The Senate Homeland Security and Governmental Affairs Committee (HSGAC) today approved two bills related to cybersecurity and software – the Industrial Control Systems Cybersecurity Competition Act and the Source Code Harmonization And Reuse in Information Technology (SHARE IT) Act. […]
Chinese state-sponsored hackers are positioning themselves to be able to take down vital U.S. resources at a moment’s notice and the U.S. must be prepared to deal with that threat, top Federal government officials told lawmakers today during a House Select Committee on the Chinese Communist Party (CCP) hearing. […]
A new white paper advocates for improved information sharing among private sector firms, stressing the need for timely, relevant, and detailed threat information to mitigate cyberattacks, aid in system recovery, and enhance the resilience of commercial networks. […]
Sens. Gary Peters, D-Mich., chairman of the Senate Homeland Security and Governmental Affairs Committee, and Mike Braun, R-Ind., introduced bipartisan legislation this week to broaden the scope of the President’s Cup Cybersecurity Competition. […]
Federal agency officials are looking for more collaboration across agencies to combat cybersecurity threats fueled by relentless adversaries who are employing the latest technologies in their attacks. […]
In joint guidance released on Jan. 17, the Cybersecurity and Infrastructure Security Agency (CISA) – alongside the FBI – is warning critical infrastructure and state, local, tribal, and territorial partners of cybersecurity threats posed by Chinese-manufactured unmanned aircraft systems (UAS), more commonly known as drones. […]
The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive today requiring agencies to mitigate “widespread and active exploitation” of vulnerabilities in Ivanti Connect Secure VPN and Policy Secure network access control appliances. […]
The government’s latest Federal Cybersecurity Research and Development (R&D) Strategic Plan is placing human-centered cybersecurity at the forefront of the nation’s cyber research and development activities and investments for the next four years. […]
The Department of Energy’s (DoE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) today announced a $30 million funding opportunity to support the research, development, and demonstration (RD&D) of next generation tools to protect clean energy delivery infrastructure from cyberattacks. […]
Witnesses told members of Congress today that the Department of Homeland Security’s (DHS) Cyber Safety Review Board (CSRB) should be an independent entity with a clear and transparent process for how it selects its board members and the incidents it investigates. […]
By creating the Bureau of Cyberspace and Digital Policy (CDP), the State Department is better positioned to achieve its cyber diplomacy goals, a new report from the Government Accountability Office (GAO) says. […]
The Aspen Institute’s US and Global Cybersecurity Groups released a new report on Tuesday that offers up recommendations on how to safely use AI in cybersecurity and steers organizations toward a “good place” where AI predominantly helps defenders. […]
Federal agencies have improved their cybersecurity information sharing in recent years but barriers remain, according to a recent joint report released by the Office of the Inspector General (OIG) of the Intelligence Community (IC). […]
The Department of Energy’s (DoE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has announced up to $70 million in funding to support research into technologies designed to increase resilience and reduce risks to energy delivery infrastructure from a variety of hazards, including cyber threats. […]
The White House’s former National Cyber Director (NCD) Kemba Walden has been tapped to lead Paladin Capital Group’s new Global Institute, the investment firm announced today. […]
The Defense Department (DoD) on Dec. 26 published its latest proposed overhaul of the agency’s Cybersecurity Maturity Model Certification (CMMC) 2.0 program that would set three levels of cybersecurity compliance for defense industrial base (DIB) contractors, and allow for contractors to perform security self-assessments at some of the lower requirement levels. […]
From implementing the National Cybersecurity Strategy to issuing broad-sweeping software security guidelines, boosting the nation’s cyber posture was top of mind for the Biden administration in 2023. […]
The National Security Agency (NSA) published its 2023 Cybersecurity Year in Review this week to share its recent cybersecurity successes, including the agency’s work to enhance national security through artificial intelligence, strategic competition, and more. […]
The Cybersecurity and Infrastructure Security Agency (CISA) issued a formal request for information (RFI) in the Federal Register today looking for feedback on its secure-by-design software practices. […]
The Department of Defense’s (DoD) Defense Digital Service (DDS) has announced that its Hack the Pentagon program has launched a continuous bug bounty program that will expand to the Chief Digital and Artificial Intelligence Office (CDAO) assets and beyond. […]
The Cybersecurity and Infrastructure Security Agency (CISA) said that it will begin a two-year strategic effort to modernize its approach to enterprise cyber threat information sharing in 2024 “to maximize value to our partners and keep pace with a changing threat environment.” […]
Microsoft announced this week that the company has taken down websites and other online assets used by the Storm-1152 cybercrime group, which the company said is the “number one seller and creator of fraudulent Microsoft accounts.” […]
The Cybersecurity and Infrastructure Security Agency (CISA), as part of its Secure Cloud Business Applications (SCuBA) program, released a series of nine security configuration baselines for Google Workspace today, including applications like Gmail, Google Drive, and Google Meet. […]
The Department of Health and Human Services (HHS) has released a concept paper that outlines the department’s cybersecurity strategy for the healthcare sector, detailing four key actions it will take to advance cyber resiliency in the sector. […]
Gen. Paul Nakasone, who heads both the National Security Agency (NSA) and the U.S. Cyber Command (CYBERCOM), today called for a revamped “CYBERCOM 2.0,” aligning with similar calls from Congress for an independent U.S. Cyber Force. […]
A top White House cybersecurity official said Thursday that the administration’s “U.S. Cyber Trust Mark” program is on track to be released by the end of 2024. […]
The White House is calling on Federal agencies to prioritize creating internet of things (IoT) asset inventories by the end of fiscal year (FY) 2024 as a way to better gauge cybersecurity risks. […]
Twenty of the 23 civilian Chief Financial Officers (CFO) Act of 1990 agencies have failed to meet the White House’s cyber incident logging requirements by an August 2023 deadline, and according to a Dec. 4 watchdog report, 17 of these agencies were found to be at the lowest level of maturity – tier 0 – in that category. […]
The Cybersecurity and Infrastructure Security Agency (CISA) – along with the National Security Agency (NSA), Environmental Protection Agency (EPA), and the Israel National Cyber Directorate (INCD) – have released a new cybersecurity advisory warning of continued Iranian-backed cybersecurity attacks aimed towards American and Israeli water and wastewater systems (WWS). […]
The Federal Cybersecurity Workforce Expansion Act has been reintroduced in the House as part of a bipartisan, bicameral effort to strengthen the nation’s cyber defenses and cybersecurity workforce by creating two new training programs within the Federal government. […]