cyberattack Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cyberattack/ Breaking news about the market for products, systems and services for the U.S. intelligence community Tue, 28 Apr 2026 11:30:36 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg cyberattack Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cyberattack/ 32 32 59882712 NSA releases joint guidance on defending against China-nexus covert networks https://intelligencecommunitynews.com/nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks Tue, 28 Apr 2026 11:30:36 +0000 https://intelligencecommunitynews.com/?p=44424 On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s...

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s Australian Cyber Security Centre, and others in releasing the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”

The CSA details how multiple China-nexus threat actors are now using external covert networks to facilitate malicious cyber activity strategically, at scale. These dynamic covert networks include botnets that leverage many compromised devices to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. These botnets frequently include compromised small office/home office network infrastructure (routers, firewalls, network attached storage, etc.) and internet of things devices (web cameras, video recorders, smart devices, etc.).

While many new covert infrastructure networks are regularly developed and deployed for use by multiple China-nexus threat actors, existing networks are also updated because of defensive or legal action, software updates, or new exploits being used to target different technologies, according to the CSA. This renders a detailed list of all known networks (how they are constructed and communicated) and previous defense paradigms ineffective. Legitimate users also browse the internet using the networks and devices involved, making attribution of the malicious activity challenging. However, since most networks of compromised infrastructure use the same basic set up, understanding the generalized structure can help aid in defensive efforts.

This CSA explains the widespread shift in tactics, techniques, and procedures by malicious cyber actors away from using individually procured infrastructure to multiple externally managed large covert networks used by many actors simultaneously. It describes the typical makeup of a covert network and how it is used, and includes protective advice for organizations targeted by cyber activity using a covert network as an access vector. Additionally, the guidance outlines tailored steps organizations of all sizes can take to mitigate the risk of attacks.

Anyone who is a target of China-nexus threat actors may be impacted by the use of covert networks, and anyone using a vulnerable device could have their device co-opted into one of these China-nexus covert networks. Cybersecurity analysts and network defenders — including those protecting national security, Department of War, and Defense Industrial Base systems — are advised to use the protective advice and mitigations listed in this CSA to thwart malicious activities.

Read the full report.

Source: NSA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
44424
NSA, FBI warn of Russian GRU threats against routers https://intelligencecommunitynews.com/nsa-fbi-warn-of-russian-gru-threats-against-routers/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-russian-gru-threats-against-routers Fri, 10 Apr 2026 13:43:22 +0000 https://intelligencecommunitynews.com/?p=44296 On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service...

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service announcement, “Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information” to encourage further defensive actions.

The U.S. Department of Justice, FBI, and international law enforcement partners recently disrupted a GRU network of compromised small-office home-office (SOHO) routers used as part of malicious hijacking operations. All device owners and network defenders are encouraged to take action to remediate and reduce the attack surface of similar edge devices.

Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28, Fancy Bear, and Forest Blizzard — have collected credentials and exploited vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224.The GRU has indiscriminately compromised a wide pool of US and global victims, especially targeting information related to military, government, and critical infrastructure.

The FBI, NSA, and co-sealing agencies encourage SOHO router users to change default usernames and passwords, disable remote management interfaces from the Internet, update to latest firmware versions, and upgrade end-of-support devices. Users should also carefully consider certificate warnings in web browsers and email clients.

Organizations that allow telework should review relevant policies regarding how employees access sensitive data — including the use of virtual private networks (VPNs) or hardened application configurations.

If you, or someone you know, suspects that you have been targeted or compromised by a Russian GRU cyber intrusion, NSA recommends reporting the activity to your local FBI field office, filing a complaint with the Internet Crime Complaint Center (IC3), or otherwise following your organization’s incident reporting requirements.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
44296
CISA issues cyberattack alert, recommendations https://intelligencecommunitynews.com/cisa-issues-cyberattack-alert-recommendations/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-cyberattack-alert-recommendations Sun, 22 Mar 2026 23:34:54 +0000 https://intelligencecommunitynews.com/?p=44133 On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting...

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.

To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.

To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune; the principles of these recommendations can be applied to Intune and more broadly to other endpoint management software:

  • Use principles of least privilege when designing administrative roles.
  • Enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene.
  • Configure access policies to require Multi Admin Approval in Microsoft Intune.

 

Source: CISA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
44133
NSA and partners reveal Chinese state-sponsored actions https://intelligencecommunitynews.com/nsa-and-partners-reveal-chinese-state-sponsored-actions/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-partners-reveal-chinese-state-sponsored-actions Wed, 21 Jul 2021 13:51:14 +0000 https://intelligencecommunitynews.com/?p=29964 On July 19, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI)...

