Defense Systems

Final rule, formal training orgs on CMMC could hit this summer

A final rule on the Defense Department's unified cybersecurity standard could debut as soon as this summer but implementation hinges on standing up a formal training system.

Defense Systems

Austin tackles cyber and social policy

Senators question defense secretary nominee about cyber and racism as several National Guardsmen removed from inauguration duty.

Defense Systems

Trump issues last-minute order targeting foreign cyber threats

A Jan. 19 executive order from Donald Trump in the waning hours of his presidency aims to force cloud providers to keep more complete records about their customers to support U.S. investigations of hacks and other computer crimes.

Defense Systems

Rob Joyce to lead NSA cyber office

Joyce's predecessor, Anne Neuberger, is joining President-elect Joe Biden's administration as a deputy national security advisor.

Defense Systems

FireEye not ready to name Russians as SolarWinds attackers

The company has not seen enough evidence to positively trace the hackers behind the ongoing SolarWinds Orion hack to Russian entities, a FireEye executive said.

Defense Systems

CMMC, industrial capital strategy could continue in Biden's DOD

The Defense Department's top buyer, Ellen Lord, said the incoming Biden administration will have to contend with adversarial investments and cybersecurity weaknesses in the contractor base.

Defense Systems

CISA details attacks on cloud services

The Cybersecurity and Infrastructure Security Agency warned of attacks that leverage phishing and email forwarding vulnerabilities as well as one that bypassed multifactor authentication.

Defense Systems

Russia behind SolarWinds hack, intel agencies claim

According to a Jan. 5 statement from the Cyber Unified Coordination Group, “an Advanced Persistent Threat actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks."

Defense Systems

Evanina: SolarWinds victims numbers 'will continue to grow'

A top counterintelligence official today said the number of known federal agencies affected by the SolarWinds hack will likely to continue to rise beyond initial estimates.

Defense Systems

SolarWinds hackers accessed DOJ email

Suspected Russian intelligence agents are believed to have accessed "around" 3% of email inboxes, but not any classified systems, according to a Justice Department spokesman.

Defense Systems

Hackers breaking into networks without SolarWinds, CISA says

The Cybersecurity and Infrastructure Security Agency says hackers are breaching federal networks by exploiting methods besides the SolarWinds Orion vulnerabilities.

Policy

IGs Ask: How Well Do Feds Share Cyber-Threat Info?

A key government contractor has already weighed in with a scathing review.

Defense Systems

White House task force says Russia likely to blame for SolarWinds hack

The Cyber Unified Coordination Group said in a statement on Tuesday that fewer than 10 government agencies have been "compromised by follow-on activity" on federal systems as a result of the hack.

Threats

Russia ‘Likely’ Behind SolarWinds Hack, Cyber Response Agencies Say

The Cyber Unified Coordination Group believes fewer than ten government agencies were compromised by the still-active intelligence operation.

Science & Tech

Two-Thirds of DOD’s Major IT Projects Are Behind Schedule, GAO Found

Defense officials say lack of talent is slowing the adoption of cybersecurity best practices.

Defense Systems

SolarWinds hit with investor lawsuit over hack

SolarWinds is facing a class-action lawsuit in a Texas court from an investor who says the company misled the public and its customers by not disclosing a known vulnerability to its update server.

Defense Systems

CISA updates on SolarWinds compromise

To help agency leaders mitigate the SolarWinds Orion software compromise, the Cybersecurity and Infrastructure Security Agency issued new guidance and posted two new resources.

Ideas

The SolarWinds Hack Doesn’t Demand a Violent Response

Major retaliation is more likely to spur escalation than improve deterrence.

Defense Systems

50 orgs 'genuinely impacted' by SolarWinds hack, FireEye chief says

Approximately 50 organizations downloaded malicious code via SolarWinds software and were "genuinely impacted" by the sophisticated hacking campaign, according to FireEye CEO Kevin Mandia.