Cybersecurity

CISA Orders Agencies to Mitigate VMWare Vulnerabilities Under Deadline

Advanced adversaries appear to be exploiting the vulnerabilities to get around multifactor authentication.

Cybersecurity

Agencies Showcase Federal Cyber Progress, Outline Future Threats

Witnesses from CISA, NIST, and the GSA spoke before a House Homeland subcommittee on their current efforts to bolster the nation’s cyber defenses.

Podcasts

Critical Update: Evolution in the 'Valley of Death'

Nextgov looks at the use of cooperative research and development agreements by some major industry players to highlight how the meaning of the phrase, and implementation of its associated authorities, has shifted over the years.

Cybersecurity

Transportation Proposes Near $1M Fine for Colonial Pipeline One Year After Hack

The firm has 30 days to respond with evidence contesting the agency’s allegation of safety violations.

Cybersecurity

CISA Points to Water Sector in Seeking $80 Million More for FEMA Grants

CISA and FEMA are currently rolling out the first of $1 billion the Homeland Security agencies got in Rescue Act funding to help state and local entities improve their cybersecurity.

Cybersecurity

CISA Adds New Russian Malware to Cyber Advisory

The agency updated its warning regarding malware deployed by Russian state actors as the country continues war against Ukraine.

Cybersecurity

CISA’s Newest Advisor Could Soon Have Agencies Asking: 'Does This Spark Joy?'

Another CISA advisor has referred to Bob Lord as a “digital Marie Kondo,” tidying up the Democratic National Committee by throwing out old software and unused tech.

Cybersecurity

CISA Adds Industrial Control System Specialists to Joint Cyber Defense Collaborative

Companies in the space are trying to shape public policy and push for money agencies can use to—among other things—track their devices and other assets.

Cybersecurity

CISA Seeks Comment on Visibility Effort Being Piloted with Cloud Service Providers

The agency is starting to spend the $690 million it got through the American Rescue Act to monitor security and respond to incidents across federal civilian networks.

Cybersecurity

Federal Law Enforcement Warns Against Hackers Targeting Crypto Companies

Three agencies warned that North Korean-sponsored Lazarus Group and subsidiaries are targeting companies linked to blockchain technology and working with crypto and NFTs.

Cybersecurity

What CISA Wants Critical Infrastructure Partners to Report on Cyber Incidents

A new guide provides clues into how the agency might be thinking of crucial details, such as what should count as an “incident” under a new law.

Cybersecurity

Joint Alert Warns Advanced Hackers Have Developed Tool Targeting Industrial Control Systems

The design of the tool, which allows full system access to certain operational technology in environments such as power plants and water treatment facilities, can also be used by less sophisticated attackers.

Cybersecurity

FCC Chair Claims Cybersecurity Role Congress Crafted for CISA

The commission is joining the fray in a budding turf fight at the Cybersecurity and Infrastructure Security Agency that also involves sector risk management agencies like the Department of Energy.

Cybersecurity

White House Asserts Micromanagement Critique Was About a Previous Administration

Debate is heating up over the role of sector-risk management agencies in shoring up security of the nation’s critical infrastructure.

Cybersecurity

6 Takeaways On Cybersecurity Policy from the President’s FY 2023 Budget

The administration expects CISA to grow by just under 300 full-time employees over the next year, for example.