The post NSA and partners reveal Chinese state-sponsored actions appeared first on Intelligence Community News.

]]>
On July 19, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) released a Cybersecurity Advisory, Chinese State-Sponsored Cyber Operations: Observed TTPs. This advisory describes over 50 tactics, techniques, and procedures (TTPs) Chinese state-sponsored cyber actors used when targeting U.S. and allied networks, and details mitigations.

Chinese state-sponsored cyber activity poses a major threat to U.S. and allied systems. These actors aggressively target political, economic, military, educational, and critical infrastructure personnel and organizations to access valuable, sensitive data. These cyber operations support China’s long-term economic and military objectives.

One significant tactic detailed in the advisory includes the exploitation of public vulnerabilities within days of their public disclosure, often in major applications, such as Pulse Secure, Apache, F5 Big-IP, and Microsoft products. This advisory provides specific mitigations for detailed tactics and techniques aligned to the recently released, NSA Funded MITRE D3FEND framework.

General mitigations outlined include: prompt patching; enhanced monitoring of network traffic, email, and endpoint systems; and the use of protection capabilities, such as an antivirus and strong authentication, to stop malicious activity.

The advisory is broken into three parts: an overview of this nation state threat for executive decision makers, a deep dive into the techniques used when targeting U.S. and allied networks, and a table providing a visualization of the malicious activity for net defenders, mapped to the MITRE ATT&CK framework.

The NSA, CISA, and FBI recommended mitigations empower our customers to reduce the risk of Chinese malicious cyber activity, and increase the defensive posture of their critical networks.

Source: NSA

The post NSA and partners reveal Chinese state-sponsored actions appeared first on Intelligence Community News.

]]>
29964
NSA and partners expose brute force global cyber campaign https://intelligencecommunitynews.com/nsa-and-partners-expose-brute-force-global-cyber-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-partners-expose-brute-force-global-cyber-campaign Fri, 09 Jul 2021 13:13:37 +0000 https://intelligencecommunitynews.com/?p=29870 On July 1, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and...

The post NSA and partners expose brute force global cyber campaign appeared first on Intelligence Community News.

]]>
On July 1, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and the UK’s National Cyber Security Centre (NCSC) released a Cybersecurity Advisory exposing malicious cyber activities by Russian military intelligence against U.S. and global organizations, starting from mid-2019 and likely ongoing.  This advisory is being released as part of NSA’s routine and continuing cybersecurity mission to warn network defenders of nation state threats.

“Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments” details how the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) has targeted hundreds of U.S. and foreign organizations using brute force access to penetrate government and private sector victim networks. The advisory reveals the tactics, techniques, and procedures (TTPs) GTsSS actors used in their campaign to exploit targeted networks, access credentials, move laterally, and collect and exfiltrate data. It also arms system administrators with the mitigations needed to counter this threat.

Malicious cyber actors use brute force techniques to discover valid credentials often through extensive login attempts, sometimes with previously leaked usernames and passwords or by guessing with variations of the most common passwords. While the brute force technique is not new, the GTsSS uniquely leveraged software containers to easily scale its brute force attempts.

Once valid credentials were discovered, the GTsSS combined them with various publicly known vulnerabilities to gain further access into victim networks. This, along with various techniques also detailed in the advisory, allowed the actors to evade defenses and collect and exfiltrate various information in the networks, including mailboxes.

The advisory warns system administrators that exploitation is almost certainly ongoing. Targets have been global, but primarily focused on the United States and Europe. Targets include government and military, defense contractors, energy companies, higher education, logistics companies, law firms, media companies, political consultants or political parties, and think tanks.

NSA encourages Department of Defense (DoD), National Security Systems (NSS), and Defense Industrial Base (DIB) system administrators to immediately review the indicators of compromise (IOCs) included in the advisory and to apply the recommended mitigations. The most effective mitigation is the use of multi-factor authentication, which is not guessable during brute force access attempts. Read the advisory for a complete list of IOCs and mitigations.

Visit NSA.gov/What-We-Do/Cybersecurity/Advisories-Technical-Guidance/ to read more.

Source: NSA

 

The post NSA and partners expose brute force global cyber campaign appeared first on Intelligence Community News.

]]>
29870
NIST releases ransomware framework draft https://intelligencecommunitynews.com/nist-releases-ransomware-framework-draft/?utm_source=rss&utm_medium=rss&utm_campaign=nist-releases-ransomware-framework-draft Fri, 11 Jun 2021 13:42:27 +0000 https://intelligencecommunitynews.com/?p=29642 On June 10, the National Institute of Standards and Technology (NIST) released the preliminary draft of the Cybersecurity Framework Profile...

The post NIST releases ransomware framework draft appeared first on Intelligence Community News.

]]>
On June 10, the National Institute of Standards and Technology (NIST) released the preliminary draft of the Cybersecurity Framework Profile for Ransomware Risk Management. Comments are due by July 9.

Ransomware is a type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access. In some instances, attackers may also steal an organization’s information and demand additional payment in return for not disclosing the information to authorities, competitors, or the public. Ransomware can disrupt or halt organizations’ operations.

This report defines a Ransomware Profile, which identifies security objectives from the NIST Cybersecurity Framework that support preventing, responding to, and recovering from ransomware events. The profile can be used as a guide to managing the risk of ransomware events. That includes helping to gauge an organization’s level of readiness to mitigate ransomware threats and to react to the potential impact of events.

Source: NIST

The post NIST releases ransomware framework draft appeared first on Intelligence Community News.

]]>
29642
FBI, CISA, ODNI issue statement on cyberattack https://intelligencecommunitynews.com/fbi-cisa-odni-issue-statement-on-cyberattack/?utm_source=rss&utm_medium=rss&utm_campaign=fbi-cisa-odni-issue-statement-on-cyberattack Fri, 18 Dec 2020 14:49:20 +0000 https://intelligencecommunitynews.com/?p=28262 On December 16, the the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Office...

The post FBI, CISA, ODNI issue statement on cyberattack appeared first on Intelligence Community News.

]]>
On December 16, the the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) issued the following joint statement:

Over the course of the past several days, the FBI, CISA, and ODNI have become aware of a significant and ongoing cybersecurity campaign. Pursuant to Presidential Policy Directive (PPD) 41, the FBI, CISA, and ODNI have formed a Cyber Unified Coordination Group (UCG) to coordinate a whole-of-government response to this significant cyber incident. The UCG is intended to unify the individual efforts of these agencies as they focus on their separate responsibilities. This is a developing situation, and while we continue to work to understand the full extent of this campaign, we know this compromise has affected networks within the federal government.

As the lead for threat response, the FBI is investigating and gathering intelligence in order to attribute, pursue, and disrupt the responsible threat actors. The FBI is engaging with known and suspected victims and information gained through FBI’s efforts will provide indicators to network defenders and intelligence to our government partners to enable further action.

pAs the lead for asset response activities, CISA took immediate action and issued an Emergency Directive instructing federal civilian agencies to immediately disconnect or power down affected SolarWinds Orion products from their network. CISA remains in regular contact with our government, private sector and international partners, providing technical assistance upon request, and making needed information and resources available to help those affected quickly recover from this incident. CISA is engaging with our public and private stakeholders across the critical infrastructure community to ensure they understand their exposure and are taking steps to identify and mitigate any compromises.

As the lead for intelligence support and related activities, ODNI is helping to marshal all of the Intelligence Community’s relevant resources to support this effort and share information across the United States Government.

To report suspicious or criminal activity related to information found in this statement, contact your local FBI field office at www.fbi.gov/contact-us/field. To request incident response resources or technical assistance related to this statement, visit https://www.us-cert.gov/report or email Central@cisa.gov.

Source: ODNI

The post FBI, CISA, ODNI issue statement on cyberattack appeared first on Intelligence Community News.

]]>
28262
NSA offers help detecting malicious authentication https://intelligencecommunitynews.com/nsa-offers-help-detecting-malicious-authentication/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-offers-help-detecting-malicious-authentication Fri, 18 Dec 2020 14:44:28 +0000 https://intelligencecommunitynews.com/?p=28260 In response to ongoing cybersecurity events, the National Security Agency (NSA) released a Cybersecurity Advisory on December 17 titled, “Detecting...

The post NSA offers help detecting malicious authentication appeared first on Intelligence Community News.

]]>
In response to ongoing cybersecurity events, the National Security Agency (NSA) released a Cybersecurity Advisory on December 17 titled, “Detecting Abuse of Authentication Mechanisms.” This advisory provides guidance to National Security System (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) network administrators to detect and mitigate against malicious cyber actors who are manipulating trust in federated authentication environments to access protected data in the cloud. It builds on the guidance shared in the cybersecurity advisory regarding VMware with state-sponsored actors exploiting CVE 2020-4006 and forging credentials to access protected files, though other nation states and cyber criminals may use this tactic, technique, and procedure (TTP) as well.

