NSA Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/nsa/ Breaking news about the market for products, systems and services for the U.S. intelligence community Fri, 22 May 2026 11:56:42 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg NSA Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/nsa/ 32 32 59882712 NSA releases security design considerations for AI-driven automation https://intelligencecommunitynews.com/nsa-releases-security-design-considerations-for-ai-driven-automation/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-security-design-considerations-for-ai-driven-automation Fri, 22 May 2026 11:56:42 +0000 https://intelligencecommunitynews.com/?p=44638 On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context...

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation.”

MCP is an application-level protocol that provides a simple and agreed upon messaging pattern and transport format currently used by many AI-enabled systems for managing interactions between services. The guidance aims to reduce risk while supporting safe innovation in AI-augmented systems.

Real-world adoption of MCP has accelerated. It is increasingly found in AI deployments across products used in business, finance, legal, software development, and other industries, including for sensitive tasks like querying personally identifiable information.

While MCP simplifies the integration of diverse capabilities into powerful agent workflows, the current protocol specification requires careful and cautious implementation for security. Gaps in MCP design, implementation, and operational posture have created significant and evolving security concerns including serialization risks, trust boundaries, and agent misuse, to name a few, according to the CSI.

Although traditional cybersecurity principles such as authentication, authorization, and input validation remain necessary protective measures, agentic AI systems — especially those featuring MCP — introduce novel and systemic risks like dynamic tool invocation, implicit trust relationships, and context sharing. Established cyber defense strategies unfortunately do not adequately address these new risks.
These are not isolated problems that can be patched at the interface or endpoint level. Securing MCP systems requires treating the agentic environment as a continuum. Misaligned assumptions or subtle inconsistencies at any stage can propagate and compound into exploitable conditions.

This report examines these security concerns, outlines gaps that must be addressed before MCP can be used securely and confidently. It offers practical recommendations for organizations adopting MCP in high-stakes or production environments. The guidance is designed to remain relevant as the MCP protocol, implementations, and operations continue to evolve.

Adopters are advised to proceed with caution, drawing on lessons from prior distributed and plugin-based ecosystems while applying heightened scrutiny to MCP’s novel integration and automation patterns. Continued collaborative work among implementers, security researchers, and standards organizations will be essential to establish more robust and trustworthy foundations for AI infrastructure, particularly for national security and other high assurance environments.

Read the full report.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
44638
NSA, partners release agentic AI guidance https://intelligencecommunitynews.com/nsa-partners-release-agentic-ai-guidance/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-partners-release-agentic-ai-guidance Mon, 04 May 2026 11:42:21 +0000 https://intelligencecommunitynews.com/?p=44471 On April 30, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and...

The post NSA, partners release agentic AI guidance appeared first on Intelligence Community News.

]]>
On April 30, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and others to release the Cybersecurity Information Sheet (CSI), “Careful Adoption of Agentic AI Services.”

This report is a comprehensive guide to understanding and mitigating the unique risks associated with the rise of agentic artificial intelligence (AI) within critical infrastructure, including the defense sector. The CSI highlights general security considerations for agentic AI, including the inherited risks of large language models (LLMs), increased attack surfaces, increased complexity, the evolving security landscape as the technology matures, and the need to address AI security as part of established cybersecurity paradigms.

Unlike traditional generative AI, which typically requires human validation, agentic AI systems are designed to operate autonomously, making them a powerful tool. This presents both unprecedented opportunities and significant cybersecurity challenges organizations must address to protect national security and critical infrastructure.

Careful Adoption of Agentic AI Services” outlines risk spaces to consider, including:

•    Privilege Risks: Over-privileged agents can amplify the impact of a single compromise.
•    Design and Configuration Risks: Insecure design and provisioning can introduce vulnerabilities.
•    Behavior Risks: Goal misalignment, specification gaming, deceptive behavior, and emergent capabilities can lead to unexpected or undesirable outcomes.
•    Structural Risks: The interconnected nature of agentic systems increases the attack surface and complexity.
•    Accountability Risks: The opacity of agentic systems makes accountability hard to trace, complicating auditing and compliance.

Securing agentic AI systems requires proactive measures that address risks introduced by autonomy, interconnected components, and evolving capabilities. The report recommends deploying agentic AI incrementally, continuously assessing against evolving threat models, and maintaining strong governance, explicit accountability, rigorous monitoring, and human oversight which are essential for safe and secure operation.

Organizations that use agentic AI services, including those in the defense sector, are encouraged to review this guidance and adopt the outlined cybersecurity mitigations.

Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom National Cyber Security Centre (NCSC-UK).

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post NSA, partners release agentic AI guidance appeared first on Intelligence Community News.

]]>
44471
NSA releases joint guidance on defending against China-nexus covert networks https://intelligencecommunitynews.com/nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks Tue, 28 Apr 2026 11:30:36 +0000 https://intelligencecommunitynews.com/?p=44424 On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s...

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s Australian Cyber Security Centre, and others in releasing the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”

The CSA details how multiple China-nexus threat actors are now using external covert networks to facilitate malicious cyber activity strategically, at scale. These dynamic covert networks include botnets that leverage many compromised devices to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. These botnets frequently include compromised small office/home office network infrastructure (routers, firewalls, network attached storage, etc.) and internet of things devices (web cameras, video recorders, smart devices, etc.).

While many new covert infrastructure networks are regularly developed and deployed for use by multiple China-nexus threat actors, existing networks are also updated because of defensive or legal action, software updates, or new exploits being used to target different technologies, according to the CSA. This renders a detailed list of all known networks (how they are constructed and communicated) and previous defense paradigms ineffective. Legitimate users also browse the internet using the networks and devices involved, making attribution of the malicious activity challenging. However, since most networks of compromised infrastructure use the same basic set up, understanding the generalized structure can help aid in defensive efforts.

This CSA explains the widespread shift in tactics, techniques, and procedures by malicious cyber actors away from using individually procured infrastructure to multiple externally managed large covert networks used by many actors simultaneously. It describes the typical makeup of a covert network and how it is used, and includes protective advice for organizations targeted by cyber activity using a covert network as an access vector. Additionally, the guidance outlines tailored steps organizations of all sizes can take to mitigate the risk of attacks.

Anyone who is a target of China-nexus threat actors may be impacted by the use of covert networks, and anyone using a vulnerable device could have their device co-opted into one of these China-nexus covert networks. Cybersecurity analysts and network defenders — including those protecting national security, Department of War, and Defense Industrial Base systems — are advised to use the protective advice and mitigations listed in this CSA to thwart malicious activities.

Read the full report.

Source: NSA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
44424
NSA, FBI warn of Russian GRU threats against routers https://intelligencecommunitynews.com/nsa-fbi-warn-of-russian-gru-threats-against-routers/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-russian-gru-threats-against-routers Fri, 10 Apr 2026 13:43:22 +0000 https://intelligencecommunitynews.com/?p=44296 On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service...

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service announcement, “Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information” to encourage further defensive actions.

The U.S. Department of Justice, FBI, and international law enforcement partners recently disrupted a GRU network of compromised small-office home-office (SOHO) routers used as part of malicious hijacking operations. All device owners and network defenders are encouraged to take action to remediate and reduce the attack surface of similar edge devices.

Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28, Fancy Bear, and Forest Blizzard — have collected credentials and exploited vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224.The GRU has indiscriminately compromised a wide pool of US and global victims, especially targeting information related to military, government, and critical infrastructure.

The FBI, NSA, and co-sealing agencies encourage SOHO router users to change default usernames and passwords, disable remote management interfaces from the Internet, update to latest firmware versions, and upgrade end-of-support devices. Users should also carefully consider certificate warnings in web browsers and email clients.

Organizations that allow telework should review relevant policies regarding how employees access sensitive data — including the use of virtual private networks (VPNs) or hardened application configurations.

If you, or someone you know, suspects that you have been targeted or compromised by a Russian GRU cyber intrusion, NSA recommends reporting the activity to your local FBI field office, filing a complaint with the Internet Crime Complaint Center (IC3), or otherwise following your organization’s incident reporting requirements.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
44296
NSA shares LEO SATCOM system risks and mitigations https://intelligencecommunitynews.com/nsa-shares-leo-satcom-system-risks-and-mitigations/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-shares-leo-satcom-system-risks-and-mitigations Wed, 25 Mar 2026 22:43:21 +0000 https://intelligencecommunitynews.com/?p=44170 On March 24, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in...

The post NSA shares LEO SATCOM system risks and mitigations appeared first on Intelligence Community News.

]]>
On March 24, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in collaboration with the Australian Space Agency and others in releasing the Cybersecurity Information Sheet (CSI), “Securing space: Cyber security for low earth orbit satellite communications.”

The report highlights high-level cybersecurity risks and mitigation strategies for users of Low Earth Orbit (LEO) satellite communication (SATCOM) systems. The risks and mitigations are detailed through the lens of the space segment comprising the satellites themselves; the ground segment encompassing satellite control centers, ground stations, gateways, and user terminals; the user segment that includes end-user devices, applications, and associated interfaces that connect to LEO SATCOM services; and the communication links and broader supply chain for LEO SATCOM systems.

The CSI suggests numerous mitigation strategies for the space segment and legacy space equipment, including implementing tailored security measures, and using frequency-hopping signals, redundant communication paths, and anti-jam antennas. For the ground segment, continuous monitoring and anomaly detection are essential. The user segment should focus on strengthening endpoint security and enforcing secure access practices.

The report also provides frameworks for maintaining the resilience of critical networks, while offering valuable insights and guidelines for users to understand their roles and responsibilities in securing LEO SATCOM systems.

LEO SATCOM systems improve network resilience and enable emergency communications across both government and private sectors; however, as LEO satellite constellations grow, the attack surface open to adversaries increases, significantly increasing the risk to the system if the correct cybersecurity measures are not applied.

In LEO SATCOM networks, Confidentiality, Integrity, and Availability — known as the CIA triad — are critical to maintaining secure and reliable operations. LEO SATCOM systems face unique challenges due to their distributed architecture and limited physical access to space-based assets. They also rely on radio frequency links that are susceptible to jamming, spoofing, and interception.

Organizations that use LEO SATCOM services are encouraged to review this guidance and adopt the outlined cybersecurity mitigations.

Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), and Australian Space Agency.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA shares LEO SATCOM system risks and mitigations appeared first on Intelligence Community News.

]]>
44170
NSA releases Cisco SD-WAN alert https://intelligencecommunitynews.com/nsa-releases-cisco-sd-wan-alert/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-cisco-sd-wan-alert Fri, 27 Feb 2026 14:58:04 +0000 https://intelligencecommunitynews.com/?p=43949 On February 26, the National Security Agency (NSA), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), and other...

The post NSA releases Cisco SD-WAN alert appeared first on Intelligence Community News.

]]>
On February 26, the National Security Agency (NSA), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), and other agencies issued the Cybersecurity Alert “Exploitation of Cisco SD-WAN Appliances,” and a corresponding, “Cisco SD-WAN Threat Hunt Guide.”

The alert warns of malicious cyber actors targeting Cisco Catalyst Software Defined Wide Area Network (SD-WAN) systems used globally. The Hunt Guide details the tactics, techniques, and procedures (TTPs) used by the actors, and helps organizations identify and investigate potential compromise of their Cisco Catalyst SD-WAN systems.

For over a year, malicious actors exploited vulnerabilities in Cisco SD-WANs. Most notably, by leveraging a previously unknown (zero-day) vulnerability, CVE-2026-20127, these actors introduced a malicious rogue peer, gained authenticated access, and established persistent, long-term presence within the compromised SD-WAN networks.

Cybersecurity professionals and network administrators are strongly advised to take immediate action to ensure all Cisco Catalyst SD-WAN devices are fully patched to the appropriate Fixed Release version. They are also advised to hunt for evidence of compromise, as described in the Hunt Guide, and apply Cisco’s SD-WAN hardening guidance to reduce risks. Patching, executing the Hunt Guide, and reviewing the SD-WAN hardening guidance in full is crucial for high-confidence network security.

Co-sealing this Cybersecurity Alert and Hunt Guide are the National Security Agency (NSA); Cybersecurity and Infrastructure Security Agency (CISA); Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC); Canadian Centre for Cyber Security (Cyber Centre); New Zealand’s National Cyber Security Centre (NCSC-NZ); and United Kingdom’s National Cyber Security Centre (NCSC-UK).

Read the full reports.
Exploitation of Cisco SD-WAN Appliances
Cisco SD-WAN Threat Hunt Guide

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA releases Cisco SD-WAN alert appeared first on Intelligence Community News.

