-
WikiLeaks's CIA dump a likely Russian move to make Trump’s charges appear credible: Experts
Some Trump supporters have suggested that the hacking of the DNC and of the Clinton campaign was not the work of Russia’s intelligence agencies. Rather, it was a “false flag” operation carried out by the U.S. intelligence community, but which was made to look as if it was carried out by Russian intelligence. They portray Trump as a victim of the “deep state,” or permanent bureaucracy, which is hostile to the president’s agenda. Security experts say that the latest WikiLeaks’s publication of information about CIA hacking and surveillance tools – information likely given to WikiLeaks by Russian intelligence – may well be a Russian effort to make Trump’s fact-free charges, that he was “spied on” by U.S. intelligence, appear more credible.
-
-
RAND study examines 200 real-world “Zero-Day” software vulnerabilities
Zero-day software vulnerabilities – security holes that developers haven’t fixed or aren’t aware of – can lurk undetected for years, leaving software users particularly susceptible to hackers. A new study from the RAND Corporation, based on rare access to a dataset of more than 200 such vulnerabilities, provides insights about what entities should do when they discover them.
-
-
S&T awards nearly $8 million to enhance open-source software static analysis tools
DHS S&T has awarded a $7.86 million contract to Kestrel Technology, LLC of Palo Alto, California to expand the coverage capabilities of static analysis tools used to detect potential vulnerabilities in new software systems and increase developer confidence in those tools. S&T’s Static Tool Analysis Modernization Project (STAMP) addresses the presence of weaknesses in software and deals with the root problem by improving software security before it is released by the developer.
-
-
Once overlooked, uninitialized-use “bugs” may facilitate hacker attacks
Popular with programmers the world over for its stability, flexibility, and security, Linux now appears to be vulnerable to hackers. New research found that uninitialized variables — largely overlooked bugs mostly regarded as insignificant memory errors — are actually a critical attack vector that can be reliably exploited by hackers to launch privilege escalation attacks in the Linux kernel.
-
-
Mathematician explains how to defend against quantum computing attacks
The encryption codes that safeguard internet data today won’t be secure forever. Future quantum computers may have the processing power and algorithms to crack them. A new paper clarifies misunderstandings about the complex field of public key cryptography and provides a common basis of understanding for the technical experts who will eventually be tasked with designing new internet security systems for the quantum computing age.
-
-
Serious security vulnerabilities found in home, business, industrial robots
Researchers have identified numerous vulnerabilities in multiple home, business, and industrial robots available on the market today. The vulnerabilities identified included many graded as high or critical risk, leaving the robots susceptible to cyberattack. Once a vulnerability has been exploited, a hacker could potentially gain control of the robot for cyber espionage, turn a robot into an insider threat, use a robot to expose private information, or cause a robot to perform unwanted actions when interacting with people, business operations, or other robots. In the most extreme cases, robots could be used to cause serious physical damage and harm to people and property.
-
-
Russia's interference in U.S., European elections could be “act of war”: NATO commander
General Sir Adrian Bradshaw, the Deputy Supreme Allied Commander Europe, has said that Russian cyberattacks on NATO member states could be deemed an act of war and trigger the principle of the military alliance’s collective defense. Bradshaw said reports of Russian interference in American and European elections and Russian international disinformation campaign could lead alliance leaders to broaden the definition of an “attack.” European intelligence agencies have said that Russia’s successful interference in the U.S. 2016 presidential election has emboldened Moscow to replicated in Europe the methods it used in the U.S. There is already evidence that Russia has launched a hacking and disinformation campaign aiming to help far-right, ethno-nationalist, and populist politicians win the coming elections in France, the Netherlands, and Germany.
-
-
Game theory insights could improve cyberwarfare strategy
Whether a nation should retaliate against a cyberattack is a complicated decision, and a new framework guided by game theory could help policymakers determine the best strategy. A new study examines when a victim should tolerate a cyberattack, when a victim should respond — and how. The researchers use historical examples to illustrate how the Blame Game applies to cases of cyber or traditional conflict involving the United States, Russia, China, Japan, North Korea, Estonia, Israel, Iran, and Syria.
