Showing posts sorted by relevance for query DHS. Sort by date Show all posts
Showing posts sorted by relevance for query DHS. Sort by date Show all posts

The White House Introduced- Electric Sector Cybersecurity Risk Maturity Model



The White House has launched a new initiative designed to help companies in the electric power industry measure the maturity of their security programs against a new maturity model. The program is being run in tandem with the Department of Homeland Security and Department of Energy and is meant to help the utility companies find their weak spots and where they need to improve.
The Electric Sector Cybersecurity Risk Maturity Model Pilot is the first such program launched by the White House, which has been pointing to information security--and specifically the security of systems running utilities and critical infrastructure--as a priority since the beginning of the Obama administration. The administration has developed a number of strategies and policy documents in the last few years, but this is the first foray into the kind of maturity model that typically is seen in private industry.
The White House, DHS and Energy launched the initiative last week with a meeting of government officials and executives from electric companies to discuss the main problems facing the industry when it comes to information security.
In his blog Howard Schmidt, the White House cybersecurity coordinator, said -
"This initiative -- the Electric Sector Cybersecurity Risk Maturity Model Pilot -- is a new White House initiative led by the Department of Energy, in collaboration with the Department of Homeland Security, to develop a model to help us identify how secure the electric grid is from cyber threats and test that model with participating utilities. Gaining knowledge about strengths and remaining gaps across the grid will better inform investment planning and research and development, and enhance our public-private partnership efforts," 

More More Information Click Here


-Source (threatpost)






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Obama Hired a Team to protect Pentagon Networks From Cyberattack

An elite team of computer technicians assembled by the Obama administration to protect Pentagon networks from cyberattack shockingly includes a former Clinton official who “lost” thousands of archived emails under subpoena and who more recently left the Department of Homeland Security under an ethical cloud related to her qualifications, WND has learned.
The administration in May quietly hired Laura Callahan for a sensitive post at the U.S. Cyber Command, a newly created agency set up to harden military networks as part of an effort to prevent a “cyberspace version of Pearl Harbor.”

The move raises doubts about the administration’s vetting process for sensitive security positions. In 2004, Callahan was forced to resign from Homeland Security after a congressional investigation revealed she committed résumé fraud and lied about her computer credentials.
Investigators found that Callahan paid a diploma mill thousands of dollars for her bachelors, masters and doctorate degrees in computer science. She back-dated the degrees, all obtained between 2000 and 2001, to appear as if she earned them in 1993, 1995 and 2000, respectively. She landed the job of deputy DHS chief information officer in 2003.

-News Source (Conservativebyte)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Twitter Hacked, More Than 250,000 User Data Compromised

Twitter Hacked, More Than 250,000 User Data Compromised

The social networking giant and the world famous micro blogging site Twitter again fallen victim of cyber attack. Last year we have seen that the tight security system if twitter have been compromised many times. Yet again in this year the San Francisco based social media giant who have more than 500 million registered users failed to protect them selves from hackers. On last Friday Twitter acknowledged that it had become the latest victim in a number of cyber-attacks against media companies, saying hackers may have gained access to information on 250,000 of its more than 200 million active users. The micro blogging giant said in a blog posting that earlier this week it detected attempts to gain access to its user data. It shut down one attack moments after it was detected. According to reports usernames, email addresses, session tokens and encrypted/salted passwords for 250,000 users might have been accessed in what it described as a “sophisticated attack” 

"This attack was not the work of amateurs, and we do not believe it was an isolated incident,” said Bob Lord, Twitter’s director of information security. “The attackers were extremely sophisticated, and we believe other companies and organisations have also been recently similarly attacked” Bob added. 

