Security News

US Cyber Command: Patch Windows 'Bad Neighbor' TCP/IP bug now
2020-10-14 10:42

US Cyber Command warns Microsoft customers to immediately patch their systems against the critical and remotely exploitable CVE-2020-16898 vulnerability addressed during this month's Patch Tuesday. "Update your Microsoft software now so your system isn't exploited: CVE-2020-16898 in particular should be patched or mitigated immediately, as vulnerable systems could be compromised remotely," US Cyber Command said in a tweet earlier today,.

US Cyber Command: Foreign APTs Likely to Exploit New Palo Alto Networks Flaw
2020-06-30 10:50

Palo Alto Networks revealed on Monday that it has patched a critical authentication bypass vulnerability in its PAN-OS firewall operating system, and U.S. Cyber Command believes foreign APTs will likely attempt to exploit it soon. "When Security Assertion Markup Language authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled, improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability," Palo Alto Networks explained in an advisory.

Documents Describe US Cyber Command's Campaign to Hack ISIS
2020-01-22 19:18

The U.S. Cyber Command's campaign to hack ISIS and disrupt its media operations faced some challenges, including a lack of data storage, but ultimately proved successful, according to government documents from 2016 that were made public Tuesday. The heavily-redacted documents published by the National Security Archive, a not-for-profit research organization, show that U.S. Cyber Command was not prepared to handle the amount of information it collected when it hacked ISIS. The command, which is part of the U.S. Defense Department and includes units from all military branches, also faced problems with interagency coordination and the lengthy process of vetting ISIS cyber targets.

US Cyber Command warns that the Outlook is not so good - Iranians hitting email flaw
2019-07-03 23:51

Government-backed campaign going after bug that was patched in 2017 An ongoing Iranian government-backed hacking campaign is now trying to exploit a Microsoft Outlook flaw from 2017.…

US Cyber Command Warns of Outlook Vulnerability Exploits
2019-07-03 17:18

Researchers Say Attackers Could Have Ties to Iranian-Backed APT GroupThe U.S. Cyber Command has issued a warning that attackers are attempting to exploit an older vulnerability in Microsoft...

Gen. Nakasone on US CyberCommand
2019-02-22 11:35

Really interesting article by and interview with Paul M. Nakasone (Commander of U.S. Cyber Command, Director of the National Security Agency, and Chief of the Central Security Service) in the...

'Time for US Cyber Command to Take the Gloves Off'
2018-07-13 20:18

In the wake of news that 12 additional Russians have been indicted for conspiring to interfere with the 2016 presidential election, a key question emerges: What will President Trump say when he...

Getting the Bad Guys to Fund US Cyber Command's Growth (InfoRiskToday)
2017-08-29 10:18

The ISMG Security Report leads with views on a novel way to fund the growth of the United States military's Cyber Command by seizing assets such as digital currencies from hackers and other...

US Cyber Command gets unified military command status (Help Net Security)
2017-08-23 19:19

Last week, US President Donald Trump announced that the United States Cyber Command, which is currently a division of the NSA, will be elevated to the status of a Unified Combatant Command focused...

Splitting the NSA and US Cyber Command (Schneier on Security)
2017-08-03 11:29

Rumor is that the Trump administration will separate the NSA and US Cyber Command. I have long thought this was a good idea. Here's a good discussion of what it does and doesn't mean....