-
-
Building privacy right into software code
It is the programmer’s job to enforce these privacy restrictions. Because privacy-related code is scattered throughout all the programs Facebook uses to run its systems, the programmer must be vigilant everywhere. To make sure nobody finds out where I am unless I want them to, the programmer must tell the system to check my privacy settings everywhere it uses my location value, directly or indirectly. The best way to avoid these problems is to take the task of privacy protection away from humans and entrust it to the computers themselves. We can – and should – develop programming models that allow us to more easily incorporate security and privacy into software. Prior research in what is called “language-based information flow” looks at how to automatically check programs to ensure that sloppy programming is not inadvertently violating privacy or other data-protection rules.
-
-
Simulated ransomware attack highlights vulnerability of industrial controls
Ransomware generated an estimated $200 million for attackers during the first quarter of 2016, and the researchers believe it’s only a matter of time before critical industrial systems are compromised and held for ransom. Cybersecurity have developed a new form of ransomware that was able to take over control of a simulated water treatment plant. After gaining access, the researchers were able to command programmable logic controllers (PLCs) to shut valves, increase the amount of chlorine added to water, and display false readings. The simulated attack was designed to highlight vulnerabilities in the control systems used to operate industrial facilities such as manufacturing plants, water and wastewater treatment facilities, and more.
-
-
Tech coalition fights DHS proposal to collect social media passwords
Earlier this week, the Center for Democracy & Technology announced the creation of a coalition of tech companies, NGOs, and privacy advocates to oppose efforts by DHS to collect social media passwords from individuals entering the United States. The coalition focuses on visa applicants who might be compelled to share their passwords under new DHS policies.
-
-
Cybersecurity of the power grid: A growing challenge
Called the “largest interconnected machine,” the U.S. electricity grid is a complex digital and physical system crucial to life and commerce in this country. Today, it is made up of more than 7,000 power plants, 55,000 substations, 160,000 miles of high-voltage transmission lines, and millions of miles of low-voltage distribution lines. This web of generators, substations, and power lines is organized into three major interconnections, operated by 66 balancing authorities and 3,000 different utilities. That’s a lot of power, and many possible vulnerabilities. The grid has been vulnerable physically for decades. Today, we are just beginning to understand the seriousness of an emerging threat to the grid’s cybersecurity.
-
-
A computer’s blinking light could transmit data
A desktop computer’s tiny blinking LED light would hardly arouse the suspicions of anyone working in an office after hours. However, that LED could be silently winking out an optical stream of the computer’s secrets to a data-stealing drone.
-
-
Cybersecurity degree approved for Kennesaw State
The cybersecurity field in the U.S. will need an additional 1.5 million workers by the year 2020. The Board of Regents of the University System of Georgia on Tuesday approved an online Bachelor of Science in Cybersecurity at Kennesaw State University. The cybersecurity major includes elements of information technology, information security and assurance, and criminal justice, giving students a combination of technical knowledge and information security management skills.
-
-
Russia, Trump and the 2016 election: What’s the best way for Congress to investigate?
Exactly how will the U.S. conduct a fair and accurate investigation into Russian meddling in the 2016 election and links with President Donald Trump’s campaign? U.S. congressional leaders are discussing options. At a time when Congress is sharply polarized along partisan lines, congressional investigations tend to become microcosms of that polarization. This is all the more true when an investigation involves an issue about which the president is vulnerable to political embarrassment or attack. If the intelligence committee proves unable to conduct a thorough and bipartisan investigation of Russian meddling and Trump’s campaign, pressure will build on America’s leaders to establish a more independent probe. Hanging in the balance could be whether the United States can forge consensus about what happened and how to prevent it from happening again.
-
More headlines
The long view
Encryption Breakthrough Lays Groundwork for Privacy-Preserving AI Models
In an era where data privacy concerns loom large, a new approach in artificial intelligence (AI) could reshape how sensitive information is processed. New AI framework enables secure neural network computation without sacrificing accuracy.
Need for National Information Clearinghouse for Cybercrime Data, Categorization of Cybercrimes: Report
There is an acute need for the U.S. to address its lack of overall governance and coordination of cybercrime statistics. A new report recommends that relevant federal agencies create or designate a national information clearinghouse to draw information from multiple sources of cybercrime data and establish connections to assist in criminal investigations.