Agencies to Address Pulse Secure Vulnerabilities

The vulnerabilities led to the compromise of government agencies early last summer and, together with a newly disclosed flaw, continue to be exploited.

Cybersecurity

Energy Department Announces 100-Day Sprint to Shore Up Power Grid Cybersecurity

The department will partner with the Cybersecurity and Infrastructure Security Agency and utilities to improve visibility, detection and response to cyber threats.

Cybersecurity

White House Stands Down Coordination Effort on SolarWinds, Microsoft Exchange Hacks

The leading cybersecurity official on the National Security Council shared lessons learned as agencies reach patching goals.

Cybersecurity

Agencies Have Till Midnight April 15 to Apply New Microsoft Exchange Patches

Four of the 95 vulnerabilities Microsoft released as part of its monthly “patch Tuesday” were identified by the National Security Agency.

Ideas

The Biden Administration’s Cybersecurity Roadmap

Making some changes to how the federal government buys cyber tools is one of the things the new Homeland Security secretary has mentioned.

Cybersecurity

Former DHS Secretary Details SolarWinds Hackers’ Access to His Email

Chad Wolf said the information was all unclassified but the compromise was still disturbing.

Cybersecurity

Top Homeland Security Senators Want Details on Agencies Hit in SolarWinds, Microsoft Intrusions

Sens. Gary Peters and Rob Portman also request more information on key defensive programs and federal cyber leadership.

Cybersecurity

CISA Orders Agencies to Conduct Fresh Scans of Microsoft Exchange Servers

The agency issued supplemental guidance requiring new tests with Microsoft-provided tools and measures to harden the attractive target.

Cybersecurity

New Software Vendor Standards Coming Within Weeks, CISA Head Says 

The White House is leading an interagency effort focused on software development that will determine federal procurement of information technology.

Cybersecurity

CISA Will Use New Authority Over Internet Service Providers to Fight Ransomware, Official Says

Acting CISA Director Brandon Wales praised the government’s coordination absent a national cyber director.

Cybersecurity

CISA, FBI Officials Say Federal Payroll Facility Was Not Targeted in Hacking Campaigns

CISA’s acting director identified ways the government is working to improve information sharing about cybersecurity incidents between agencies.

Emerging Tech

Advocacy Groups Again Ask CBP to Withdraw Biometrics Expansion Proposal

Customs and Border Protection accepted a second round of comments after the change in administrations. 

Cybersecurity

CISA, FBI Link Exploitation of Microsoft Exchange to Nation-State Actors

The agencies also warned of impending commoditization by criminal groups of access gained through vulnerabilities in the email and calendar service.

Cybersecurity

CISA: No Federal Agencies Compromised Through Microsoft Exchange Servers

Investigations remain ongoing, Cybersecurity and Infrastructure Security Agency leaders said at a hearing on modernizing the federal government’s approach to cybersecurity.