Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’

Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’
Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’

“Strategic competition is alive and well in cyberspace, and we’re doing it every day with persistent engagement,” the CYBERCOM and NSA leader said.

DISA Head: DoD Working To Modernize ICAM, C2, Data Use

DISA Head: DoD Working To Modernize ICAM, C2, Data Use
DISA Head: DoD Working To Modernize ICAM, C2, Data Use

“I have a mantra of ‘I want to kill to the [Common Access Card] as the primary authentication mechanism for the department’,” Lt. Gen. Robert Skinner said. “Industry has better authentication, and it’s not just two-factor, it’s truly multi-factor authentication.”

China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days

China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days
China’s New Data Security Law Will Provide It Early Notice Of Exploitable Zero Days

The law’s vulnerability disclosure provisions will give the Chinese government a head start on remediating — and potentially exploiting — zero-day vulnerabilities, possibly to include those discovered in tech used by the Defense Department, Intelligence Community, and across the US public and private sectors more broadly.

US Playing Long Game To Pressure China On Cyber Ops: Experts

US Playing Long Game To Pressure China On Cyber Ops: Experts
US Playing Long Game To Pressure China On Cyber Ops: Experts

“It’s part of a larger diplomatic strategy,” cyber policy expert James Lewis said of the US attribution to China for Microsoft Exchange hacks earlier this year.

US, Allies, Partners Formally Attribute Exchange Hacks To China

US, Allies, Partners Formally Attribute Exchange Hacks To China
US, Allies, Partners Formally Attribute Exchange Hacks To China

“The PRC’s pattern of irresponsible behavior in cyberspace is inconsistent with its stated objective of being seen as a responsible leader in the world,” a senior administration official said on Sunday night.

China Likely Outed Soon For Exchange Hacks

China Likely Outed Soon For Exchange Hacks
China Likely Outed Soon For Exchange Hacks

The Exchange campaign attribution will also provide hints about the role of the first national cyber director in such incidents. NSA veteran Chris Inglis was confirmed for the position just weeks ago.

Hacks Drive Growing Calls For Mandatory Cyber Data Sharing

Hacks Drive Growing Calls For Mandatory Cyber Data Sharing
Hacks Drive Growing Calls For Mandatory Cyber Data Sharing

The cyber executive order “properly emphasizes” information sharing. Sens. Peters and Portman float updating FISMA. FERC calls for mandatory pipeline cyber standards. Report says vulnerable Exchange Server “most likely culprit” at Colonial. FireEye details DarkSide’s business ops.

Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting

Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting
Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting

“It reflects a fundamental shift in our mindset — from incident response to prevention, from talking about security to doing security,” a senior administration official says.

Automation, ID & Zero Trust: NIST Scientists Speak

Zero-trust security “is not one single product that one can purchase off the shelf,” a NIST scientist observes. But underlying zero trust’s many component parts are a few critical elements, including identity and automation.

VPN Patch Released For 24 Federal Agencies

VPN Patch Released For 24 Federal Agencies
VPN Patch Released For 24 Federal Agencies

The patch secures a zero-day vulnerability disclosed last month and is just one of four vulnerabilities being actively exploited in Pulse Connect Secure.

CISA Investigates Possible Hacks of Federal Agencies

CISA Investigates Possible Hacks of Federal Agencies
CISA Investigates Possible Hacks of Federal Agencies

“We are working with each agency to validate whether an intrusion has occurred and will offer incident response support accordingly,” CISA’s deputy executive assistant director told Breaking Defense.

‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner

‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner
‘Mandatory’ Cyber Info Sharing Bill Coming, Says Senate Intel Chair Warner

“My hope is that we can create this structure… to get an early warning system,” the Senate Intel Committee chair said. “Voluntary sharing is no longer effective.”

US Agencies, Defense Companies Hacked Via VPNs

US Agencies, Defense Companies Hacked Via VPNs
US Agencies, Defense Companies Hacked Via VPNs

Threat actors are targeting one newly discovered and three previously known vulnerabilities in Pulse Connect Secure enterprise VPNs, according to a CISA emergency directive and alert, as well as blog posts by FireEye and Ivanti. “There is no indication the identified backdoors were introduced through a supply chain compromise of the company’s network or software deployment process,” FireEye noted.

White House Winds Down SolarWinds, Exchange Cyber Teams

White House Winds Down SolarWinds, Exchange Cyber Teams
White House Winds Down SolarWinds, Exchange Cyber Teams

“The innovations… and the lessons learned from these responses will be used to improve future unified, whole of government responses to significant cyber incidents,” the White House says.