Ukraine war drives rising concern about nation-state hackers, survey says

Ukraine war drives rising concern about nation-state hackers, survey says
Ukraine war drives rising concern about nation-state hackers, survey says

“Foreign governments” are now the No. 1 cybersecurity concern for US public sector IT professionals, reports SolarWinds, itself rebuilding after a 2020 hack blamed on Russia.

Hacks raised questions about Pentagon’s role in securing cyber and networks: 2021 In Review

Hacks raised questions about Pentagon’s role in securing cyber and networks: 2021 In Review
Hacks raised questions about Pentagon’s role in securing cyber and networks: 2021 In Review

The military focused its efforts on networked warfare and the US government responded to cyberattacks.

‘The game has changed’: VMware exec says defense industry faces destructive cyberattacks, belligerent foes

‘The game has changed’: VMware exec says defense industry faces destructive cyberattacks, belligerent foes
‘The game has changed’: VMware exec says defense industry faces destructive cyberattacks, belligerent foes

VMware’s Tom Kellermann linked increasingly aggressive attacks to geopolitical tensions with Russia and Belarus.

Former CISA head warns of rivals’ ‘destructive’ cyber capabilities

Former CISA head warns of rivals’ ‘destructive’ cyber capabilities
Former CISA head warns of rivals’ ‘destructive’ cyber capabilities

“There’s one line [in the notice] that should scare the hell out of everyone everywhere,” Chris Krebs said.

Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’

Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’
Nakasone: Cold War-style deterrence ‘does not comport to cyberspace’

“Strategic competition is alive and well in cyberspace, and we’re doing it every day with persistent engagement,” the CYBERCOM and NSA leader said.

Russian ‘SolarWinds’ Hackers Launch New Attack On IT Supply Chain, Microsoft Says

Russian ‘SolarWinds’ Hackers Launch New Attack On IT Supply Chain, Microsoft Says
Russian ‘SolarWinds’ Hackers Launch New Attack On IT Supply Chain, Microsoft Says

New campaign is evidence “Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain and establish a mechanism for surveilling — now or in the future — targets of interest to the Russian government,” researchers say.

DISA Head: DoD Working To Modernize ICAM, C2, Data Use

DISA Head: DoD Working To Modernize ICAM, C2, Data Use
DISA Head: DoD Working To Modernize ICAM, C2, Data Use

“I have a mantra of ‘I want to kill to the [Common Access Card] as the primary authentication mechanism for the department’,” Lt. Gen. Robert Skinner said. “Industry has better authentication, and it’s not just two-factor, it’s truly multi-factor authentication.”

Nakasone Now Sees Ransomware, Influence Ops As ‘National Security’ Threats

Nakasone Now Sees Ransomware, Influence Ops As ‘National Security’ Threats
Nakasone Now Sees Ransomware, Influence Ops As ‘National Security’ Threats

“We aim to convey that, ‘Hello, we are from the government, and we’re here to help’ is not a scary idea,” the general joked, alluding to a famous quote by former President Reagan.

Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity

Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity
Mandiant CEO Sees ‘Coordinated National, Global Response’ As Next Advance In Cybersecurity

“Academics will sit back and say, ‘Well, if you just did that and that and that, you would have avoided it.’ But if there’s no way to impose risk or consequences for [threat actors] doing it, your day is coming,” Mandia said.

US Playing Long Game To Pressure China On Cyber Ops: Experts

US Playing Long Game To Pressure China On Cyber Ops: Experts
US Playing Long Game To Pressure China On Cyber Ops: Experts

“It’s part of a larger diplomatic strategy,” cyber policy expert James Lewis said of the US attribution to China for Microsoft Exchange hacks earlier this year.

China Likely Outed Soon For Exchange Hacks

China Likely Outed Soon For Exchange Hacks
China Likely Outed Soon For Exchange Hacks

The Exchange campaign attribution will also provide hints about the role of the first national cyber director in such incidents. NSA veteran Chris Inglis was confirmed for the position just weeks ago.

Mandatory Cyber Reporting Within 24 Hours: Sen. Warner Bill

Mandatory Cyber Reporting Within 24 Hours: Sen. Warner Bill
Mandatory Cyber Reporting Within 24 Hours: Sen. Warner Bill

Sen. Warner’s draft legislation, long expected, marks one of the first attempts to create a federal law mandating cyber incident reporting by some entities. Notably, the bill provides reporting entities with a degree of privacy and legal protection.

Hacks Drive Growing Calls For Mandatory Cyber Data Sharing

Hacks Drive Growing Calls For Mandatory Cyber Data Sharing
Hacks Drive Growing Calls For Mandatory Cyber Data Sharing

The cyber executive order “properly emphasizes” information sharing. Sens. Peters and Portman float updating FISMA. FERC calls for mandatory pipeline cyber standards. Report says vulnerable Exchange Server “most likely culprit” at Colonial. FireEye details DarkSide’s business ops.

Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting

Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting
Biden Orders Fed Cybersecurity Boost; Targets Prevention, Reporting

“It reflects a fundamental shift in our mindset — from incident response to prevention, from talking about security to doing security,” a senior administration official says.