]]>
43949
NSA releases first two phases of zero trust guidelines https://intelligencecommunitynews.com/nsa-releases-first-two-phases-of-zero-trust-guidelines/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-first-two-phases-of-zero-trust-guidelines Sun, 01 Feb 2026 18:46:02 +0000 https://intelligencecommunitynews.com/?p=43744 On January 30, the National Security Agency (NSA) released Phase One and Phase Two of the Zero Trust Implementation Guidelines (ZIGs) to outline the...

The post NSA releases first two phases of zero trust guidelines appeared first on Intelligence Community News.

]]>
On January 30, the National Security Agency (NSA) released Phase One and Phase Two of the Zero Trust Implementation Guidelines (ZIGs) to outline the activities needed to achieve the Department of War (DoW)-defined Target-level Zero Trust (ZT) maturity.

Phase One and Phase Two aim to move an organization from Discovery to Target-level implementation by mapping out the activities, requirements, precursors and successors as related to the activities. The phased design of the ZIGs offers modularity and high customizability, allowing implementation of foundational and advanced activities as applicable and the ability to tailor the ZIGs to align with unique goals and restraints.

Phase One details 36 activities organizations can use to build upon or further refine their environment to establish a secure foundation that supports 30 ZT capabilities specific to this phase.

Phase Two details 41 activities that initiate the integration of core ZT solutions within the component environment. These activities enable 34 capabilities specific to this phase.

Before reviewing these Phases, system owners, cybersecurity professionals, and stakeholders are encouraged to review the Primer and the Discovery Phase, released earlier this month, to ensure a deep understanding of ZT activities and their organization’s operational landscape prior to ZT implementation.

In conjunction with the Primer and Discovery, this series of ZIGs aim to guide and assist those planning to implement, or already implementing, ZT architecture, and provide a better understanding of the capabilities required to achieve Target level ZT maturity for the DoW CIO ZT Framework.

Read Phase One and Phase Two here.

Source: NSA

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post NSA releases first two phases of zero trust guidelines appeared first on Intelligence Community News.

]]>
43744
NSA releases first Zero Trust Implementation Guideline https://intelligencecommunitynews.com/nsa-releases-first-zero-trust-implementation-guideline/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-first-zero-trust-implementation-guideline Fri, 16 Jan 2026 14:49:14 +0000 https://intelligencecommunitynews.com/?p=43622 On January 14, the National Security Agency (NSA) released the first two products in a series of Zero Trust Implementation...

The post NSA releases first Zero Trust Implementation Guideline appeared first on Intelligence Community News.

]]>
On January 14, the National Security Agency (NSA) released the first two products in a series of Zero Trust Implementation Guidelines (ZIGs) to provide practical, actionable recommendations to facilitate the implementation of Zero Trust (ZT).

This series of reports outlines the steps to implement the technologies and processes that support achieving the Target-level ZT Capabilities, Activities, and Expected Outcomes described in the Department of War (DoW) CIO ZT Framework.

In this release, the Primer and Discovery Phase are the gateway to ZT implementation, providing guidance and direction to ensure organizations are fully equipped to digest and implement the Phase 1 and Phase 2 ZIGs upon their release.

The Primer outlines the strategy and principles used to develop the ZIGs and provides a holistic approach to maximizing the usage of the series. Notably, the ZIGs are designed to be modular, allowing organizations at different levels of ZT maturity to select and implement the capabilities most relevant to the needs of their environment.

The Discovery Phase is intended to help organizations establish foundational visibility and understand the critical data, applications, assets, and services, as well as access and authorization activity existing within the architecture. The goal of this initial phase is to enable informed prioritization and planning by creating a reliable baseline that supports effective ZT implementation.

System owners, cybersecurity professionals, and stakeholders should review these foundational guidelines to gain a deeper understanding of ZT activities and their organization’s operational landscape in preparation for the release of the Phase 1 and Phase 2 ZIGs.

Read the full products below:

 

Source: NSA

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post NSA releases first Zero Trust Implementation Guideline appeared first on Intelligence Community News.

