Normal view
-
DataBreaches.Net
- Stevens Point servers go offline, city officials not sure if caused by a cyberattack
Wyoming courts investigate extent of personal data exposed in cybersecurity breach
-
DataBreaches.Net
- Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more
Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more
FBI Hack Exposed FBI’s Own Hacking Unit
Canva hacked via vendor’s Salesforce instance; Other customers affected as well
Latvia arrests suspected hacker for electronics repair company breach
-
DataBreaches.Net
- ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)
ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)
-
DataBreaches.Net
- Spokane Public Schools takes some systems offline after ‘network security incident’
Spokane Public Schools takes some systems offline after ‘network security incident’
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical infrastructure operators free access to frontier AI models to protect their systems.
Rep. Josh Gottheimer, D-N.J., introduced the AI Cyber Defense Act Monday, inspired by the series of cyberattacks on water facilities in recent months. “If we don’t get ahead of it, it can mean a disaster for our families,” he said at a news conference when he first announced the measure and others tackling water cybersecurity.
Gottheimer holds a couple of posts relevant to the legislation: He’s one of three co-chairs of the House Democratic Commission on Artificial Intelligence, and the top Democrat on the House Intelligence Committee’s cyber subcommittee. He also has bipartisan support for the bill, with co-sponsors Reps. Don Bacon, R-Neb., Zach Nunn, R-Iowa, Hillary Scholten, D-Mich., and Greg Landsman, D-Ohio.
The bill directs the Department of Homeland Security, through CISA, to create a program “through which owners and operators of critical infrastructure that participate in the Program are able to securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure.”
AI-tinged, water-focused cybersecurity pilot programs are all the rage lately. The introduction of Gottheimer’s legislation is adjacent to, but different from, a test program that the Office of the National Cyber Director recently announced in Texas.
One criticism of that program is that private sector companies offered their cyber and AI services through it on a purely voluntary basis, with no significant budget to bolster the pilot. Gottheimer’s bill would authorize $100 million for the pilot program from 2027 to 2031 before it ends, although appropriators would have to follow through on providing the actual dollars. The Trump administration has significantly cut CISA funding in its second term.
“Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” Gottheimer said when he introduced the bill. “It’s expensive to bring the AI in to analyze your system and find those vulnerabilities.”
Critical infrastructure owners and operators could apply for the pilot program, which the bill directs to give priority to nonprofit, publicly owned, rural and small-sized organizations.
“The same technology that can help a small town’s IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn’t even discovered yet,” Gottheimer said when he announced the bill. “AI didn’t create this threat, but it’s accelerated it, and our defenses have to keep up.”
The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.
Another worry for water systems: infostealer exposure
Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday.
The study from identity risk firm SpyCloud follows months of reports about a wave of cyberattacks hitting targets in the sector, which U.S. government officials suspect are tied to Iran.
The company built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains and ultimately analyzed 10,000 organizations, finding that 1,787 showed active infostealer exposure.
In one case, a single infected device at a smart meter technology provider that SpyCloud didn’t name contained saved logins linked to roughly 167 different U.S. utility metering tenants — meaning that one exposure opened the door to many more.
That “cascading supply chain exposure” was one of the biggest findings of the report that SpyCloud shared exclusively with CyberScoop, said Jason Lancaster, chief investigations officer at the cyber firm, along with the quantitative approach” to measure exposure overall.
“We talk about it a lot,” Lancaster said of the exponential risk that one exposure can present. “There’s examples here and there, but that was a standout example of, here’s a tangible thing that is an exposure right now.”
Generally, “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry,” Lancaster said. “In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device. That’s enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network.”
Still, the study had limitations. It doesn’t address what apparently led to the cyberattacks that unfolded in Minnesota and elsewhere this summer: internet-exposed programmable logic controllers.
It’s “important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices,” the report said. It did, however, find that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology or remote-access systems.
Some of the report’s conclusions were about the limitations of the data itself.
“Exposure concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented,” SpyCloud said. “That’s a pattern in the data, not a claim that every water system nationwide carries this risk — and it measures identity exposure, not confirmed intrusion.”
It’s the first study of its kind that SpyCloud has done for a specific industry, so the company doesn’t have comparisons to other industries, Lancaster said. SpyCloud has begun a responsible disclosure process for those affected within its report, he said, beginning with a briefing for the Cybersecurity and Infrastructure Security Agency.
“It’s important to remember, infostealer logs aren’t the end of an incident — they are often the beginning,” Lancaster said. “Access brokers sell these logs specifically because ransomware crews and other fraudsters want exactly this kind of entry point. So, the real question isn’t whether the exposure is dangerous. It’s how much time you have before someone weaponizes that stolen data against you.”
The post Another worry for water systems: infostealer exposure appeared first on CyberScoop.
Dems seek top-to-bottom assessment of CISA workforce
A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.
The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.
“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”
Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.
Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.
Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.
Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.
Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.
“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”
National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.
The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.
Ransomware attack on Kansas county will affect some services
-
DataBreaches.Net
- The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?
The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?
Raon data leak: Insider leak of 1,894 cases went undetected for 4 years
-
DataBreaches.Net
- Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?
Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?
-
DataBreaches.Net
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
-
DataBreaches.Net
- Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack