Intel Agencies Archives - Intelligence Community News https://intelligencecommunitynews.com/category/intel-agencies/ Breaking news about the market for products, systems and services for the U.S. intelligence community Fri, 22 May 2026 11:56:42 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg Intel Agencies Archives - Intelligence Community News https://intelligencecommunitynews.com/category/intel-agencies/ 32 32 59882712 NSA releases security design considerations for AI-driven automation https://intelligencecommunitynews.com/nsa-releases-security-design-considerations-for-ai-driven-automation/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-security-design-considerations-for-ai-driven-automation Fri, 22 May 2026 11:56:42 +0000 https://intelligencecommunitynews.com/?p=44638 On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context...

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation.”

MCP is an application-level protocol that provides a simple and agreed upon messaging pattern and transport format currently used by many AI-enabled systems for managing interactions between services. The guidance aims to reduce risk while supporting safe innovation in AI-augmented systems.

Real-world adoption of MCP has accelerated. It is increasingly found in AI deployments across products used in business, finance, legal, software development, and other industries, including for sensitive tasks like querying personally identifiable information.

While MCP simplifies the integration of diverse capabilities into powerful agent workflows, the current protocol specification requires careful and cautious implementation for security. Gaps in MCP design, implementation, and operational posture have created significant and evolving security concerns including serialization risks, trust boundaries, and agent misuse, to name a few, according to the CSI.

Although traditional cybersecurity principles such as authentication, authorization, and input validation remain necessary protective measures, agentic AI systems — especially those featuring MCP — introduce novel and systemic risks like dynamic tool invocation, implicit trust relationships, and context sharing. Established cyber defense strategies unfortunately do not adequately address these new risks.
These are not isolated problems that can be patched at the interface or endpoint level. Securing MCP systems requires treating the agentic environment as a continuum. Misaligned assumptions or subtle inconsistencies at any stage can propagate and compound into exploitable conditions.

This report examines these security concerns, outlines gaps that must be addressed before MCP can be used securely and confidently. It offers practical recommendations for organizations adopting MCP in high-stakes or production environments. The guidance is designed to remain relevant as the MCP protocol, implementations, and operations continue to evolve.

Adopters are advised to proceed with caution, drawing on lessons from prior distributed and plugin-based ecosystems while applying heightened scrutiny to MCP’s novel integration and automation patterns. Continued collaborative work among implementers, security researchers, and standards organizations will be essential to establish more robust and trustworthy foundations for AI infrastructure, particularly for national security and other high assurance environments.

Read the full report.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
44638
NRO launches NROL-172 https://intelligencecommunitynews.com/nro-launches-nrol-172/?utm_source=rss&utm_medium=rss&utm_campaign=nro-launches-nrol-172 Tue, 12 May 2026 12:02:58 +0000 https://intelligencecommunitynews.com/?p=44544 On May 11, the National Reconnaissance Office (NRO), in partnership with U.S. Space Force Space Systems Command’s System Delta 80...

The post NRO launches NROL-172 appeared first on Intelligence Community News.

]]>
On May 11, the National Reconnaissance Office (NRO), in partnership with U.S. Space Force Space Systems Command’s System Delta 80 (SYD 80), Space Launch Delta 30, and SpaceX, successfully launched the NROL-172 mission aboard a SpaceX Falcon 9 rocket from Space Launch Complex-4 East at Vandenberg Space Force Base in California on May 11, 2026, at 10:13 p.m. EDT.

This mission is the thirteenth overall launch of the NRO’s multi-phenomenology proliferated architecture and second proliferated launch of 2026. NROL-172 is also the second mission in partnership with SSC SYD 80 under the National Security Space Launch (NSSL) Phase 3 Lane 1 Launch Service NRO Task Order awarded in October 2024. NSSL, a government launch acquisition partnership program between SSC and the NRO aimed at ensuring continued assured access to space for national security missions, is overseen and operated by SSC headquartered at Los Angeles Air Force Base in California.

NRO’s ability to leverage multiple acquisition approaches demonstrates NRO’s commitment to delivering critical national systems on orbit faster than ever before. The NRO’s proliferated architecture, in addition to our other ISR systems, supports multiple missions across the intelligence and Department of War (DoW) communities, including the ground moving target indicator mission as part of the DoW’s space-based sensing and targeting architecture.

Through sustained launch activity and accelerated deployment of next-generation systems, NRO fields the most advanced and capable government constellation our nation has ever delivered with hundreds of satellites now on orbit. Building on this momentum, 2026 is poised to be another dynamic year with a robust launch schedule. Many of these missions will advance the NRO’s proliferated architecture, with additional proliferated launches planned through 2029 to ensure sustained growth and innovation.

Source: NRO

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post NRO launches NROL-172 appeared first on Intelligence Community News.

]]>
44544
NSA, partners release agentic AI guidance https://intelligencecommunitynews.com/nsa-partners-release-agentic-ai-guidance/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-partners-release-agentic-ai-guidance Mon, 04 May 2026 11:42:21 +0000 https://intelligencecommunitynews.com/?p=44471 On April 30, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and...

The post NSA, partners release agentic AI guidance appeared first on Intelligence Community News.

]]>
On April 30, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and others to release the Cybersecurity Information Sheet (CSI), “Careful Adoption of Agentic AI Services.”

This report is a comprehensive guide to understanding and mitigating the unique risks associated with the rise of agentic artificial intelligence (AI) within critical infrastructure, including the defense sector. The CSI highlights general security considerations for agentic AI, including the inherited risks of large language models (LLMs), increased attack surfaces, increased complexity, the evolving security landscape as the technology matures, and the need to address AI security as part of established cybersecurity paradigms.

Unlike traditional generative AI, which typically requires human validation, agentic AI systems are designed to operate autonomously, making them a powerful tool. This presents both unprecedented opportunities and significant cybersecurity challenges organizations must address to protect national security and critical infrastructure.

Careful Adoption of Agentic AI Services” outlines risk spaces to consider, including:

•    Privilege Risks: Over-privileged agents can amplify the impact of a single compromise.
•    Design and Configuration Risks: Insecure design and provisioning can introduce vulnerabilities.
•    Behavior Risks: Goal misalignment, specification gaming, deceptive behavior, and emergent capabilities can lead to unexpected or undesirable outcomes.
•    Structural Risks: The interconnected nature of agentic systems increases the attack surface and complexity.
•    Accountability Risks: The opacity of agentic systems makes accountability hard to trace, complicating auditing and compliance.

Securing agentic AI systems requires proactive measures that address risks introduced by autonomy, interconnected components, and evolving capabilities. The report recommends deploying agentic AI incrementally, continuously assessing against evolving threat models, and maintaining strong governance, explicit accountability, rigorous monitoring, and human oversight which are essential for safe and secure operation.

Organizations that use agentic AI services, including those in the defense sector, are encouraged to review this guidance and adopt the outlined cybersecurity mitigations.

Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom National Cyber Security Centre (NCSC-UK).

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post NSA, partners release agentic AI guidance appeared first on Intelligence Community News.

]]>
44471
NSA releases joint guidance on defending against China-nexus covert networks https://intelligencecommunitynews.com/nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks Tue, 28 Apr 2026 11:30:36 +0000 https://intelligencecommunitynews.com/?p=44424 On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s...

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s Australian Cyber Security Centre, and others in releasing the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”

The CSA details how multiple China-nexus threat actors are now using external covert networks to facilitate malicious cyber activity strategically, at scale. These dynamic covert networks include botnets that leverage many compromised devices to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. These botnets frequently include compromised small office/home office network infrastructure (routers, firewalls, network attached storage, etc.) and internet of things devices (web cameras, video recorders, smart devices, etc.).