Jim Prosser, a Twitter spokesman, would not say how hackers infiltrated Twitter’s systems, but Twitter’s blog post said hackers had broken in through a well-publicized vulnerability in Oracle’s Java software. Last month, after a security researcher exposed a serious vulnerability in the software, though Oracle patched the security hole, but Homeland Security said the fix was not sufficient. The DHS issued a rare alert that warned users to disable Java on their computers. Prosser said Twitter was working with government and federal law enforcement to track down the source of the attacks. For now, he said the company had reset passwords for, and notified, every compromised user. The company encouraged users to practice good password hygiene, which typically means coming up with different passwords for different sites, and using long passwords that cannot be found in the dictionary.
Twitter said it “hashed” passwords — which involves mashing up users’ passwords with a mathematical algorithm — and “salted” those, meaning it appended random digits to the end of each hashed password to make it more difficult, but not impossible, for hackers to crack. Once cracked, passwords can be valuable on auction-like black market sites where a single password can fetch $20.

While talking about Twitter and cyber issues, I would like to remind you that in last year twitter faced several cyber attacks where more than 55,000 twitter account details was leaked, after this issue in the middle of last year the social networking giant faced massive denial of service which interrupted its services. Later a huge number of Twitter users across the globe received  emails warning that their account have been compromised and their passwords had been reset, and it was another security breach which affected twitter. Such big organization are not at all careless about security, so as twitter and it has been proved when they hired renowned white hat hacker Charlie Miller to boost up their security, but after this current massacre, it seems that twitter need to think more and emphasize a lot to make sure that their system is good enough to prevent cyber attacks. For all the hot cyber updates and reviews stay tuned with VOGH.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

#ProjectWhiteFox -Team GhostShell Hacked 1.6 Million Accounts of NASA, ESA, Pentagon & FBI

#ProjectWhiteFox -Team GhostShell Hacked 1.6 Million Accounts of NASA, ESA, Pentagon & FBI

After the devastating "Project Blackstar" now the hacktivist group calling them selves "Team GhostShell" announced another big hack, where the hackers have targeted several big organizations. This round of cyber attack was going under the banner of #ProjectWhiteFox, in which GhostShell has posted log-in details of 1.6 million accounts they claim are taken from a series of attacks on organizations including NASA, FBI, European Space Agency and Pentagon, as well as many companies that partner with these organizations. The Anonymous subsidiary group has posted the details on Pastebin, while describing the aim of the hack; as part of their #ProjectWhiteFox campaign to promote hacktivism and freedom of information on the internet. The hacker group claimed that the leaked information contained log-in names, passwords, email addresses, CV & several other sensitive information. In their release GhostShell said - "For those two factors we have prepared a juicy release of 1.6 million accounts/records from fields such as aerospace, nanotechnology, banking, law, education, government, military, all kinds of wacky companies & corporations working for the department of defense, airlines and more."
GhostShell members also said that they have messaged security bosses about the insecurity a number of organizations they targeted during attacks throughout 2012, describing it as "an early Christmas present." 
In a Pastebin file, GhostShell features a list of 37 organizations and companies, including The European Space Agency, NASA’s Engineers: Center for Advanced Engineering, and a Defense Contractor for the Pentagon. GhostShell sets itself apart from other hacktivist groups by targeting more than just one company or organization, and then releasing the results of its attack all at once. This set of hacks is spread out across 456 links, many of which simply contain raw dump files uploaded to GitHub and mirrored on paste sites Slexy.org and PasteSite.com.
The uploaded files contain what appears to be user data that looks to have been obtained from the servers of the various firms (likely via SQL injection). The entries include IP addresses, names, logins, email addresses, passwords, phone numbers, and even home addresses. Email accounts include the big three (Gmail, Hotmail, and Yahoo), as well as many .gov accounts. There are also various documents and material related to partnerships between companies and government bodies, as well as sensitive information for the aforementioned industries. 
Furthermore, the group says it has sent an email to the ICS-CERT Security Operations Center, Homeland Security Information Network (HSIN), Lessons Learned and Information Sharing (LLIS), the FBI’s Washington Division and Seattle location, Flashpoint Intel Partners, Raytheon, and NASA. In it, they say to have detailed “another 150 vulnerable servers from the Pentagon, NASA, DHS, Federal Reserve, Intelligence firms, L-3 CyberSecurity, JAXA, etc.”





-Source (TNW)






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Leaked FBI Documents is Calling "Anonymous is A National Security Threat"


According to a PDF containing what purports to be a leaked psychological assessment of the leaders of LulzSec and Anonymous by the FBI's Behavioral Science Unit (which also profiles serial killers), Anonymous is not only not a collection of individuals, it's a coherent group that poses a threat to national security.
Neither the FBI nor Dept. of Homeland Security have commented on the "leak," which may be a fake according to the TechHerald, but seems to reflect accurately the thinking behind a series of DHS warning bulletins and crackdowns that have resulted in 75 raids and 16 arrests of Anonymous members just this year.
Anons themselves refer to the group as a rough, almost coincidental collective of individuals that occasionally cooperate on projects to protest specific things. There are approximately eight vortices of special interest within the collective, according to interviews, postings and counter-arguments posted by various Anonymi in response to invective by those it attacked.
Attacks are the work of small groups of interested individuals who, on their own initiative and using public argument as their weapon, gather like-minded Anonymi to protest governmental outrages or attack injustice in whatever form they find it, according to de facto leaders in the non-existent but vocal #OPpublicrelations.
In March, for example, members of Anonymous and 4Chan debated, in the finest traditions of American Democracy and citizen activism, whether to attack and defeat the Internet scourge that is Rebecca Black – the annoying but harmless pop "singer" whose made herself famous with a mom-and-dad-funded music video on YouTube that repeated the same lyrics so often it became apparent those might be the only words she knows.(Other, less world-shaking Anonymous projects resulted in significant attacks against the embattled governments of Egypt and Syria, the exposure of government atrocities in Bolivia, civil protest against censorship on the Bay Area Rapid Transit System, attacks on Visa, Mastercard and Paypal in support of whistleblower site WikiLeaks and a long-simmering, high-profile protest against unrestricted greed, corrosive dishonesty of Wall Street and the and economic destruction from which the rest of the country suffers while financiers continues to prosper.)
The FBI has analyzed various instant messages, forum postings, emails, Twitter posts and other documentation and decided Anonymous behaves more like a coherent organization led by a small number of powerful and focused activists, not a politically involved group of individuals using the Anonymous banner as gathering point.
  • "The Anonymous ‘collective’ has risen from an amorphous group of individuals on the Internet to the current state of a potential threat to national security. Due to the nature of Anonymous, they believe that they are a leaderless collective. However, it has been shown that there is a defined leadership group," the document reads.

  • "A thorough assessment of each UNSUB’s online activities, speech patterns, and general writings was collected by the FBI. Each UNSUB was individually assessed by members of the SBU (sic) and a psychological profile created from these datasets."

  • Most of the members of Anonymous are under 30, but the bulk of its leadership are not teenage hacker/script-kids as many portray themselves, according to the FBI.

  • "It is likely" that Sabu, one of the more vocal spokestrolls for the LulzSec mini-collective of Anonymous, "works in the information security sector and has been doing so since the early days of the internet and hacking activities. His use of net speak is interspersed with proper American English diction and grammar that implies he is an American citizen and has been educated,” the FBI notes said.

BS, quoth the Anon:

"Anonymous is not a group, it does not have leaders, people can do ANYTHING under the flag of their country," according to one member in an email interview with the AP. "Anything can be a threat to National Security, really," the member said in an email interview. "Any hacker group can be."
If the document is real, it ends on a disturbingly dangerous and presumptive conclusion: that attacks and protests by Anonymous will eventually lead to the death of members of Anonymous, law enforcement or the public that will drive many supporters away from Anonymous.
Until then, Anonymous, whether collectively or individually, may be unstoppable in practical terms.

