Cybersecurity

Nakasone deflects senators' invitations to seek domestic spying powers

Lawmakers have continued to prod the NSA chief to request new surveillance authorities that might prevent another SolarWinds-type breach.

Cybersecurity

Microsoft patches new Exchange CVEs, credits NSA with discovery

The new vulnerabilities found in Exchange servers running on-premises are separate from zero-day exploits discovered and announced in March.

Cybersecurity

IC warns that U.S. adversaries are ramping up cyber attacks

The worldwide threat assessment by the U.S. intelligence community comes one day before the heads of several agencies are scheduled to testify during open and closed session to the Senate Select Committee on Intelligence.

Cybersecurity

Biden taps Inglis, Easterly for top cyber jobs

National Security Agency veterans will serve as first national cyber director and lead the Cybersecurity and Infrastructure Security Agency.

Cybersecurity

Top cyber slots still unfilled amid multiple crises

Chris Krebs, the former CISA director, has been vocal in recent months about the need for his old job to be filled in short order while the administration confronts multiple cybersecurity problems within the federal government.

Cybersecurity

Senators seek details on Einstein's performance and limitations

Ahead of its scheduled reauthorization next year, two senators are seeking detailed information about Einstein, a government cybersecurity program that has come into the spotlight in the wake of the breach involving SolarWinds.

Cybersecurity

CISA, FBI warn of hacking threat against Fortinet product

The advisory warns that an unattributed threat actor is using known vulnerabilities in a Fortinet security product to gain access to government and industry networks.

Cybersecurity

Krebs cautions on push for national cyber director

The former CISA chief expressed confidence in Deputy National Security Advisor Anne Neuberger to help the White House confront the multiple cybersecurity incidents it is facing.

Cybersecurity

Mayorkas announces cyber 'sprints' on ransomware, ICS, workforce

The Homeland Security secretary announced a series of focused efforts to address issues around ransomware, critical infrastructure and the agency's workforce that will all be launched in the coming weeks.

Acquisition

Expected breach disclosure mandates will test government-industry cooperation

The White House and lawmakers are eyeing steps to make sure contractors have to alert the federal government to cybersecurity breaches on their systems, but expect companies to balk at rules that put them at risk for legal action or require the disclosure of trade secrets.

Digital Government

NIST framework focuses on election cybersecurity

The new draft framework combining election security and cybersecurity is the first of its kind for NIST.

Cybersecurity

Impatient lawmakers press Biden for cyber director nominee

President Joe Biden has said cybersecurity will be a top priority for his administration, but two senior positions focused on the issue remain either vacant or held by an acting official.

Digital Government

Industry groups call for TMF reforms following funding boost

The groups' call for changes to how the government operates the modernization fund echoes concerns that multiple former CIOs voiced to FCW this month in interviews.

Modernization

GAO warns on cyber risks to power grid

The country's electrical systems are increasingly susceptible to cyberattacks, according to government auditors, and there is uncertainty about the extent to which a localized attack might cascade through power distribution systems.

Cybersecurity

CISA head: Group of SolarWinds victims is 'solidified'

Brandon Wales, the acting director of the Cybersecurity and Infrastructure Security Agency, also said his agency is still working to determine if any federal networks were compromised by vulnerabilities discovered in Microsoft Exchange.

Cybersecurity

Agency hacks could accelerate push to zero trust security model

Chris DeRusha, the federal chief information security officer, said agencies largely have the tools they need to adopt zero trust security protocols but making a change will "require a shift in mindset."

Cybersecurity

Senators press for federal agency accountability over SolarWinds

Three top cybersecurity officials struggled to answer questions from lawmakers about who is to blame for the government's failure to stop the breach of nine federal agencies.

Cybersecurity

King: Mandatory breach disclosure bill coming soon

Sen. Angus King (I-Maine), a co-chair of the Cyberspace Solarium Commission, said he plans to propose new legislation in the coming weeks.

Cybersecurity

House lawmakers seek answers on SolarWinds from agency chiefs

The letters sent to senior administration officials come as Senate lawmakers plan to hold a hearing on the breach of federal networks.

Digital Government

IC: Foreign actors tried to affect U.S. election via influence campaigns, but not by hacking

The intelligence community's newly declassified report largely concludes Russia attempted to meddle in the U.S. election through influence operations but did not attempt the kinds of cyberattacks observed in 2016.