Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity

Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity
Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity

“Academics will sit back and say, ‘Well, if you just did that and that and that, you would have avoided it.’ But if there’s no way to impose risk or consequences for [threat actors] doing it, your day is coming,” Mandia said.

China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days

China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days
China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days

The law’s vulnerability disclosure provisions will give the Chinese government a head start on remediating — and potentially exploiting — zero-day vulnerabilities, possibly to include those discovered in tech used by the Defense Department, Intelligence Community, and across the US public and private sectors more broadly.

Senators Introduce Bill Requiring Notification Of Cyber Incidents Within 24 Hours

Senators Introduce Bill Requiring Notification Of Cyber Incidents Within 24 Hours
Senators Introduce Bill Requiring Notification Of Cyber Incidents Within 24 Hours

“We shouldn’t be relying on voluntary reporting to protect our critical infrastructure,” Sen. Warner said.

US, Allies, Partners Formally Attribute Exchange Hacks To China

US, Allies, Partners Formally Attribute Exchange Hacks To China
US, Allies, Partners Formally Attribute Exchange Hacks To China

“The PRC’s pattern of irresponsible behavior in cyberspace is inconsistent with its stated objective of being seen as a responsible leader in the world,” a senior administration official said on Sunday night.

China Likely Outed Soon For Exchange Hacks

China Likely Outed Soon For Exchange Hacks
China Likely Outed Soon For Exchange Hacks

The Exchange campaign attribution will also provide hints about the role of the first national cyber director in such incidents. NSA veteran Chris Inglis was confirmed for the position just weeks ago.

US, UK Warn Of New Worldwide Russian Cyberespionage

US, UK Warn Of New Worldwide Russian Cyberespionage
US, UK Warn Of New Worldwide Russian Cyberespionage

“This is a good reminder that the GRU remains a looming threat, which is especially important given the upcoming Olympics, an event they may well attempt to disrupt,” observed John Hultquist, VP of Analysis at Mandiant Threat Intelligence.

US ‘Retains Clear Superiority’ In Cyber; China Rising: IISS Study

US ‘Retains Clear Superiority’ In Cyber; China Rising: IISS Study
US ‘Retains Clear Superiority’ In Cyber; China Rising: IISS Study

“China is a second-tier cyber power but, given its growing industrial base in digital technology, it is the state best placed to join the US in the first tier,” an IISS report says.

CISA Investigates Possible Hacks of Federal Agencies

CISA Investigates Possible Hacks of Federal Agencies
CISA Investigates Possible Hacks of Federal Agencies

“We are working with each agency to validate whether an intrusion has occurred and will offer incident response support accordingly,” CISA’s deputy executive assistant director told Breaking Defense.

‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner

‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner
‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner

“My hope is that we can create this structure… to get an early warning system,” the Senate Intel Committee chair said. “Voluntary sharing is no longer effective.”

White House Winds Down SolarWinds, Exchange Cyber Teams

White House Winds Down SolarWinds, Exchange Cyber Teams
White House Winds Down SolarWinds, Exchange Cyber Teams

“The innovations… and the lessons learned from these responses will be used to improve future unified, whole of government responses to significant cyber incidents,” the White House says.

Israelis May Ban High Tech Cars From Bases: ‘Perfect Espionage Vector’

Israelis May Ban High Tech Cars From Bases: ‘Perfect Espionage Vector’
Israelis May Ban High Tech Cars From Bases: ‘Perfect Espionage Vector’

“Imagine you work at a chemical research part of a base. Its location is secret. But you have a smart car. Through other espionage activities, I found out you work there. I hack your phone or your car’s online account,” Keatron Evans said. “I track your location as you go to work every day. Now I know the specific GPS location of your work facility. It goes downhill quickly from there.”

SolarWinds Hack: ‘The Truth Is Much More Complicated’

SolarWinds Hack: ‘The Truth Is Much More Complicated’
SolarWinds Hack: ‘The Truth Is Much More Complicated’

SolarWinds threat actor reportedly accessed DHS emails and DoE schedules. Cyberespionage campaigns are “the types of things we should expect [Russia] to do,” one cybersecurity expert observed. “I’m not arguing we shouldn’t have a response. We should respond. …My only argument is that we should not overact.”

Why Was The SolarWinds Campaign So Difficult to Detect?

Why Was The SolarWinds Campaign So Difficult to Detect?
Why Was The SolarWinds Campaign So Difficult to Detect?

Only after months of investigation by nearly 100 highly skilled digital forensics experts did FireEye discover the malicious “implant” in the most unlikely place. We break it all down in plain language.

CISA ‘Strongly Urges’ Patching As Widespread Exchange Server Hacking Continues

CISA ‘Strongly Urges’ Patching As Widespread Exchange Server Hacking Continues
CISA ‘Strongly Urges’ Patching As Widespread Exchange Server Hacking Continues

Security professionals are increasingly observing multiple threat actors, from nation-states to cryptominers, exploiting the vulnerabilities. As for China-based HAFNIUM, “This is part of the much larger Chinese effort to constantly be ferreting out new vulnerabilities and then exploiting them — with no end in sight,” said Heritage’s Dean Cheng. “The Chinese will pay close attention to the Biden administration response.”