While many new covert infrastructure networks are regularly developed and deployed for use by multiple China-nexus threat actors, existing networks are also updated because of defensive or legal action, software updates, or new exploits being used to target different technologies, according to the CSA. This renders a detailed list of all known networks (how they are constructed and communicated) and previous defense paradigms ineffective. Legitimate users also browse the internet using the networks and devices involved, making attribution of the malicious activity challenging. However, since most networks of compromised infrastructure use the same basic set up, understanding the generalized structure can help aid in defensive efforts.

This CSA explains the widespread shift in tactics, techniques, and procedures by malicious cyber actors away from using individually procured infrastructure to multiple externally managed large covert networks used by many actors simultaneously. It describes the typical makeup of a covert network and how it is used, and includes protective advice for organizations targeted by cyber activity using a covert network as an access vector. Additionally, the guidance outlines tailored steps organizations of all sizes can take to mitigate the risk of attacks.

Anyone who is a target of China-nexus threat actors may be impacted by the use of covert networks, and anyone using a vulnerable device could have their device co-opted into one of these China-nexus covert networks. Cybersecurity analysts and network defenders — including those protecting national security, Department of War, and Defense Industrial Base systems — are advised to use the protective advice and mitigations listed in this CSA to thwart malicious activities.

Read the full report.

Source: NSA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
44424
CISA warns of programmable logic controller exploitation https://intelligencecommunitynews.com/cisa-warns-of-programmable-logic-controller-exploitation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-warns-of-programmable-logic-controller-exploitation Sun, 12 Apr 2026 17:37:55 +0000 https://intelligencecommunitynews.com/?p=44304 On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable...

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.”

Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

U.S. organizations should urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the Mitigations section of the advisory to reduce the risk of compromise.

Source: CISA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
44304
NSA, FBI warn of Russian GRU threats against routers https://intelligencecommunitynews.com/nsa-fbi-warn-of-russian-gru-threats-against-routers/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-russian-gru-threats-against-routers Fri, 10 Apr 2026 13:43:22 +0000 https://intelligencecommunitynews.com/?p=44296 On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service...

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service announcement, “Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information” to encourage further defensive actions.

The U.S. Department of Justice, FBI, and international law enforcement partners recently disrupted a GRU network of compromised small-office home-office (SOHO) routers used as part of malicious hijacking operations. All device owners and network defenders are encouraged to take action to remediate and reduce the attack surface of similar edge devices.

Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28, Fancy Bear, and Forest Blizzard — have collected credentials and exploited vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224.The GRU has indiscriminately compromised a wide pool of US and global victims, especially targeting information related to military, government, and critical infrastructure.

The FBI, NSA, and co-sealing agencies encourage SOHO router users to change default usernames and passwords, disable remote management interfaces from the Internet, update to latest firmware versions, and upgrade end-of-support devices. Users should also carefully consider certificate warnings in web browsers and email clients.

Organizations that allow telework should review relevant policies regarding how employees access sensitive data — including the use of virtual private networks (VPNs) or hardened application configurations.

If you, or someone you know, suspects that you have been targeted or compromised by a Russian GRU cyber intrusion, NSA recommends reporting the activity to your local FBI field office, filing a complaint with the Internet Crime Complaint Center (IC3), or otherwise following your organization’s incident reporting requirements.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
44296
ODNI releases 13th annual IC transparency report https://intelligencecommunitynews.com/odni-releases-13th-annual-ic-transparency-report/?utm_source=rss&utm_medium=rss&utm_campaign=odni-releases-13th-annual-ic-transparency-report Fri, 03 Apr 2026 14:03:12 +0000 https://intelligencecommunitynews.com/?p=44237 On April 1, the Office of the Director of National Intelligence (ODNI) released the Annual Statistical Transparency Report (ASTR) Regarding the...

The post ODNI releases 13th annual IC transparency report appeared first on Intelligence Community News.

