Cybersecurity

US sanctions Chinese company that helped facilitate espionage hacks

Integrity Technology Group, known to researchers as Flax Typhoon, contracted with China’s Ministry of State Security to carry out infiltrations into internet of things devices, the FBI previously said.

Cybersecurity

Lawmakers request briefing from Treasury secretary on Chinese hack

The compromised third-party offering was a commercial remote services tool not listed in the marketplace for FedRAMP, the government’s cloud security compliance framework.

Cybersecurity

Chinese-sponsored hackers accessed Treasury documents in ‘major incident’

The incident comes in the final days of the Biden presidency and as officials work to root out China-tied hackers from U.S. telecommunications systems.

Cybersecurity

Major cyber news drops under the buzzer for 2024

A ninth U.S. telecommunications provider fell onto Salt Typhoon’s victim list, and the UN’s controversial cybercrime treaty was adopted.

Cybersecurity

Hundreds of organizations were notified of potential Salt Typhoon compromise

Some of the exploited vulnerabilities have had fixes available for several years. One provider’s management system was protected with a basic numeric password.

Cybersecurity

US charges Israeli-Russian national with making software for LockBit ransomware gang

LockBit has made headlines for years, allowing purveyors of its malware to haul away millions of dollars from victims.

Cybersecurity

Congress approves 2025 NDAA with important cyber provisions

Left out was language that would have helped clarify the scope and reach of a controversial surveillance power that was renewed in April.

Cybersecurity

CISA orders federal agencies to secure their cloud environments

Federal civilian agencies are compelled by the Binding Operational Directive to adopt specific cloud standards under SCuBA, a government blueprint that helps agencies assess cloud security security guidelines.

Cybersecurity

CISA issues updated draft of national cyber incident response plan

The NCIRP was first released in 2016. The updates include pathways for non-federal groups to get involved in responding to devastating cyberattacks.

Cybersecurity

Salt Typhoon attacks prompt talk of hacking back against China

In classified settings, lawmakers have often asked national security officials why American cyber forces don’t go on the attack more often, one senator said.

Cybersecurity

Agencies look to automation software to usher in next phase of post-quantum security

The Cybersecurity and Infrastructure Security Agency is working with select agencies to implement post-quantum cryptography, and will turn to vendors to further secure federal data.

Cybersecurity

Senate bill would require FCC to issue binding cyber rules for telecom firms

The measure from Sen. Ron Wyden, D-Ore. comes in the wake of Chinese-backed hackers breaching a swath of major telecommunications providers.

Cybersecurity

FY2025 NDAA targets spyware threats to U.S. diplomats, military devices

The language comes as the State department has pressed foreign governments to collectively set standards to prevent spyware abuses.

Cybersecurity

Lawmakers targeted in encrypted messaging phishing scam

Officials have been urging Americans and federal staff to pivot to encrypted messaging services amid a recent Chinese breach into telecommunications networks.

Cybersecurity

FCC proposes updates to wiretap security standards following Chinese telecom hacks

Several lawmakers have called for the agency to reform wiretap standards governed by the Communications Assistance for Law Enforcement Act, or CALEA.

Cybersecurity

At least 8 US carriers hit in Chinese telecom hacks, senior official says

The hacks carried out by the Salt Typhoon group impacted a couple dozen countries and may have been ongoing for one to two years, the official said.

Cybersecurity

Senators call for investigation of DOD’s comms following Chinese telecom breach

“DOD’s failure to secure its unclassified voice, video and text communications with end-to-end encryption technology has left it needlessly vulnerable to foreign espionage,” Sens. Eric Schmitt, R-Mo., and Ron Wyden, D-Ore., wrote to the Pentagon’s inspector general.

Cybersecurity

NIST issues updated cyber guides focused on assessments and communication

Two new volumes were released by the National Institute of Standards and Technology that aim to broaden the publication’s applicability to organizations outside federal agencies.

Cybersecurity

Chinese telecom espionage began with ‘much broader’ aims, officials say

The U.S. has been investigating the Salt Typhoon hackers since late spring and early summer this year, a senior FBI official said.

Cybersecurity

US proposes rule to prevent the sale of financial data to foreign adversaries

Data brokers would have to comply under terms set by the Fair Credit Reporting Act, in an effort that aims to stop exploitation of Americans’ data overseas.