Acquisition

When can US spies buy your personal data? New guidelines are coming

Certain missions require government acquisition of personal information collected by data brokers, and appropriate safeguards need to be put in place, the official said at a Cyber Command-hosted event.

Acquisition

Wyden bill requires new cyber standards in federal tech procurement

The legislation comes in the wake of several cyber incidents targeting the federal government.

Policy

Section 702 renewal has support in Congress, but intelligence officials are leery of warrant measure

The disputed surveillance authority expires April 19, and the intelligence community is sending a full-court press to keep it from garnering significant privacy reforms.

Cybersecurity

Congress tries again for comprehensive data privacy bill

The bill would establish national data privacy standards, with the Federal Trade Commission crafting rules for enforcement.

Cybersecurity

China-backed operatives used fake social profiles to gauge US political division, Microsoft says

Some of the fake accounts used AI-generated images, and have doubled or tripled their followers since being detected, the company told Nextgov/FCW.

Cybersecurity

Linux backdoor was a long con, possibly with nation-state support, experts say

If the XZ Utils vulnerability hadn’t been caught in time, hackers would have had a “skeleton key to the world,” one analyst told Nextgov/FCW.

Breaking News People

White House deputy national cyber director to step down next week

Camille Stewart Gloster’s last day will be Tuesday, she told Nextgov/FCW. It’s unknown who will fill the position.

Cybersecurity

Return of net neutrality will hamstring some foreign broadband firms, FCC official says

The reclassification of broadband as a Title II service will give the Federal Communications Commission new power over internet service providers, and the agency says it will be a boon to U.S. network security.

Cybersecurity

Microsoft at fault for ‘avoidable errors’ leading to Chinese email hack last year, DHS group finds

The company’s cybersecurity culture contributed to an environment that enabled the incident, according to the findings.

Cybersecurity

CISA resource looks to help high-risk groups thwart cyberattacks

Civil society organizations, community groups and others often lack budgets and resources needed to defend against hackers.

Cybersecurity

CISA sounds alarm on deep-seated vulnerability in Linux tool

The malicious code was introduced by a user that has long-contributed to the open-source ecosystem.

Cybersecurity

DOD stands up new civilian-facing cyber policy office

The nominated head of the new Pentagon office is awaiting confirmation in Congress.

Emerging Tech

Clinton warns of hackers’ ‘leap in technology’ impacting the 2024 election

Rapid AI-backed advancements have let bad actors craft more sophisticated deepfakes and other sham content that could sway election results, she said.

Cybersecurity

2 wireless protocols expose mobile users to spying — the FCC wants to fix that

The protocols are a cornerstone of wireless communications but may contain flaws that enable hackers to tap into Americans’ mobile activities, the agency says.

Cybersecurity

CISA's proposed framework for cyber incident reporting rules includes subpoena power

The rules also require that covered entities that pay ransomware hackers to regain control of their systems and data must report such payments to CISA.

Cybersecurity

Some banks moving too slow to address AI-powered cyberthreats, Treasury says

The agency’s findings will be distributed to Capitol Hill with the hope of drumming up legislation or other initiatives to study the risks.

Policy

US targets 6 to 8 month timeframe for new nations to join spyware pact

Six new countries joined the agreement last week, and the State Department was working behind the scenes to initially get more signed on.

Cybersecurity

US accuses Chinese hackers of 14-year campaign targeting government officials

The coordinated charges include sanctions on Chinese government-affiliated hackers and an up to $10 million reward for information about the defendants.