The overall assessment for the movement however is the following:

1. The movement is out of control and there seems to be no real coherent motivation
2. The leaders have begun to hide themselves a bit more due to arrests that have been made
3. Their reliance on technology will eventually be their downfall
4. Their interpersonal relationships are weak points, as such they should be leveraged
5. Their increasing attacks on infrastructure will eventually lead to serious results that could in fact lead to deaths

-News Source (IT World)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Homeland Security Approved Cyber security Bill "PRECISE" (H.R. 3674)

Homeland Security Approved Cyber security Bill "PRECISE" (H.R. 3674)

The House Homeland Security Committee approved H.R. 3674, the Promoting and Enhancing Cybersecurity and Information Sharing Effectiveness Act of 2011 (the PRECISE Act) by voice vote, after a lengthy mark-up session that saw the bill’s scope scaled back. This Cybersecurity bill was approved on April 18 aimed at securing federal information systems and helping private sector critical infrastructure owners/operators, but key committee members complained that its watered-down provisions weren’t adequate. The bill, originally introduced by Rep. Dan Lungren (R-CA) in February had aimed to create a national information sharing organization to oversee the cyber protection of critical infrastructure, but will now only authorize the National Cybersecurity and Communications Integration Center (NCCIC) at the Department of Homeland Security (DHS).
The committee’s ranking member, Rep. Bennie Thompson (D-MS), bitterly objected to the changes, saying they essentially gutted the bill. In a statement following the bill’s mark-up, he said it “bears little resemblance to the measure that the Cybersecurity Subcommittee approved in February.” He said key provisions that promoted information sharing between and among the private sector and government and privacy protections were removed behind closed doors by the committee’s leadership.


-Source (Govt. Security News)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Cyber Atlantic 2011


Cyber security remains a potential risk mitigation event for all individuals, communities, organizations and governments who rely on the Internet.  This global village of users continues to review, re-evaluate and re-position defensive strategies against this cybersecurity risk arena — with the Cyber Atlantic 2011 cyber security exercise being the latest event to take place.
The Cyber Atlantic exercise 2011 is part of the ongoing EU-U.S. partnership to strengthen mutual capabilities for addressing emerging threats to global networks. Through the EU-U.S. Working Group on Cybersecurity – including representatives from DHS’ National Cyber Security Division (NCSD), the Department of Justice, EU member states and the European Commission – stakeholders focus on cyber incident management, enhancing public-private partnerships, and raising awareness about cyber threats, and combating cybercrime. Two hypothetical scenarios were tested in Cyber Atlantic 2011: a cyber-attack which attempted to extract and publish online sensitive information from the EU’s national cyber security agencies, and an attack on supervisory control and data acquisition (SCADA) systems in EU power generation equipment



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security Experts are saying that China at Risk From Cyber Attacks



A report from the U.S. Department of Homeland Security has revealed that software systems used by China to run its weapons, utilities and chemical plants systems suffer from an inherent bug, leaving them vulnerable to hacker's cyber attacks. The report, which was first disclosed to Reuters, saw the department warn China over the vulnerabilities in its software. The software was designed by Beijing-based Sunway Force Control Technology Co. According to the department, hackers could exploit the bug to inflict an attack that could cause lasting damage on critical parts of the country's infrastructure.

Dillon Beresford, a researcher for NSS Labs -- the private security firm that discovered the bugs -- commented to Reuters, "These are vulnerabilities that hackers could leverage to cause destruction".The department's advice comes in the wake of numerous cyber attacks against several big-name companies and government departments and agencies. Sunway's products, widely used in China, are also deployed to a lesser extent in other countries including the United States, DHS's Industrial Control Systems Cyber Emergency Response Team said in its advisory  Since its advice, Sunway has reportedly  developed software patches to plug the security holes. Experts have since revealed that even with these fixes, it will take the software's users weeks, maybe months to install the new security fixes. In this month alone there have been reports of successful attacks on Citibank, The International Monetary Fund, the U.S. Senate and CIA.  The news comes a month after public attention turned to China after the search giant Google reported a hacking attempt on its Gmail email service. China was widely expected of involvement in the attack after Google traced the origin of the hackers to one of the country's provinces. There is as yet no firm date when the security fixes will be fully functional. Sunway's products, while most widely used in China, are also used by certain Western companies.  

