Showing posts with label Department of Homeland Security. Show all posts
Showing posts with label Department of Homeland Security. Show all posts

Tuesday, December 15, 2020

Hackers breach US agencies, Homeland Security a reported target

NEW YORK - The US Department of Homeland Security was the third federal department to be targeted in a major cyberattack, US media reported Monday, a day after Washington revealed the hack which may have been coordinated by a foreign government.

The Washington Post cited unnamed officials who said that the DHS -- which is in charge of protecting the country from attacks both online and off -- had been added to a growing list of targets in the attack, including the Treasury and Commerce departments.

A statement from DHS Monday did not confirm the report, saying only that it was "aware of cyber breaches across the federal government and working closely with our partners in the public and private sector on the federal response."

The Cybersecurity and Infrastructure Security Agency (CISA), which is attached to the DHS, on Sunday said it had ordered federal agencies to immediately stop using SolarWinds Orion IT products following reports that hackers had used a recent update to gain access to internal communications. 

"We urge all our partners -- in the public and private sectors -- to assess their exposure to this compromise and to secure their networks," said CISA Acting Director Brandon Wales.

SolarWinds over the weekend admitted that hackers had exploited a backdoor in an update of some of its software released between March and June.

The hacks are part of a wider campaign that also hit major cybersecurity firm FireEye, which said its own defenses had been breached by sophisticated attackers who stole tools used to test customers' computer systems.

FireEye said it suspected the attack was state-sponsored, and warned it could have affected numerous high profile targets across the globe.

"This campaign may have begun as early as Spring 2020 and is currently ongoing," FireEye said in a blog post.

RUSSIA INVOLVED?

The content the hackers have sought to steal -- and how successful they have been -- is not known at this time. 

"We believe this is nation-state activity at significant scale, aimed at both the government and private sector," said IT giant Microsoft, which is also investigating, in a blog post. 

While Microsoft refrained from naming a country, several US media pointed the finger at the Russian group "APT29", also known as "Cozy Bear." 

According to the Washington Post, the group is part of Moscow's intelligence services, and hacked servers at the State Department and the White House during the Obama administration.

The Russian Embassy in the United States categorically denied the accusations in a statement on Facebook.

Both the public and private sectors must be increasingly on guard against such hacks, warned Hank Schless, senior manager at Lookout, a California-based mobile security company. 

"Adversarial nation-states have recognized the value in targeting both sectors, which means neither is safe from the types of attacks that have government resources behind them," he said.

Matt Walmsley of Vectra, which provides cyberattack detection services from its base in California, agreed.

"Security teams need to drastically reduce the overall risk of a breach by gaining instant visibility and understanding of who and what is accessing data or changing configurations, regardless of how they are doing it, and from where," he said.

Agence France-Presse

Friday, January 4, 2019

U.S. House passes bills that would end gov't shutdown, without wall funds


WASHINGTON - The U.S. House of Representatives, where Democrats now hold a majority, approved legislation on Thursday to end a partial government shutdown that began nearly two weeks ago at several federal agencies and fund the Department of Homeland Security through Feb. 8.

Under the bills, the departments of State, Commerce, Agriculture, Labor, Treasury and other agencies would be funded through Sept. 30, the end of the current fiscal year.

Hours before the vote, the White House said advisers to President Donald Trump would recommend that he veto the measure if Congress passed it without any additional money for Trump's proposed wall along the U.S.-Mexico border. 

The 2019-2020 Congress convened with roughly a quarter of the federal government closed, affecting 800,000 employees, in a shutdown triggered by Trump's demand last month for the money for a U.S.-Mexican border wall - opposed by Democrats - as part of any legislation funding government agencies.

The House earlier on Thursday had formally picked Nancy Pelosi, a veteran Democratic lawmaker and liberal from San Francisco, as its speaker, beginning her second stint in one of Washington's most powerful jobs. She is the only woman ever to serve as speaker and will preside over the most diverse U.S. House in history, including a record number of women and Latinos.

The two-part Democratic package includes a bill to fund the Department of Homeland Security at current levels through Feb. 8, providing $1.3 billion for border fencing and $300 million for other border security items including technology and cameras.

