❌

Reading view

There are new articles available, click to refresh the page.

CISA promotes a fresh way to deter cyberattackers: Lie to them

For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered.

The Wednesday guidance, “Using Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters and penetration testers about how decoys can be a cheap, effective way to disrupt attackers, said Chris Butera, acting executive director of the cybersecurity division.

‘We’ve been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who’s already gained access to networks,” Butera told CyberScoop at Google Cloud’s Cyber Defense Summit 26.

It’s especially complementary for zero-trust (maintaining that no user or device is trustworthy by default) and assume-compromise (assuming that hackers have already gotten into a network) approaches, Butera said.

While the guidance is “really relevant for everyone,” it’s something that can be especially useful in critical infrastructure sectors that don’t have the most personnel or money, he said.

“This could be something to prioritize as a lower cost solution,” Butera said. “You can create your own honey tokens yourself.”

The 22-page guidance includes decoy principles and goals, definitions of the different kinds of decoys and how to use them and scenarios for deployment.

Honeytokens, for instance, are “Data elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity.”

“Cyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” Butera said in a news release. “With this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.” 

The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.

Why federal cyber defense demands an offense-driven mindset

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of federal CISOs to name the three critical weaknesses an adversary could exploit today to compromise their missions, and you’ll likely be met with a mountain of compliance reports.

That disconnect reveals a critical velocity problem in government risk management.      Traditional vulnerability management treats every Common Vulnerabilities and Exposures (CVE) entry and high Common Vulnerability Scoring System (CVSS) score as an equal emergency, regardless of whether it’s actually exploitable. Security teams spend weeks chasing theoretical findings, while adversaries exploit overlooked attack paths in hours. CVSS scores are static abstractions: they cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage.

As AI collapses the window between vulnerability disclosure and exploit execution, CISA’s issuance of BOD 26-04 marks a long-overdue pivot. The directive codifies what frontline defenders already know: agencies cannot win 90-day patch races against adversaries moving at machine speed. Federal cyber defense must shift from reactive spreadsheet patching to real-time prioritization based on exploitability, active threats and mission risk.

Vulnerable does not mean exploitable

During 30 years in IT operations and military cyber environments, I lost count of how many times I had to tell an auditor: “That high-severity CVE is a false positive, the vulnerable module isn’t running, or we’ve mitigated it six different ways.”

That gap between vulnerable and exploitable is where federal security teams lose the clock. Vulnerability scanners produce thousand-page laundry lists. Teams work from the top down, spending finite engineering hours patching high-severity “purples.” They often exhaust their time and budget before reaching the medium- and low-severity findings.

Adversaries do not follow a 90-day patch cycle. Attackers rarely burn a valuable zero-day exploit when a misconfiguration, weak trust relationship or stolen credential provides a direct path to their objective. As my colleague Todd Beebe from Freeport LNG has noted, “Credentials are the everyday zero-day.” Attackers don’t hack in when they can simply log in.

Defenders spend months building fortresses around static “crown jewel” systems while adversaries maneuver around those controls by chaining low-severity weaknesses with compromised identities. CVEs are only part of the story: misconfigurations and the tactics, techniques and procedures that live between CVEs matter just as much. We’ve validated thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE, and the only way to understand those paths is through offense-driven defense. Closing a vulnerability ticket on schedule doesn’t mean you have stopped an attacker. Untested assumptions are what get organizations in the news.

The cyber version of the McNamara Fallacy

Federal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

I learned this lesson firsthand while leading IT and cybersecurity operations for a specialized defense unit. Our team was compliant. We checked every DISA STIG box, passed every audit and maintained immaculate documentation. Then a red team assessed our environment. Across people, process and technology, our organization performed well, but the assessment still found things a threat actor could immediately take advantage of.

When I asked whether they could return in three months to verify our fixes, they laughed. “No way,” they said. “You don’t have the budget, and we don’t have the resources.”

That experience fundamentally shifted my mindset: it is much easier to be compliant than secure.

Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

Proving defenses work in real time

Across modern framework developments, from NIST SP 800-53 Rev. 5 and NIST CSF 2.0 to federal zero trust mandates, FedRAMP, and Continuous Threat Exposure Management (CTEM), the market is shifting from static attestation toward validation and verification:

  • Compliance asks if a control is present and documented.
  • Validation asks if that control stops realistic attacker behavior now.
  • Verification asks if remediation eliminated the attack path in production.

To outpace adversaries, agencies must augment human expertise with autonomous penetration testing capabilities. We know this works in high-assurance public-sector environments. Under the NSA’s Continuous Autonomous Penetration Testing (CAPT) program, autonomous testing has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations.

More importantly, the program accelerated remediation, saving more than 340,000 labor hours and enabling lean security teams to verify and close 71% of critical findings within 30 days. That is the difference between an annual-audit mindset and real-time operational defense.

Three action steps for federal leaders

Federal leaders should take three steps to operate at the speed of the threat:

  1.   Define risk through exploitability and impact. Risk is the product of likelihood and impact. But legacy vulnerability management accepts theoretical guessing of likelihood and fails to account for the consequences of the exploitation. Remediation should prioritize validated attack paths posing immediate mission risk.
  1. Move to continuous verification. In the military, we said, “Trust but verify.” In modern cyber defense, it is simply “verify.” Agencies must safely and continuously test controls, architectures, and identity permissions in production from multiple perspectives, including outside-in, assumed-breach, identity-based, and cloud-native.
  2. Verify the fix, not the activity. A ticket should not close merely because someone deployed a patch or changed a configuration. It should close only after a targeted retest confirms the exploitable attack path is gone.

As Corey Brunkow, Horizon3’s Director of Federal Operations, puts it: “Compliance is the baseline, not the finish line. In the new era of AI-enabled attacks, government and supply chain partners cannot afford to mistake a documented security control for an effective one.” The only way to know whether defenses can withstand an adversary is to send an attacker at them. Federal leaders must turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does.

Learn how Horizon3 can help organizations move from point-in-time compliance to continuous, autonomous penetration testing.

The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday.

The gang is relying on access brokers,compensating them anywhere from $100 to $1 million, with higher prices going to those who work exclusively with Medusa. However, most of the brokers work simultaneously for “multiple variants at the same time,” the advisory from the Cybersecurity and Infrastructure Security Agency, FBI and Health and Human Services Department states in one of the updated portions of the advisory.

Tuesday’s update advisory expands upon aMarch 2025 advisory, drawing on ongoing FBI investigations.nIt includes information on the kinds of software vulnerabilities Medusa has exploited, such as Fortra GoAnywhere and BeyondTrust flaws.

“Medusa actors operate opportunistically by targeting victims with unpatched software rather than focusing on specific organizations or sectors; however, the Healthcare and Public Health (HPH) Sector has been a frequent victim of Medusa operations,” according to the advisory. “Medusa actors leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure.’

“However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching,” the advisory continues.

The approach appears to be netting gains: From March 2025 to April of this year, the victim tally in the advisory jumped from more than 300 to more than 500. The group was first identified in 2021.

“Medusa actors often use legitimate tools and living off the land techniques to evade detection. They may also leverage remote monitoring and management software and remote access services, including Remote Desktop Protocol, for lateral movement,” as updated sections of the advisory detail. “Once inside a network, they use common utilities and tools to support credential access, data exfiltration, and ransomware deployment.”

Earlier this year, Microsoft detailed how a group it dubbed Storm-1175 was making use of Medusa ransomware in speedy operations. Symantec and Carbon Black also detailed earlier this year how North Korean hackers were leaning on Medusa to target the health care sector.

The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

What’s Trust Among Friends: Secure Connections & Man-in-the-Middle Attacks

Logan Lembke // Living in the information age is great, isn’t it? With just a visit to the internet you can learn what happened in London on September 2nd, 1666, […]

The post What’s Trust Among Friends: Secure Connections & Man-in-the-Middle Attacks appeared first on Black Hills Information Security, Inc..

❌