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Team Ghost Released Tax Records of Brazilian Govt, Exclusive Documents of #op-SouthAfrica & 10K SQL- Vulnerable Sites


Black Hat Ghost is back again with boom. Previously they exposed the secrete documents of DOD, NATO, NSA, DHS and many more. This time they exposed the entire tax record of Brazilian Govt. Also Team Ghost published a documents containing more  than 10,000 SQL-i vulnerable sites and their details.
Not yet completed Team Ghost was running an operation named #opSouthAfrica and in this operation they have hacked into 50+ high profile websites of South-Africa including Govt. and so on.


According to The Official Press Release:- 

Today I posted 3 Mediafire links
First link containing:
Tax records from www.balbinos.sp.gov.br From 2002-2011. I exposed everything they've purchased
in the last 9 years. ;)

Second link containing:

The whole contents of #opSouthAfrica, which was created by myself and involved hacking over 50 SouthAfrican websites, these were the main sites I targeted, and it shows Usernames, passwords, emails, Postal address's,databases,SQL Dumps and so on.

The third link of Tonights raids:
Contained 10,000+ SQL-i Vulnerable website links. Every one of these links was in-fact vulnerable at some point in time. So if a couple don't work now, then they've patched it.
These are just a taste of what's to come.

First  link:
http://www.mediafire.com/?elm9kvaend2tk8y   <--- Tax records

Second link:
http://www.mediafire.com/?nk69n6c5ufek8yk <--- #opSouthAfrica

Third  link:

http://www.mediafire.com/?ryx7apfx6ohca7b   <--- 10k+ Vulnerable Sites
 

Fore more info Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Pentagon Is Expanding Cyber-Security Program


The Pentagon is exploring whether to expand a pilot program that protects the networks of defense contractors to include other companies, and even those in industries that serve mainly civilians. But some private sector officials are not sure that the Defense Department should lead the effort.
Speaking at a conference in Baltimore this week, Deputy Defense Secretary William J. Lynn III said that the Defense Industrial Base (DIB) Cyber Pilot, which currently involves 20 large defense companies, is already showing signs of success. It relies on classified threat “signatures” or data that can help detect malicious code before it penetrates a network.
The signatures and other data that help detect threats are provided by the National Security Agency, which collects electronic data on foreign adversaries and operates under the auspices of the Pentagon. The signatures are loaded into devices run by the Internet service providers, including AT&T and Verizon, which provide Internet services to the companies.
The voluntary 90-day pilot, which the Pentagon said should be completed by early fall, has already shown that “it stops hundreds of signatures that we wouldn’t previously have seen,” Lynn said. “It appears to be cost-effective.”

The Pentagon has declined to give details to back up Lynn’s assertions. In an email earlier this week, Pentagon spokeswoman April Cunningham said: “We do not yet have enough information regarding the pilot to make any decisions about the success or effectiveness of the pilot.” She added: “We are not yet in a position to discuss specific metrics.”
She declined to say whether the Pentagon tested NSA’s signatures and other data against other models for effectiveness. “It is the long-standing policy of the Department of Defense not to discuss matters of operational security.”
Speaking at a conference run by the Defense Information Systems Agency, Lynn expressed significant concern “that over the past decade we’ve lost terabytes of data to foreign intruders, foreign intelligence services, to attacks on corporate networks of defense companies.” A great deal of it, he said, “concerns our most sensitive systems-- aircraft avionics, surveillance technologies, satellite communication systems, and network security protocols.”
As a result, he said, the Pentagon is considering expanding the pilot to more defense companies, and discussing with other agencies whether to “apply this same concept to other sectors, whether it’s the power sector, nuclear energy, the transportation sector or the financial sector.’’
But some officials in other industries questioned whether the Pentagon is the right leader for the effort. One concern involves privacy. NSA participation — even if tangential-- raises fears that the spy agency may at some point gain access to private citizens’ data. Defense officials have addressed that worry for now by saying that the government will not directly filter the network traffic or receive any of the captured malicious code.
Then there is the issue of who leads the initiative. The Department of Homeland Security, which is involved in the Pentagon’s cyber pilot program, is also working with other critical sectors on cyber security.
A financial services industry official, who was not authorized to speak publicly, said his industry would prefer “one point” of collaboration. That point, he said, likely would be DHS. “Let’s not have 10, 20, 30 different bilateral arrangements with each government agency and each sector,” he said. “That would result in a web of confusion.”
A telecom industry official, who also was not authorized to speak publicly, agreed: “What we would like is one consolidated government effort that we can hitch our wagons to.” 

