DHS

Teenage Hackers Must be Stopped: US DHS’s CSRB Report
Richi Jennings | | 2 factor auth, 2-factor authentication, 2fa, 2FA bypass, 2FA Flaws, 2FA phishing, 2FA policies, 2FA/MFA, cellphone fraud, CSRB, Cyber Safety Review Board, Department of Homeland Security, DHS, DUAL FACTOR AUTHENTICATION, factor auth, homeland security, Homeland Security Presidential Directive, homelandsecurity, Lapsus$, Multi-Factor Authentication, Multi-Factor Authentication (MFA), Multifactor Authentication, SB Blogwatch, SIM swap, sim swap fraud, SIM swap scams, SIM swapping, two factor authentication, U.S. Department of Homeland Security, United States Department of Homeland Security, US Homeland Security
2FA SMS FAIL: Lapsus$ social engineers exploited weak two-factor authentication. Something must be done! (Well, this is something.) ...
Security Boulevard

Cybersecurity Awareness Month Champion | See Yourself in Cyber | Contrast Security
Another year has passed, and once again Contrast is proud to be a Champion for Cybersecurity Awareness Month throughout October, to help in promoting global awareness of online safety and privacy. Co-led ...

US Emergency Alert System Has ‘Huge Flaw’ — Broadcasters Must Patch NOW
Richi Jennings | | Anyone for a hack that leads to an end-of-the-world warning that sends the population into a savage, DHS, Digital Alert Systems, Emergency Alert System, fcc, FEMA, IPAWS, Monroe Electronics, murderous frenzy?, SB Blogwatch
The Emergency Alert System run by FEMA and the FCC is vulnerable to hacking. This is NOT a test. All will be revealed next week at DEF CON 30 ...
Security Boulevard
The DHS is inviting hackers to break into its systems, but there are rules of engagement
The United States Department of Homeland Security (DHS) is inviting security researchers to uncover vulnerabilities and hack into its systems, in an attempt to better protect itself from malicious attacks. The DHS ...

Defense Contractors Highly Susceptible to Ransomware
Even as cybercriminals take aim at critical infrastructure, many of the United States’ top 100 federal contractors are inadequately prepared to repel ransomware attacks. These were among the findings of a report ...
Security Boulevard
How Pipeline Owners and Operators Can Fulfill the TSA’s Second Security Directive
Alex Bagwell | | Compliance, Department of Homeland Security, DHS, ICS Security, industrial control systems, operational technology
Back in June, I wrote about the Transportation Security Agency’s (TSA) new security directive concerning pipeline owners and operators. The order mandated those entities to disclose security incidents such as the ransomware ...
On the Importance of Protecting U.S. Pipeline Owners and Operators
Alex Bagwell | | Department of Homeland Security, DHS, ICS Security, Monitoring, operational technology, pipeline
In the beginning of May, a U.S. pipeline company suffered a ransomware attack. The company decided to respond by halting operations while it investigated the incident. This delayed tens of millions of ...
CISA and Desist
C. Warren Axelrod | | Bryan Ware, Christopher Krebs, cisa, CSO/CISO Perspectives, DHS, General, Information Security News, Spotlight
It’s an old joke: “Heads I win, tails you lose,” but it can also play out in reality. How often do cybersecurity professionals end up on the wrong side of that bet? ...

Government Rumor Control, US Hospital Ransomware Threat, Russian Hackers Charged
Tom Eston | | Cybersecurity, DHS, Digital Privacy, election, Episodes, FBI, Hackers, Hospitals, Podcast, Privacy, Ransomware, Russia, US election, Vote, voter, Weekly Edition
In episode 145 for November 2nd 2020: Kevin Johnson joins me to discuss the US government’s attempt to prevent disinformation and rumors about the election, a new ransomware threat targeting US hospitals, ...

Personal and Medical Information of Children and Adults Stolen in DHS Data Breach
Alina Bizga | | Cyber-attack, Data breach, DHS, Digital Privacy, Georgia Department of Human Services, Industry News, private health information, stolen data, stolen personal identifiable information
Cyberattackers have managed to steal personal and medical information of children and adults involved in Child Protective Services (CPS) and DHS Division of Family & Children Services (DFCS) cases, the Georgia Department ...