Security News

DOD expands bug disclosure program to all publicly accessible systems
2021-05-04 20:20

US Department of Defense officials today announced that the department's Vulnerability Disclosure Program has been expanded to include all publicly accessible DOD websites and applications. DOD's VDP is led by the Department of Defense Cyber Crime Center, and it allows security researchers to search for and report any vulnerabilities affecting public-facing DOD information systems.

US DoD Launches Vuln Disclosure Program for Contractor Networks
2021-04-06 14:23

The United States Department of Defense this week announced the launch of a new vulnerability disclosure program on HackerOne to identify vulnerabilities in Defense Industrial Base contractor networks. Running as a pilot, the Defense Industrial Base Vulnerability Disclosure Program covers participating DoD contractor partner's information systems and web properties, as well as other assets within scope, and is separate from the DoD vulnerability disclosure program that already runs on HackerOne.

U.S. DoD Weapons Programs Lack ‘Key’ Cybersecurity Measures
2021-03-05 20:45

Weapons programs from the U.S. Department of Defense are falling short when it comes to incorporating cybersecurity requirements, according to a new watchdog report. While the DoD has developed a range of policies aimed at hardening the security for its weapon systems, the guidance leaves out a key detail - the contracts for procuring various weapons.

Checkmarx makes its automated AST solution available to all DoD agencies
2020-12-10 00:30

With this, Checkmarx furthers its commitment to supporting the public sector by making its automated application security testing solution available to all DoD agencies in the form of a hardened container, helping them to confidently build and release secure software while meeting the strict security and compliance requirements of the U.S. military. This enables all DoD agencies and developers to easily acquire and integrate the Checkmarx solution into their DevOps environments and automatically insert security into the entire SDLC, while also avoiding lengthy ATO timelines.

DoD, DHS Warn of Attacks Involving SLOTHFULMEDIA Malware
2020-10-05 08:44

The U.S. Department of Defense's Cyber National Mission Force and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency last week published a malware analysis report for what they described as a new malware variant named SLOTHFULMEDIA. SLOTHFULMEDIA is described as a dropper that deploys two files when executed, including a RAT designed to allow hackers to control compromised devices, and a component that removes the dropper once the RAT achieves persistence on the targeted computer. The U.S. government's malware analysis report includes technical details about how the malware works, indicators of compromise and recommendations for securing systems against such threats.

Prevalent offers questionnaires for all levels of the CMMC to C3PAOs and DoD contractors
2020-06-28 23:45

Prevalent announced that it is the first third-party risk management company to offer questionnaires for all five levels of the CMMC to certified third-party audit organizations and Department of Defense contractors. "In today's environment it's more important than ever to ensure that third-party suppliers are compliant with DoD standards. Prevalent prides itself on providing contractors and auditors with questionnaires to support all of the certification levels needed to ensure a secure supply chain."

New version of CloudBees CI solution meets stringent US DoD standards
2020-06-11 00:30

The new release of CloudBees CI is available immediately and enables DoD and civilian agencies of the U.S. federal government, as well as enterprises in private industry, to drive more value through their software delivery pipelines while lowering security risk. Platform One provides platforms that are already accredited and can only use containerized software with an approved CtF. "With the CtF, CloudBees CI can be readily used by DoD agencies, as well as civilian agencies and federal system integrators," said Michael Wright, director, federal sector, at CloudBees.

The DoD Isn't Fixing Its Security Problems
2020-04-17 15:35

In a majority of cases, DoD has not completed the cybersecurity training and awareness tasks it set out to. The report focuses on three ongoing DoD cybersecurity hygiene initiatives.

Budgetary, policy, workforce issues influencing DOD and intelligence community IT priorities
2020-01-15 05:00

Information Technology spending by Department of Defense and Intelligence Community agencies will continue to grow as they work to keep pace with the evolution of both the threat landscape and technology development, according to Deltek. IT solutions such as cloud computing, modern data management, big data, cybersecurity and artificial intelligence are in high demand by intelligence agencies with increasingly complex national security missions.

Hawkeye enters into a Cooperative Research and Development Agreement with the DOD
2019-11-08 01:15

Hawkeye, a next-generation imaging technology company, recently announced that it has entered into a Cooperative Research and Development Agreement (CRADA) with the Department of Defense (DOD)....