The second part would fund the other federal agencies that are now unfunded including the Departments of Agriculture, Interior, Transportation, Commerce and Justice, through Sept. 30, the end of the current fiscal year.

"We're not doing a wall. It has nothing to do with politics. It has to do with a wall is an immorality between countries. It's an old way of thinking. It isn't cost effective," Pelosi told reporters late on Thursday.

As speaker, Pelosi now is situated to lead Democratic opposition to Trump's agenda and carry out investigations of his administration following two years during which congressional Republicans largely acquiesced to the president.

Trump on Thursday made an unannounced appearance in the White House briefing room to make the case for the border wall, accompanied by members of a union that represents border patrol agents that endorsed him for president in 2016. He congratulated Pelosi on her selection as speaker and said: "Hopefully we're going to work together."

"The wall - you can call it a barrier, you can call it whatever you want - but essentially we need protection in our country," Trump told reporters, without taking questions.

Republican Senate Majority Leader Mitch McConnell signaled that the Democratic legislation had no future in the Senate, calling it "political theater, not productive lawmaking."

"Let's not waste the time," he said on the Senate floor. "Let's not get off on the wrong foot with House Democrats using their platform to produce political statements rather than serious solutions."

McConnell said the Senate would not take up any proposal that did not have a real chance of getting Trump's signature.

source: news.abs-cbn.com

Monday, February 6, 2017

Apple, Google to urge Trump to alter travel order: sources


Several technology companies plan to send a letter to US President Donald Trump on Monday urging his administration to follow through on proposed changes to a travel ban on seven mainly Muslim nations, sources familiar with the letter said Sunday.

"We welcome the changes your administration has made in recent days in how the Department of Homeland Security will implement the Executive Order," according to a draft of the letter.

The technology companies expected to sign the letter include Apple Inc., Facebook Inc., Alphabet Inc.'s Google, Twitter Inc., Microsoft Corp. and Yahoo Inc.

The sources did not want to be identified because discussions regarding the letter were ongoing.

On Jan. 27, Trump issued an executive order imposing a 90-day ban affecting citizens from Iran, Iraq, Libya, Somalia, Sudan, Syria and Yemen and a 120-day bar on all refugees. Those travel bans caused chaos by trapping some travelers at airports and stranding others overseas.

A federal judge on Friday put a temporary nationwide block on that week-old executive order, leading the Republican president to criticize the judge and the court system.

"We stand ready to help your administration identify other opportunities to ensure that our employees can travel with predictability and without undue delay," the technology companies, some of which have had a frosty relationship with Trump since the campaign, said in the letter.

"We are concerned ... that your recent Executive Order will affect many visa holders who work hard here in the United States and contribute to our country's success ... our ability to grow our companies and create jobs depends on the contributions of immigrants from all backgrounds."

Technology companies Amazon.com Inc. and Expedia In., both of which are based in Washington, filed a brief in support of the Washington judge's temporary stay.

source: news.abs-cbn.com

Sunday, January 29, 2017

U.S. states discussing lawsuit over Trump immigration order


A group of state attorneys general are discussing whether to file their own court challenge against President Donald Trump's order to restrict people from seven Muslim-majority countries entering the United States, officials in three states told Reuters.

Democrat attorneys general are expected to be a source of fierce resistance to Trump, much as Republican AGs opposed former President Barack Obama. A lawsuit brought by states would heighten the legal stakes surrounding the president's executive order, signed late on Friday, as courtroom challenges to the ban have so far mostly been filed by individuals.

Officials in the offices of attorneys general in Pennsylvania, Washington and Hawaii said on Saturday they were evaluating what specific claims could be filed, and in which court.

"We do believe the executive order is unconstitutional," Hawaii attorney general Douglas Chin told Reuters on Saturday. He declined to give further detail.

The states could decide not to file, and it is unclear how many states would ultimately sign on for such an effort.

"There certainly are conversations underway," said Joe Grace, a spokesman for Pennsylvania attorney general Josh Shapiro.

A Trump representative could not be reached immediately for comment.