]]>
43622
Tim Kosiba named next NSA deputy director https://intelligencecommunitynews.com/tim-kosiba-named-next-nsa-deputy-director/?utm_source=rss&utm_medium=rss&utm_campaign=tim-kosiba-named-next-nsa-deputy-director Sun, 11 Jan 2026 19:33:35 +0000 https://intelligencecommunitynews.com/?p=43569 On January 9, the National Security Agency (NSA) announced that Secretary of War Pete Hegseth and Director of National Intelligence...

The post Tim Kosiba named next NSA deputy director appeared first on Intelligence Community News.

]]>
On January 9, the National Security Agency (NSA) announced that Secretary of War Pete Hegseth and Director of National Intelligence Tulsi Gabbard have designated, and President Donald Trump has approved, Timothy Kosiba to serve as NSA’s 21st deputy director.

As the senior civilian leader of the agency, Kosiba will oversee strategy execution, establish policy, guide operations, and manage the senior civilian leadership. As an agency deputy in the U.S. national security system, he will support the U.S. defense and intelligence enterprise in the formulation of national security policies, and position NSA as an integrated mission partner enabling U.S. decisive advantage and security against foreign threats.

“On behalf of NSA and U.S. Cyber Command, I’d like to welcome Tim Kosiba back to NSA,” said LTG William J. Hartman, acting commander, U.S. Cyber Command; performing duties of director of the NSA, and chief of the Central Security Service (CSS). “Tim is a people-focused leader with a wealth of experience that makes him perfect for the deputy director role, accumulated over a distinguished 33-year federal career. I am confident that Tim will continue to drive and guide us in our critical foreign signals intelligence and cybersecurity missions. His expertise and leadership will be invaluable as we advance our efforts to protect national security interests.”

With more than 30 years of experience in the Intelligence Community, Kosiba is well versed in the NSA’s mission, bringing a deep understanding of public sector cybersecurity in both practice and policy. He has been instrumental in the successful implementation of the NSA’s Cyber Security Policy and frequently represented both the NSA and U.S. Cyber Command at the White House and other government-sponsored deliberations on cyber activities.

“It is an honor to come back home and serve as the National Security Agency’s next deputy director,” Kosiba said. “As it has been for more than 30 years, my deep commitment to our mission continues, and I am excited to once again serve alongside the agency’s incredible workforce.”

Source: NSA

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post Tim Kosiba named next NSA deputy director appeared first on Intelligence Community News.

]]>
43569
NSA, FBI warn of pro-Russia Hacktivist threats https://intelligencecommunitynews.com/nsa-fbi-warn-of-pro-russia-hacktivist-threats/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-pro-russia-hacktivist-threats Mon, 15 Dec 2025 13:17:23 +0000 https://intelligencecommunitynews.com/?p=43400 On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and over 20 others to release the Cybersecurity Advisory (CSA), “Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure,” and provide recommended mitigations to reduce the likelihood and impact of related incidents.

The authoring agencies have observed pro-Russia hacktivist groups—attributed to the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—capitalizing on the widespread availability of inadequately secured virtual network computing (VNC) connections to infiltrate operational technology (OT) control devices within critical infrastructure systems and conduct cyber operations against organizations worldwide.

The groups’ ongoing opportunistic targeting methodology can lead to broad targeting and indiscriminate compromise of critical infrastructure entities, including those in Water and Wastewater, Food and Agriculture, and the Energy Sector. Further, their observed lack of strategic focus increases the likelihood of targeting of unintended victims, and tends to result in haphazard attacks with unanticipated damages.

These actors are primarily seeking notoriety with their actions, regularly self-attributing and exaggerating cyberattacks on social media and in group channels to garner attention from peers and the media. Despite this, and their lack of sophisticated ability, actors have been observed willfully causing damage to vulnerable critical infrastructure.

These actors utilize simple, cheap, and easy-to-replicate tactics, techniques, and procedures (TTPs) for the ease of dissemination and replication across various entities, increasing the risk of wide-spread adoption by other cyber actors and escalated frequency of attacks. The authoring agencies warn there is risk that continued attacks may result in further harm or consequences.

Critical infrastructure entities, OT asset owners and operators, and OT device manufactures are encouraged to become familiar with the outlined TTPs and apply the recommended mitigation strategies to reduce the likelihood and impact of incidents related to pro-Russia hacktivists. The report also provides incident response actions organizations should take if compromise is detected.

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
43400