Cyber Defense
CISA warns threat hunting staff of end to Google, Censys contracts as agency cuts set in
“We understand the importance of these tools in our operations and are actively exploring alternative tools to ensure minimal disruption,” said the email sent to several hundred CISA cyber threat hunters.
Updated
MITRE-backed cyber vulnerability program to lose funding Wednesday
Organizations across industry, government, national security and critical infrastructure rely on the CVE Program, which serves as the de-facto global standard for vulnerability identification and management.
The need for collaborative global cyber diplomacy is growing
COMMENTARY | Strengthening global cyber collaboration is needed now more than ever.
NIST releases finalized guidelines on protecting AI from attacks
The final guidance for defending against adversarial machine learning offers specific solutions for different attacks, but warns current mitigation is still developing.
NIST’s vulnerability database logjam is still growing despite attempts to clear it
Vulnerability submissions increased 32% in 2024, NIST said. The agency is considering machine learning to automate certain vulnerability analysis tasks.
Exclusive
Lawmakers seek DHS records in probe of US response to Chinese cyber campaigns
The House Homeland Security Committee wants DHS to provide internal documents on China’s Volt and Salt Typhoon hacking units, according to a letter being sent Monday.
Cyberspace Solarium Commission turns five years old
The commission has largely influenced cybersecurity policymaking in Congress through the first half of the decade.
IBM contract for overseas cyber assistance canned amid USAID shutdown
The foreign aid agency — a prime target of President Donald Trump’s agenda to eliminate perceived government waste — declared cybersecurity an economic development issue in 2021.
Veterans Affairs loses cybersecurity migration project lead after DOGE layoffs
Another project co-lead is among the 21 legacy USDS staffers who chose to leave civil service this week rather than work with DOGE.
DOGE employee Edward Coristine lands at CISA with DHS email
A handle dubbed “Rivage” was reportedly tied to Coristine, and used to discuss and solicit hacking activities with a cybercrime syndicate known as The Com.
Trump to nominate former RNC official to be national cyber director
It’s not clear how Sean Cairncross would address ongoing ONCD efforts, as the Trump administration has sought to refocus certain cyber priorities in the federal government.
Coast Guard workforce lacks maritime cyber expertise, watchdog says
The maritime service says it will develop “competency requirements” for relevant personnel by the end of December. It’s also planning new procedures to document maritime cyber incidents.
Featured eBooks
Space companies say cyber threat intelligence is often overclassified, unactionable
Space and aerospace industry feedback from a series of government-run workshops noted that such threat intelligence is difficult to translate into actionable cyber efforts.
Biden signs executive order inspired by lessons from recent cyberattacks
The order gives CISA more eyes to hunt cyber threats on government networks and directs agencies and contractors to be more transparent about the security of their software stockpiles.
Forthcoming executive order seeks to plug holes in federal cyber practices
The eleventh-hour cybersecurity executive action asks agencies to rethink software procurement, supply chains and AI, among other things.
Exclusive