]]>
On April 1, the Office of the Director of National Intelligence (ODNI) released the Annual Statistical Transparency Report (ASTR) Regarding the Intelligence Community’s (IC) Use of National Security Surveillance Authorities for Calendar Year 2025. The ASTR combines statistics with contextual information to share with the American people on the IC’s use of Foreign Intelligence Surveillance Act (FISA) authorities, National Security Letters, and other national security authorities. The report also provides insights into how these authorities are overseen to ensure privacy and protect the civil liberties of persons whose information is acquired as a part of the IC’s national security work.

A few of the report’s findings are highlighted below:

  • During this reporting period, there was an increase in the number of FISA Section 702 targets consistent with increases seen in previous annual reports.
  • The number of U.S. person query terms used by the National Security Agency (NSA), Central Intelligence Agency (CIA) and National Counterterrorism Center (NCTC) to query content remained relatively static.
  • The report notes the Foreign Intelligence Surveillance Court (FISC) issued three FISA Section 702 orders during this reporting period, including the approval of renewal certifications on March 18, 2025 (publicly released on September 12, 2025) and the approval of a new counternarcotics certification on April 9, 2025, following the FISC’s denial order on February 20, 2025 (publicly released on August 19, 2025).
  • The number of U.S. person queries conducted by the Federal Bureau of Investigation (FBI) increased slightly from the immediate prior period but remained lower than previous years, in large part because of the increased focus on technical and policy controls, as well as individual caution related to accurately implementing the reforms.
  • The report contains additional statistics, as well as explanations about how the IC uses its authorities and the counting methodologies to obtain the statistics.

 

Source: ODNI

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post ODNI releases 13th annual IC transparency report appeared first on Intelligence Community News.

]]>
44237
NGA’s MagQuest moves forward https://intelligencecommunitynews.com/ngas-magquest-moves-forward/?utm_source=rss&utm_medium=rss&utm_campaign=ngas-magquest-moves-forward Mon, 30 Mar 2026 12:53:39 +0000 https://intelligencecommunitynews.com/?p=44198 On March 29, the National Geospatial-Intelligence Agency (NGA) announced that it is sponsoring the launch of three small satellites this...

The post NGA’s MagQuest moves forward appeared first on Intelligence Community News.

]]>
On March 29, the National Geospatial-Intelligence Agency (NGA) announced that it is sponsoring the launch of three small satellites this spring to revolutionize how we measure Earth’s magnetic field. Developed through MagQuest, a 6-year, multimillion-dollar global competition, the satellites will launch aboard the Transporter-16 rideshare mission from Vandenberg Space Force Base, California, planned for March 30.

“We are on the verge of proving that small, affordable satellites can deliver the high-quality magnetic data our nation depends on,” said Mike Paniccia, NGA’s program manager for the World Magnetic Model. “These teams have spent the past few years pushing the boundaries of what’s possible with CubeSat technology, and this launch is the moment where all of that ingenuity meets the ultimate test.”

This mission represents the first-ever effort to collect reliable geomagnetic data using CubeSat technology. Once in orbit, the three CubeSats, equipped with novel solutions for precisely measuring Earth’s magnetic field, will provide data to update the World Magnetic Model — a critical infrastructure that underpins navigation for military operations, commercial aviation, and everyday mobile devices worldwide.

The current World Magnetic Model, WMM2025, is maintained using data from the European Space Agency’s Swarm mission, launched in 2013. NGA launched the MagQuest competition in 2019, seeking new, more resilient ways to collect geomagnetic data.

The CubeSat solutions developed through MagQuest can be built, launched, and operated for a fraction of the cost of the current system. MagQuest also demonstrates the effectiveness of open innovation and interagency collaboration in tackling a vital national security challenge.  Testing facilities and experts at NASA’s Goddard Space Flight Center in Greenbelt, Maryland, supported technology evaluations and analysis; NASA’s Center of Excellence for Collaborative Innovation administered the challenge; and the National Oceanic and Atmospheric Administration’s National Centers for Environmental Information provided technical support.

