The Cybersecurity (CS) Digest is a curated bi-weekly news summary for cybersecurity professionals. It is transmitted in an HTML-formatted email and provides links to articles and news summaries across a spectrum of cybersecurity topics.
CSIAC ANNOUNCEMENTS:
Safeguarding the Nation’s Critical Infrastructure: National Cyber Security Awareness Month – Week 4 - CSIAC
The 15th annual NCSAM is coming to a close, and we hope you'll join in to promote a safer, more secure and more trusted Internet for these last few days of the month. CSIAC will continue to emphasize the importance of securing our critical infrastructure as we transition into November's Critical Infrastructure Security and Resilience Month (CISRM), which is spearheaded by the U.S. Department of Homeland Security.
In Case You Missed It: CSIAC Webinar – Operational Technology Risk Assessment - CSIAC
This webinar describes cyber risk assessment for operational technology. It argues that a risk management approach to cybersecurity includes the integration of key activities: Cyber Workforce Development and training; Public-Private Partnerships; Operational Technology Risk Management Supply Chain cybersecurity; and cyber threats.
FEEDBACK FROM PREVIOUS DIGEST:
Cloud Computing:
Microsoft, Amazon CEOs Vow to Continue Defense Work After Google Bails on JEDI - Defense One
The leaders of two contenders for the Pentagon's massive cloud contract sounded off on Google's decision not to bid.
RECENT HEADLINES:
Critical Infrastructure:
Russia Likely Behind Dangerous Attack on Saudi Energy Plant: FireEye - Reuters
A dangerous computer virus designed to destroy safety systems at industrial plants was likely developed by a Russian government-backed research institute, U.S. cybersecurity firm FireEye said on Tuesday.
Cyberwarfare:
Navy Recognizes Electromagnetic Battlespace - FCW
A new Navy policy recognizes the electromagnetic spectrum as a warfighting domain "on par with sea, land, air, space and cyber."
U.S. Targets Russian Operatives Ahead of Election: NYT - Reuters
The United States has launched a cyber campaign aimed at Russian operatives in an effort to curb misinformation ahead of the Nov. 6 congressional elections, the New York Times reported on Tuesday, in what it said was the first known such operation to protect American elections.
US May Have by Far the World’s Biggest Military Budget But It’s Not Showing in Security - The Register
A "red teamer" cracked into a US Department of Defense system and rebooted it, but nobody noticed: the system suffered unexplained crashes. In another case, testers "caused a pop-up message to appear on users' terminals instructing them to insert two quarters to continue operating."
Data Security:
British Airways: Cyberattack, Data Theft Bigger Than we First Thought - ZDNet
British Airways has revealed that the massive data breach which struck hundreds of thousands of customers is bigger than first believed.
Air Canada Resets 1.7 Million Accounts After App Breach - Naked Security
Air Canada has been forced to issue a password reset for all 1.7 million users of its Android, iOS and BlackBerry mobile app after up to 20,000 accounts were compromised by hackers last week.
Hackers Target Major Airline in Data Breach Affecting Nearly 10M Customers - Digital Trends
Cathay Pacific has revealed details of a massive hack that has seen the personal data of nearly 10 million of its customers stolen.
Apple CEO Backs Privacy Laws, Warns Data Being ‘Weaponized’ - AP News
The head of Apple on Wednesday endorsed tough privacy laws for both Europe and the U.S. and renewed the technology giant's commitment to protecting personal data, which he warned was being "weaponized" against users.
Legislation and Regulation:
US Bans Exports to Chinese DRAM Maker Citing National Security Risk - ZDNet
The Trump administration on Monday announced it was banning US exports to a Chinese semiconductor firm named Fujian Jinhua Integrated Circuit Company, Ltd., citing national security concerns.
Mobile Security:
Meet the Malware Which Turns Your Smartphone Into a Mobile Proxy - ZDNet
Researchers have uncovered an active phishing campaign which targets Android devices in order to turn them into mobile proxies.
Private Sector:
Facebook Gets Fined 500,000 Pounds by U.K. for Cambridge Analytica Ordeal - CyberScoop
Facebook is getting hit with the maximum penalty allowable under United Kingdom law for a scandal in which the social media website failed to keep user data out of the hands of the political research firm Cambridge Analytica.
IBM Buys Red Hat, For The Hybrid Cloud Factor - Forbes
In a deal that not everybody saw coming, IBM used the weekend lull to announce the acquisition of Red Hat for US$190.00 per share in cash, representing a total enterprise value of approximately $34 billion. Red Hat is known for its commercially supported enterprise Linux operating system Red Hat Enterprise Linux (RHEL) and for its wider set of predominantly open source software tools and cloud computing products.
Public Sector:
DOD Extends and Expands Bug Bounty Program - FCW
The Department of Defense and the Digital Defense Services have awarded another set of contracts under their "Hack the Pentagon" bug bounty program to security firms HackerOne, Synack and Bugcrowd.
Software Security:
New Security Flaw Impacts Most Linux and BSD Distros - ZDNet
Linux and BSD variants that employ the popular X.Org Server package --almost all do-- are vulnerable to a new vulnerability disclosed on Thursday.
Windows Defender Becomes First Antivirus to Run Inside a Sandbox - ZDNet
Microsoft announced today that Windows Defender is the first antivirus to gain the ability to run inside a sandbox environment.
CSIAC Supported Communities
CSIAC supports several communities of practice, such as the Cyber Community of Interest (COI) Group and research & development working groups.
Technical Resources, Policy and Guidance
This list of related sites provides additional sources to pursue the topic of Cybersecurity. The sites include Government organizations, including federal agencies, Department of Defense and military service agencies, commercial organizations, and academic institutions.
The CS Digest provides links to third party Websites. The CSIAC is not responsible for the availability of, and content provided on, third party Websites. You should refer to the policies posted by other Websites regarding their privacy and other topics before you use them. The CSIAC is not responsible for third party content accessible through the CSIAC CS Digest, including opinions, advice, statements, advertisements and endorsements, and you bear all risks associated with the use of such content.
Leave a Comment
You must be logged in to post a comment.