Cybersecurity

State Department to levy visa restrictions on spyware abusers

The move builds on several actions taken by the Biden administration in the past year to counter abusive commercial spyware practices.

Cybersecurity

Treasury sanctions Iranian cyber officials tied to 2023 water system hacks

The hackers targeted a batch of Israeli-made programmable logic controllers used in water treatment plants around the U.S.

Cybersecurity

Ex-CIA officer and WikiLeaks source sentenced to 40 years for largest breach in agency history

Joshua Adam Schulte was found to have abused administrative privileges and secretly transmitted the documents in 2016.

Cybersecurity

National Cyber Strategy needs better implementation measures, GAO argues

The White House Office of the National Cyber Director can improve on performance measures and cost estimations, the U.S. federal oversight agency said in a Thursday analysis.

Cybersecurity

Agencies must disconnect all exposed Ivanti products by Friday, CISA says

The directive follows a related warning issued last month about cybersecurity flaws in Ivanti systems.

Cybersecurity

Biden to veto any efforts to shutter SEC cyber disclosure rules

The SEC argues the disclosure rule forces firms to be more transparent with investors. Opponents say it may compromise sensitive business data and publicize vulnerabilities.

Cybersecurity

Cyber, intelligence chiefs urge U.S. to strengthen against Chinese cyber threats

In a collective call to action, officials warned of invasive actions that China-backed hackers can take against U.S. infrastructure and elections.

Cybersecurity

US disrupts China-linked cyber campaign impacting critical infrastructure, Justice officials say

The hackers infected privately owned small office/home office routers to conceal the origins of their intrusions into critical infrastructure systems.

Cybersecurity

Top cyber, intelligence chiefs to call out China as leading cyber threat

Researchers and officials have previously designated China as a clandestine, preparatory operator in cyberspace, quietly breaching and securing systems to use to their advantage at a later time.

Exclusive Cybersecurity

‘Relatively few’ agency policies met standards for IoT security, OMB reports

Early last year, the White House office ran a sweeping assessment on agency IoT device security policies. Most fell short on aligning with NIST guidance, according to a letter sent to Sen. Mark Warner, D-Va.

People

Former DHS employees sentenced for plot to steal government software, databases

The trio wanted to to build a commercial software product that would have been sold to government agencies.

People

Retiring lawmaker Ruppersberger was one of first to sound alarm on Huawei, ZTE in US networks

The Maryland congressman, who announced he would not seek reelection at the end of his term, set a precedent for modern-day cybersecurity policy.

Cybersecurity

Proposed law aims to boost food and agriculture industry’s cyber posture

The bill would direct multiple stakeholders to conduct exercises that simulate when the food and agriculture sectors are hacked.

Defense

NSA illegally purchases Americans’ internet data without a warrant, senator says

The NSA’s purchases of commercial metadata without a court order — revealed in documents exchanged with Sen. Ron Wyden — violate consumer protection laws, the Oregon Democrat claims.

Cybersecurity

Expect ‘AI versus AI’ cyber activity between US and adversaries, Pentagon official says

Researchers and officials say AI will usher in the next phase of cyber warfare, enabling new ways to carry out classic cyberattacks and build out new hacking tools.

Cybersecurity

US regulators have done little to address firmware vulnerabilities, think tank argues

Firmware connects the hardware and software of a device, but efforts to protect it have been absent in many of the government’s recent cybersecurity initiatives, according to the report.

Acquisition

GSA used ‘egregiously flawed’ data to clear purchase of Chinese-made cameras, watchdog says

The inspector general's report noted that the acquired video conferencing cameras were not compliant with the 1979 Trade Agreements Act and contained security flaws that, in some instances, had still gone unpatched.