• Utilities increasingly aware of grid vulnerability

    An analysis by the federal government shows that if only nine of the country’s 55,000 electrical substations were shut down due to mechanical failure or malicious attack, the nation would experience coast-to-coast blackout. Another report finds cybersecurity as one of the top five concerns for U.S. electric utilities in 2014. The report also found that 32 percent of the surveyed electric utilities had deployed security systems with the “proper segmentation, monitoring and redundancies” needed for adequate cyber protection.

  • SATCOMS vulnerable to hacking

    Satellite communications systems (SATCOMS) used by soldiers on the front lines, airplanes, and ships are vulnerable to hacking, according to analyst Ruben Santamarta’s presentation at the recent Black Hatcybersecurity conference.While none of the vulnerabilities discovered could directly cause a plane to crash, or override pilot commands, they could delay or intercept communications, exposing security and classified information to bad actors.

  • Training cyber security specialists for U.S. critical cyber infrastructure

    Lawrence Livermore National Laboratory is joining Bechtel BNI and Los Alamos National Laboratory to train a new class of cyber defense professionals to protect the U.S. critical digital infrastructure. The Bechtel-Lawrence Livermore-Los Alamos Cyber Career Development Program is designed to allow the national labs to recruit and rapidly develop cyber security specialists who can guide research at their respective institutions and create solutions that meet the cyber defense needs of private industry. About 80 percent of the nation’s critical digital infrastructure and assets are owned and operated by private industry.

  • Expanding the scope and impact of cybersecurity and privacy research

    As our lives and businesses become ever more intertwined with the Internet and networked technologies, it is crucial to continue to develop and improve cybersecurity measures to keep our data, devices and critical systems safe, secure, private and accessible. The other day, the National Science Foundation’s (NSF) Secure and Trustworthy Cyberspace (SaTC) program announced two new center-scale “Frontier” awards to support large, multi-institution projects that address grand challenges in cybersecurity science and engineering with the potential for broad economic and scientific impact.

  • SWAMP: Improving software assurance activities

    The Software Assurance Market Place, or SWAMP, is an online, open-source, collaborative research environment that allows software developers and researchers to test their software for security weaknesses, improve tools by testing against a wide range of software packages, and interact and exchange best practices to improve software assurance tools and techniques.

  • ISIS’s appeal to Islamist recruits grows as al Qaeda seen as stale, tired, and ineffectual

    Advances by militant groups like the Islamic State of Iraq and Syria (ISIS) in the midst of turmoil in the Arab world, while al-Qaeda’s aging leaders remain relatively silent, have led would-be terrorists and Islamic scholars to question al-Qaeda’s influence on global Jihad and its would-be fighters. Within the social circles of potential militant recruits, al-Qaeda is increasingly seen as stale, tired, and ineffectual.

  • The smart grid offers convenience, but it also makes cyberattacks more likely

    Recent efforts to modernize the electric grid have increased communication between utilities and consumers, enhanced reliability, and created more opportunities for green energy producers; but it has also elevated the risk of cyberattacks. Proposed smart grids rely on technology that has created millions of new access points; and though more access points within the grid allows renewable energy generators to supply utilities, they also present opportunities for hackers to breach the system.

  • Canadian “sha’hid” used by ISIS in Jihadi recruitment video

    The Islamic State in Iraq and Syria’s (ISIS) strategy to use English-speaking Westerns and social media to recruit militants is unprecedented. ISIS has used World Cup hashtags on Twitterand Facebookto spread propaganda and generate death threats. The group’s adoption of new media could be seen as a move better to compete with rival militant groups. One of the more popular YouTube ISI video featuring a Canadian of was killed in an attack on a Syrian military airport.

  • Demand for cyberattack insurance grows, but challenges remain

    The surge in cyberattacks against the private sector and critical infrastructure has led to a growth in demand for cyber insurance; yet most insurers are unable properly to assess their clients’ cyber risk, let alone issue the appropriate pricing for their cyber coverage.Insurers which traditionally handle risks like weather disasters and fires, are now rushing to gain expertise in cyber technology.On average, a $1 million cyber coverage could cost $20,000 to $25,000.

  • Cloud computing poses technical challenges for digital crime-fighters

    The ultimate in distributed computing, cloud computing is revolutionizing how digital data is stored, processed, and transmitted. It enables convenient, on-demand network access to a shared pool of configurable computing resources, including servers, storage, and applications. The characteristics that make this new technology so attractive also create challenges for forensic investigators who must track down evidence in the ever-changing, elastic, on-demand, self-provisioning cloud computing environments.

  • Chinese government hackers collected information on U.S. security clearance applicants

    Chinese government hackers last March broke into the computer networks of the U.S. Office of Personnel Management, the agency which keeps the personal information of all federal employees. The hackers targeted the information of tens of thousands of employees who had applied for top-secret security clearances. Experts note that the hacking of OPM files containing information about federal employees applying for security clearance is especially disturbing since federal employees applying for security clearances enter their most personal information.

  • Pennsylvania cybersecurity group takes down international criminal network

    Over the past month, a coalition of cybersecurity forces in Pittsburgh, Pennsylvania made of regional FBI officers and members of Carnegie Mellon University’s CERT cyberteam, took down the Gameover Zeus cyber theft network, which had employed data ransom and theft schemes. The criminal group was able to snatch funds up to seven figures from owners’ bank accounts.

  • Leaked documents reveal law enforcement hacking methods

    Through the sourcing of a leaked documents cache from the Italian firm Hacking Team, members of the University of Toronto’s Citizen Lab have revealed the methods of law-enforcement hackers. While much of Snowden’s revelations concerned broad international surveillance, documents from Hacking Team reveal more specific methods such as the actual techniques for tapping phones and computers to operate as eavesdropping devices.

  • Syrian Electronic Army’s attack on Reuters makes a mockery of cyber-security (again)

    One big security issue that has arisen lately concerns control of news media. National boundaries have become blurred on the Internet, and the control any nation can have over information dissemination has been eroded — on news Web sites but especially on open platforms such as Twitter and Facebook. One lesson from all the attacks on open platforms is that a focus of any attempted hack will be a spear phishing e-mail. Tricking users into entering their details may be simple, but it can be very serious. For example the Reuters site, which was attacked by the Syrian Electronic Army (SEA), a pro-Assad group of “hacktivists,” integrates more than thirty third-party/advertising network agencies into its content. A breach on any of these could compromise the agency’s whole infrastructure.

  • DHS receives top FISMA score for the second year in a row

    DHS has received the top score in the annual Federal Information Security Management Act (FISMA), making it the only agency to achieve a score of ninety-nine two years in a row. The act, passed in 2002, requires the Office of Management and Budget to report on federal agencies’ implementation of set processes designed to secure federal IT infrastructures.Analysts credit the achievement to DHS’ Office of Inspector General’s (OIG) push for continuous monitoring of IT systems and standards. The OIG uses commercial vulnerability scanning tools and open source management software to form a system that routinely scans the agency’s networks for compliance with FISMA metrics.