Cybersecurity
CISA orders federal agencies to secure their cloud environments
Federal civilian agencies are compelled by the Binding Operational Directive to adopt specific cloud standards under SCuBA, a government blueprint that helps agencies assess cloud security security guidelines.
Defense
Several Pentagon commands failed to keep good track of classified mobile devices, audit finds
The report comes amid an ongoing Chinese intrusion into U.S. telecom systems. Congress is also working to shore up device protections for servicemembers through the annual defense authorization bill.
Cybersecurity
CISA issues updated draft of national cyber incident response plan
The NCIRP was first released in 2016. The updates include pathways for non-federal groups to get involved in responding to devastating cyberattacks.
Cybersecurity
Salt Typhoon attacks prompt talk of hacking back against China
In classified settings, lawmakers have often asked national security officials why American cyber forces don’t go on the attack more often, one senator said.
Cybersecurity
Senate bill would require FCC to issue binding cyber rules for telecom firms
The measure from Sen. Ron Wyden, D-Ore. comes in the wake of Chinese-backed hackers breaching a swath of major telecommunications providers.
Cybersecurity
FY2025 NDAA targets spyware threats to U.S. diplomats, military devices
The language comes as the State department has pressed foreign governments to collectively set standards to prevent spyware abuses.
Cybersecurity
Lawmakers targeted in encrypted messaging phishing scam
Officials have been urging Americans and federal staff to pivot to encrypted messaging services amid a recent Chinese breach into telecommunications networks.
Cybersecurity
FCC proposes updates to wiretap security standards following Chinese telecom hacks
Several lawmakers have called for the agency to reform wiretap standards governed by the Communications Assistance for Law Enforcement Act, or CALEA.
Cybersecurity
At least 8 US carriers hit in Chinese telecom hacks, senior official says
The hacks carried out by the Salt Typhoon group impacted a couple dozen countries and may have been ongoing for one to two years, the official said.
Cybersecurity
Chinese telecom espionage began with ‘much broader’ aims, officials say
The U.S. has been investigating the Salt Typhoon hackers since late spring and early summer this year, a senior FBI official said.
Cybersecurity
US proposes rule to prevent the sale of financial data to foreign adversaries
Data brokers would have to comply under terms set by the Fair Credit Reporting Act, in an effort that aims to stop exploitation of Americans’ data overseas.
Cybersecurity
Chinese hackers used a ‘range of sophisticated methods’ to breach US telecom providers, insider says
Salt Typhoon deployed various methods to break into telecommunications firms that went far beyond a singular run-of-the-mill credential-stealing attempt, according to a person familiar.
Cybersecurity
White House convened telecom leaders as details of Chinese espionage hack unfold
Many of the breached systems were not properly equipped with tools that recorded network activity, making it harder to quickly trace the origins of the hack, a person familiar said.
Cybersecurity
FCC leaders skirt call for wiretap security reform, hope to ‘go deeper’ on telecom breach briefings
Lawmakers have called on the agency to take up a rulemaking to rethink wiretapping laws amid the hacks that have ensnared several telecom companies, but top FCC officials have not signaled any forthcoming action yet.
Exclusive
Policy
FCC to propose first undersea cable security overhaul since 2001
FCC Chairwoman Jessica Rosenworcel cited rising national security risks in conflict zones as a catalyst for the proposed updates to submarine cable regulations.
Cybersecurity
New TSA cyber rules leave lawmakers, industry hopeful for happy medium regulations
The agency argues its Nov. 8 proposed rulemaking will dually address the transportation industry’s regulation concerns while ensuring they’re suitably protected from hackers. Others want to wait and see.
Cybersecurity
Hackers nabbed emails between congressional staff and Library of Congress
Affected staff were notified Friday afternoon, according to an internal email. Capitol Hill communications with the Congressional Research Service frequently involve confidential legislative drafts or policies still in the brainstorming stage.
Cybersecurity
FCC to soon announce lead administrator for cyber assurance program
More information will also be unveiled during the 2025 CES, Deputy National Security Advisor Anne Neuberger said.
People
CISA Director Jen Easterly to depart on Inauguration Day
Easterly and Deputy Director Nitin Natarajan are set to leave as an administration change casts doubt on the agency’s future.
Cybersecurity