Trump, a businessman who successfully tapped into American fears about terror attacks during his campaign, had promised what he called "extreme vetting" of immigrants and refugees from areas the White House said the U.S. Congress deemed to be high risk. He told reporters in the Oval Office on Saturday that his order was "not a Muslim ban" and said the measures were long overdue.

However, his order hit a roadblock late on Saturday when a federal judge in New York said stranded travelers could stay in the country. The American Civil Liberties Union, which sought the emergency court order, said it would help 100 to 200 people with valid visas or refugee status who found themselves detained in transit or at U.S. airports after Trump signed the order.

The Department of Homeland Security said in a statement it would comply with judicial orders but that Trump's immigration restrictions remained in effect.

source: news.abs-cbn.com

Saturday, July 4, 2015

US on alert for terror threat on July 4 holiday


NEW YORK, United States - The United States is ramping up security across the country and urging people to stay alert over the Independence Day holiday weekend over fears of a terrorist threat.

The Federal Bureau of Investigation, Department of Homeland Security and National Counterterrorism Center have all warned of an increased risk of attacks during the long Fourth of July weekend.

New York State is ratcheting up its monitoring of celebrations and events on Saturday, expected to draw large crowds to America's biggest city.

"We are keenly aware that New York State remains a top target for terrorists," Governor Andrew Cuomo said.

"As we celebrate with family and friends this Independence Day, I urge all New Yorkers to not only remember the freedoms that we hold dear, but also remain cautious of their surroundings and learn to recognize and report suspicious activity."

Other major cities, including the capital Washington, were also on heightened guard, although there were not thought to be any specific threats.

"Our nation is under threat, our law enforcement, our military are under threat, so we take the threat seriously," ABC News quoted US Park Police Chief Robert MacLean as saying.

In Boston, scene of an attack on the city's marathon in 2013 that killed three and left scores wounded, police said security would be high.

"We're just stepping it up to make sure it can be as safe as possible," Boston Police Commissioner William Evans told The Boston Globe.

A lone-wolf attack would be the "worst nightmare," he said, adding police were not aware of any specific threats.

US authorities will also be on their guard abroad.

The State Department had "reminded our posts to review their security posture and procedures," spokesman John Kirby said in a statement.

"The reminder issued by the State Department is routine, done before all major holidays, and is not indicative of any specific security threat," he added.

source: www.abs-cbnnews.com

Thursday, February 26, 2015

Lenovo website hacked; Lizard Squad claims responsibility


China's Lenovo Group Ltd website was hacked, the company said on Wednesday, days after the U.S. government advised Lenovo customers to remove a pre-installed virus-like software, "Superfish", on laptops that makes the devices more vulnerable to attacks.

Hacking group Lizard Squad claimed to be behind the attacks, according to its Twitter page.

Lizard Squad has taken credit for several high-profile outages, including attacks that took down Sony Corp's PlayStation Network and Microsoft Corp's Xbox Live network last month. Members of the group have not been identified.

"The domain name service server hosting Lenovo's website was hacked. We do not have any further information at this time to share. We'll update as soon as possible," Lenovo said in a statement to Reuters.

San Francisco-based security firm CloudFlare said hackers transferred the domain to CloudFlare in order to point it to a defacement site.

"As soon as we at CloudFlare noticed, we seized the account and worked with Lenovo to restore service while they worked to recover their domain," Marc Rogers, Principal Security Researcher at CloudFlare, said in an email to Reuters.

Starting 4 p.m. ET (2100 GMT) on Wednesday, visitors to the Lenovo website saw a slideshow of young people looking into webcams and the song "Breaking Free" playing in the background, according to The Verge, which first reported the breach.

"We're breaking free! Soarin', flyin', there's not a star in heaven that we can't reach!," Lizard Squad posted on its Twitter page, quoting the song from the movie "High School Musical".





The hackers also posted a couple of screenshots of an email between Lenovo employees regarding the "Superfish" software.



The Department of Homeland Security said in an alert on Friday that the "Superfish" program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

Rogers also said CloudFlare was able to restore service before Lenovo recovered the domain, suggesting that the outage was probably "quite small".