MagQuest’s open innovation approach intentionally attracted novel solutions from a unique group of innovators. Each team has developed a distinct CubeSat solution for collecting high-quality geomagnetic data from low-Earth orbit:

  • Compact Spaceborne Magnetic Observatory CubeSat, University of Colorado Boulder
  • Diamond-Powered Geomagnetic Data Collection from LEO, Spire Global and SBQuantum
  • Io-1, Iota Technology

 

The teams delivered their completed satellites to Exolaunch for final integration for launch. Following a successful launch and satellite deployment, each team will begin geomagnetic data collection and compare their findings to WMM2025.

An expert review panel will evaluate each team’s data across key milestones. The results of MagQuest will inform NGA’s acquisition strategy for a WMM global magnetic field data collection capability, to support production of the next global update, WMM2030.

Source: NGA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NGA’s MagQuest moves forward appeared first on Intelligence Community News.

]]>
44198
NSA shares LEO SATCOM system risks and mitigations https://intelligencecommunitynews.com/nsa-shares-leo-satcom-system-risks-and-mitigations/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-shares-leo-satcom-system-risks-and-mitigations Wed, 25 Mar 2026 22:43:21 +0000 https://intelligencecommunitynews.com/?p=44170 On March 24, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in...

The post NSA shares LEO SATCOM system risks and mitigations appeared first on Intelligence Community News.

]]>
On March 24, the National Security Agency (NSA) joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in collaboration with the Australian Space Agency and others in releasing the Cybersecurity Information Sheet (CSI), “Securing space: Cyber security for low earth orbit satellite communications.”

The report highlights high-level cybersecurity risks and mitigation strategies for users of Low Earth Orbit (LEO) satellite communication (SATCOM) systems. The risks and mitigations are detailed through the lens of the space segment comprising the satellites themselves; the ground segment encompassing satellite control centers, ground stations, gateways, and user terminals; the user segment that includes end-user devices, applications, and associated interfaces that connect to LEO SATCOM services; and the communication links and broader supply chain for LEO SATCOM systems.

The CSI suggests numerous mitigation strategies for the space segment and legacy space equipment, including implementing tailored security measures, and using frequency-hopping signals, redundant communication paths, and anti-jam antennas. For the ground segment, continuous monitoring and anomaly detection are essential. The user segment should focus on strengthening endpoint security and enforcing secure access practices.

The report also provides frameworks for maintaining the resilience of critical networks, while offering valuable insights and guidelines for users to understand their roles and responsibilities in securing LEO SATCOM systems.

LEO SATCOM systems improve network resilience and enable emergency communications across both government and private sectors; however, as LEO satellite constellations grow, the attack surface open to adversaries increases, significantly increasing the risk to the system if the correct cybersecurity measures are not applied.

In LEO SATCOM networks, Confidentiality, Integrity, and Availability — known as the CIA triad — are critical to maintaining secure and reliable operations. LEO SATCOM systems face unique challenges due to their distributed architecture and limited physical access to space-based assets. They also rely on radio frequency links that are susceptible to jamming, spoofing, and interception.

Organizations that use LEO SATCOM services are encouraged to review this guidance and adopt the outlined cybersecurity mitigations.

Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), and Australian Space Agency.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA shares LEO SATCOM system risks and mitigations appeared first on Intelligence Community News.

]]>
44170
CISA issues cyberattack alert, recommendations https://intelligencecommunitynews.com/cisa-issues-cyberattack-alert-recommendations/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-cyberattack-alert-recommendations Sun, 22 Mar 2026 23:34:54 +0000 https://intelligencecommunitynews.com/?p=44133 On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting...

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.

To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.

To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune; the principles of these recommendations can be applied to Intune and more broadly to other endpoint management software:

  • Use principles of least privilege when designing administrative roles.
  • Enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene.
  • Configure access policies to require Multi Admin Approval in Microsoft Intune.

 

Source: CISA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
44133