-News Source (Washington Post)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

NSA (National Security Agency) is Searching For Good Hackers

 
The National Security Agency has a challenge for hackers who think they’re hot stuff: Prove it by working on the “hardest problems on Earth.”
Computer hacker skills are in great demand in the U.S. government to fight the cyberwars that pose a growing national security threat — and they are in short supply.

For that reason an alphabet soup of federal agencies — DOD, DHS, NASA, NSA — are descending on Las Vegas this week for Defcon, an annual hacker convention where the $150 entrance fee is cash only — no registration, no credit cards, no names taken. Attendance is expected to top 10,000.
The NSA is among the keen suitors. The spy agency plays offence and defence in the cyberwars. It conducts electronic eavesdropping on adversaries, and it protects U.S. computer networks that hold super-secret material — a prime target for America’s enemies.

“Today it’s cyberwarriors that we’re looking for, not rocket scientists,” said Richard “Dickie” George, technical director of the NSA’s Information Assurance Directorate, the agency’s cyber-defense side.

“That’s the race that we’re in today. And we need the best and brightest to be ready to take on this cyberwarrior status,” he told Reuters in an interview.
The NSA is hiring about 1,500 people in the fiscal year, which ends Sept. 30, and another 1,500 next year, most of them cybersecurity experts. With a workforce of about 30,000, the Fort Meade-based NSA dwarfs other intelligence agencies, including the CIA.
It also engages in cyber-spying and other offensive operations, something it rarely, if ever, discusses publicly.
But at Defcon, the NSA and other “Feds” will be competing with corporations looking for hacking talent.
The NSA needs cybersecurity experts to harden networks, defend them with updates, do “penetration testing” to find security holes and watch for signs of cyberattacks.
The NSA is expanding its fold of hackers, but George said there is a shortage of those skills. “We are straining to hire the people that we need.”


It might seem to be an odd-couple fit — strait-laced government types with their rules and missions trying to recruit hackers who by definition want to defy authorities.
George said the NSA is an environment where the hacker mind-set fits with “a critical mass of people that are just like them.”
But what about culture rifts?
“When I walk down the hall there are people that I see every day and I never know what color their hair’s going to be,” George said. “And it’s a bonus if they’re wearing shoes. We’ve been in some sense a collection of geeks for a long, long time.”
The agency has long been known for its brilliant, but sometimes eccentric, mathematicians and linguists.
Jeff Moss, a hacker known as Dark Tangent, knows something about bridging the two worlds. He founded Defcon and the companion Black Hat conference for security professionals and is now a member of the Department of Homeland Security’s Advisory Council, which advises the government on cybersecurity.
“They need people with the hacker skill set, hacker mind-set. It’s not like you go to a hacker university and get blessed with a badge that says you’re a hacker. It’s a self-appointed label — you think like one or you don’t,” Moss told Reuters.

-News Source (Washington Post)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

DHS Bulletin: Anonymous & Associated Hacker Groups Deploying New Cyber Attack Tools


Department of Homeland Security (DSH) released a new bulletin A-0011-NCCIC -120020110914  (U//FOUO) saying that Anonymous and Associated hackers groups are developing and deploying new cyber attack tools. The bulletin contains brif of Anon, Their attacks on the Internet, cyber attack tools, exploits (LOIC, #RefRef, Apache Killer, URGE, Anonware) and so on. 

For More information and to download the bulletin Click Here






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...