Security News

Fed Chair Says Cyberattacks Main Risk to US Economy
2021-04-12 11:35

Federal Reserve chairman Jerome Powell said he was more worried about the risk of a large-scale cyberattack than another financial crisis like that of 2008. The risks of a 2008-like crisis with a need for government bailouts of banks were "Very, very low," the head of the US central bank said during an interview aired Sunday on CBS's "60 minutes."

PYSA Ransomware Pillages Education Sector, Feds Warn
2021-03-16 21:15

The FBI has issued a warning about an uptick in cyberattacks on the education sector that are delivering the PYSA ransomware. In a "Flash" alert to the cybersecurity community issued on Tuesday, the Feds said that PYSA has been seen in attacks on schools in 12 U.S. states and in the United Kingdom in March alone.

Now it is F5’s turn to reveal critical security bugs – and the Feds were quick to sound the alarm on these BIG-IP flaws
2021-03-11 02:03

To kick off, there's CVE-2021-22987, which scores a 9.9 on the ten-point CVSS scale of severity as it "Allows authenticated users with network access to the Configuration utility, through the BIG-IP management port, or self IP addresses, to execute arbitrary system commands, create or delete files, or disable services." Administrators are advised the flaw allows "Complete system compromise and breakout of Appliance mode." Note that this can only be exploited via the control plane, and it does require an attacker to have a valid login - so a rogue insider or someone using stolen credentials, perhaps. At a mere 9.8 rating, CVE-2021-22986 "Allows for unauthenticated attackers with network access to the iControl REST interface, through the BIG-IP management interface and self IP addresses, to execute arbitrary system commands, create or delete files, and disable services." Complete system compromise is again a possible consequence.

Chinese businessman plotted with GE insider to steal transistor secrets, say Feds
2021-03-01 20:06

A Chinese businessman has been accused by the US government of trying to steal silicon secrets from General Electric. The duo planned to use the stolen trade secrets to set up a competitor in China, it's claimed.

Cloud Attacks Are Bypassing MFA, Feds Warn
2021-01-14 16:45

The Feds are warning that cybercriminals are bypassing multi-factor authentication and successfully attacking cloud services at various U.S. organizations. "These types of attacks frequently occurred when victim organizations' employees worked remotely and used a mixture of corporate laptops and personal devices to access their respective cloud services," the alert outlined.

Feds Issue Recommendations for Maritime Cybersecurity
2021-01-06 20:29

The White House has released cybersecurity guidance for securing the Maritime Transportation System, which operates along 25,000 miles of coastal and inland waterways in the United States. The document points out that the MTS encompasses "361 ports, 124 shipyards, more than 3,500 maritime facilities, 20,000 bridges, 50,000 Federal aids to navigation, and 95,000 miles of shoreline that interconnect with critical highways, railways, airports and pipelines." In addition, there are more than 20 Federal government organizations that currently have a role in maritime security of all stripes, ranging from vessel and personnel safety to transportation standards and logistics.

Feds Pinpoint Russia as ‘Likely’ Culprit Behind SolarWinds Attack
2021-01-06 15:05

The U.S. government has identified Russia as the "Likely" culprit behind the widespread SolarWinds cyberattack that has so far affected multiple federal agencies and private-sector companies. Cyberespionage is cited as the motivation behind the attack, which the feds characterized as ongoing.

Feds: K-12 Cyberattacks Dramatically on the Rise
2020-12-11 18:14

Ransomware is not the only problem, though - CISA and the FBI said that trojan malwares, distributed denial-of-service attacks, phishing and credential theft, account hacking, network compromises and more have all been on the rise since the beginning of the school year. "Whether as collateral for ransomware attacks or to sell on the dark web, cyber-actors may seek to exploit the data-rich environment of student information in schools and education technology services," according to the joint advisory [PDF], issued Thursday.

Feds Seize $1B in Bitcoin from Silk Road
2020-11-06 19:55

The feds have seized its largest stash ever of Bitcoin, originating from the notorious Silk Road underground marketplace. In 2014, the FBI auctioned off 30,000 Bitcoins that the government seized in the initial takedown, which were housed in wallet files stored on Silk Road servers.

Feds throw book at eBay execs who deny they had anything to do with cyberstalking of site's critics
2020-11-04 22:47

Two senior eBay executives who have refused to join their colleagues and plead guilty to charges of cyberstalking have been hit with a string of fresh charges. James Baugh, 45, was eBay senior director of safety and security, and David Harville, 48, was its director of global resiliency when they were arrested back in June, along with four other eBay employees accused of stalking and intimidating a married couple who published a newsletter for the ecommerce industry that was critical of eBay.