Cybersecurity

IG: DHS Lacks Effective Privacy Oversight

While the agency had six major privacy incidents, the privacy office fell short in numerous areas.

Cybersecurity

CISA Shares Specs for Threat-Hunting Solution

The Cyberspace Solarium Commission is now pushing the Biden administration to require the same thing for companies serving the Defense Department.

Cybersecurity

CISA: SolarWinds Hackers Got Into Networks by Guessing Passwords

The agency also highlighted new indicators of compromise and recommendations for mitigating follow on activity involving Microsoft Cloud users.

Modernization

IG: Last Major CBP System Outage Caused By Code Defect Known for 2 Years

The customs agency could have avoided an August 2019 system outage—and hours of delays for travelers—with better patch management and employee training on backup procedures.

Emerging Tech

CBP Should Halt Expansion of the Biometric Entry-Exit Program, Many Commenters Write

Advocacy groups and the City of Portland wrote the Homeland Security Department urging a full stop on expanding the use of facial recognition technologies. 

Modernization

CISA Releases Draft Use Case For Securing Remote, Mobile and Teleworking Connections

The cybersecurity agency wants feedback on how to secure remote users under the Trusted Internet Connection 3 policy.

Emerging Tech

DHS Works to Improve Biometric Scanning of Masked Faces

Almost 600 human volunteers participated in a recent technology evaluation.

Cybersecurity

DIU, CISA Team Up to Coordinate Cybersecurity Tech Investments

The Defense and Homeland Security departments agreed to develop cybersecurity technologies for national security applications together.

Cybersecurity

CISA: SolarWinds Is Not the Only Way Hackers Got Into Networks

The agency also warned that getting attackers out of networks will be complex—especially because they are monitoring IT and cybersecurity employees’ emails.

Emerging Tech

Biometrics in Action

Federal agencies ramped up the use and scope of facial recognition tools in 2020, expanding programs to target more people and making significant technology upgrades.

Cybersecurity

CISA Orders Federal Agencies to Turn Off SolarWinds Products 

A critical flaw in software used throughout government was reportedly used to breach a major security company and at least two federal agencies.

Cybersecurity

FBI, CISA, State Leaders Warn Schools About Ransomware Threats

The percentage of ransomware attacks perpetrated against schools more than doubled in 2020.

Cybersecurity

Why Certain Cybersecurity Provisions Made it into the NDAA and Others Didn’t  

An effort to establish a public-private collaboration environment was cut from the final bill but a controversial insurance provision was retained.