However, Lenovo's website was inaccessible at 7:54 p.m. ET (0054 GMT). A message said the site was unavailable due to system maintenance.

source: www.abs-cbnnews.com

Friday, February 20, 2015

Lenovo laptop users urged to remove Superfish program


BOSTON - The U.S. government on Friday advised Lenovo Group Ltd customers to remove a "Superfish," a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyberattacks.

The Department of Homeland Security said in an alert that the program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

"Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the agency said.

Adi Pinhas, chief executive of Palo Alto, California-based Superfish, said in a statement that his company's software helps users achieve more relevant search results based on images of products viewed. He said the vulnerability was "inadvertently" introduced by Israel-based Komodia, which built the application described in the government notice.

Komodia CEO arak Weichselbaum declined comment on the vulnerability.

Komodia's website says it produces a "hijacker" that allows users to view data encrypted with SSL technology.

"The hijacker uses Komodia's redirector platform to allow you easy access to the data and the ability to modify, redirect, block, and record the data without triggering the target browser's certification warning," according to the site.

Marc Rogers, a researcher with CloudFlare, said that means companies which deploy Komodia technology can snoop on web traffic.

"These guys can do everything from just collect a little bit of marketing information, all the way to building a profile on you and spying on your banking connections," he said. "It's a very dangerous slope."

Rogers said that use of Komodia's technology in other products makes them vulnerable to the same types of attacks as Lenovo's Superfish.

He said other vulnerable products include two parental filters: One from Komodia known as KeepMyFamilySecure and another from Qustodio.

Komodia's Weichselbaum said his company was investigating reports of vulnerabilities in KeepMyFamilySecure.

Qustodio CEO Eduardo Cruz Chief Executive said his company's Windows parental filter was vulnerable and he hoped to push out a fix within a few days.

Lenovo did not disclose how many machines were affected, but said that only machines shipped from September to December of last year had been pre-loaded with the vulnerable software.

Affected Lenovo products include laptops in its Yoga, Flex and MiiX lines as well as its E, G, U, Y and Z series, according to the company's support website.

source: www.abs-cbnnews.com

Friday, November 21, 2014

Details of Obama's immigration plan


WASHINGTON - President Barack Obama takes executive action Thursday to left the threat of deportation for some five million people, 44 percent of the estimated 11.3 million immigrants living illegally in the United States.

The nation's undocumented people hail mostly from Mexico and Central America, and 60 percent of them live in just six US states: California, Florida, Illinois, New Jersey, New York and Texas.

Half of them have lived in the US for 13 years or more.

Here are details of Obama's sweeping plan.

Authorization for three years

A new deferred action program will shield up to four million undocumented immigrants from deportation, allowing them to apply for three-year work permits.

Those eligible must have been in the United States for more than five years, and be a parent of a US citizen or of a legal permanent resident born on or before November 20, the date of Obama's order.

Applicants must have a clean criminal record, pass a background check and pay taxes. They will also need to cover a processing fee of $465.

The Department of Homeland Security will begin accepting applications next spring.

Expanded path for young migrants

Obama is broadening the Deferred Action for Childhood Arrivals (DACA) program he created in June 2012 specifically for children, potentially adding 270,000 youths to the 600,000 already legalized by that program.

Children brought to the country before January 1, 2010 are now eligible, compared with DACA's original June 15, 2007 cutoff.

The maximum age of 31 in the original program is removed, with no new age limit imposed.

As before, applicants must have arrived in the US before age 16.

Applicants must be in school or have a high school degree or equivalent, or have been honorably discharged from the military, and have a clean criminal record.

Work authorization is expanded to three years instead of two.

Deportations
Federal authorities will shift deportation efforts from a broad dragnet to "much more sharply defined" priorities, a senior administration official said.

Those deportation targets include undocumented immigrants convicted of serious crimes, and people who recently crossed the border illegally.

Additional resources will help officials reinforce border security, speed deportation of border crossers, and streamline the immigration court process to help clear a backlog of pending cases.

Legal immigration

The administration is poised to facilitate visas for highly-skilled workers and science and technology students, a move that could impact approximately 500,000 people.

Foreign graduates of US universities in STEM fields -- science, technology, engineering and mathematics -- will be allowed to work longer in country after earning degrees, without needing a new visa, through the "Optional Practical Training" extension program.

source: www.abs-cbnnews.com