This advisory specifically discusses detection and mitigation of two TTPs to forge authentications and gain access to a victim’s cloud resources. While these TTPs require the actors to already have privileged access in an on-premises environment, they are still dangerous as they can be combined with other vulnerabilities to gain initial access, then undermine trust, security, and authentication. Initial access can be established through a number of means, including known and unknown vulnerabilities. The recent SolarWinds Orion ® code compromise is one serious example of how on-premises systems can be compromised, leading to abuse of federated authentication and malicious cloud access.

Mitigation actions include hardening and monitoring systems that run local identity and federation services, locking down tenant single sign-on (SSO) configuration in the cloud, and monitoring for indicators of compromise. NSA remains committed to providing provide timely, actionable and relevant guidance, and is partnering across the public and private sectors in ongoing incident response efforts. Releasing this advisory with further technical guidance allows NSA’s customers to apply preventative measures to the fullest extent along with the detection and mitigation actions.

Read the full advisory here.
Read the abridged version here.

Source: NSA

The post NSA offers help detecting malicious authentication appeared first on Intelligence Community News.

]]>
28260
Mercury Systems earns cyberattack protection patent https://intelligencecommunitynews.com/mercury-systems-earns-cyberattack-protection-patent/?utm_source=rss&utm_medium=rss&utm_campaign=mercury-systems-earns-cyberattack-protection-patent Wed, 19 Aug 2020 20:14:03 +0000 https://intelligencecommunitynews.com/?p=27297 Andover, MA-based Mercury Systems, Inc. announced on August 18 the receipt of a new U.S. patent covering various methods to...

The post Mercury Systems earns cyberattack protection patent appeared first on Intelligence Community News.

]]>
Andover, MA-based Mercury Systems, Inc. announced on August 18 the receipt of a new U.S. patent covering various methods to protect controller area network (CAN)-based systems from malicious cyberattacks. This new patent adds to Mercury’s intellectual property portfolio of more than 80 issued patents.

A wide range of applications and market segments utilize CAN-based systems, such as electronic control units (ECU) in automotive electronics or avionics. When these systems are interconnected, cyberattacks may potentially compromise them, leading to financial loss or even safety issues. Mercury’s Broadcast Bus Frame Filter protects ECUs against hacking attempts with zero latency and can be used with any system with a CAN bus, including automotive, military, and industrial systems.

“The patent award, combined with our recently announced Cogswell award for security program management, affirms our continued commitment to designing uncompromised solutions in the face of growing cybersecurity threats and delivering Innovation that Matters to our customers,” said Brian Perry, senior vice president and general manager of Processing at Mercury Systems. “This new patent also expands what we believe are the industry’s most advanced embedded systems security engineering and cyber resiliency capabilities.”

Source: Mercury

The post Mercury Systems earns cyberattack protection patent appeared first on Intelligence Community News.

]]>
27297
Reps. Nunes and Westmoreland comment on Anthem hack https://intelligencecommunitynews.com/reps-nunes-and-westmoreland-comment-on-anthem-hack/?utm_source=rss&utm_medium=rss&utm_campaign=reps-nunes-and-westmoreland-comment-on-anthem-hack Thu, 05 Feb 2015 21:49:47 +0000 http://intelligencecommunitynews.com/?p=5265 Rep. Devin Nunes, Chairman of the House Permanent Select Committee on Intelligence, and Rep. Lynn Westmoreland, Chairman of the Intelligence...

The post Reps. Nunes and Westmoreland comment on Anthem hack appeared first on Intelligence Community News.

]]>
HPSCI 112Rep. Devin Nunes, Chairman of the House Permanent Select Committee on Intelligence, and Rep. Lynn Westmoreland, Chairman of the Intelligence Committee’s NSA and Cybersecurity Subcommittee, released the following statements on February 5 in reaction to the cyberattack on Anthem health insurer:

Chairman Nunes: “Alongside the recent cyberattack on Sony, the hacking of Anthem shows the urgent need to improve our nation’s cybersecurity infrastructure. We’ve seen time and again that businesses and other private entities are vulnerable to cyberattacks by criminals, terrorists, and foreign governments. This situation is untenable – that’s why a top priority of the House Intelligence Committee is to develop a strong cyber bill that encourages private companies to share information about attacks on their systems.”

Chairman Westmoreland: “The Anthem hack shows the immediate need for enhanced cybersecurity measures, for both national security purposes and to protect our citizens. The hackers have exposed the weaknesses in our current system, and have jeopardized sensitive and personal data. As Chairman of the relevant Subcommittee on the House Intelligence Committee, I find this breach is unacceptable and will work hard to review and strengthen our nation’s cybersecurity laws to improve our defenses against cyber attacks.”

Source: US House of Representatives

The post Reps. Nunes and Westmoreland comment on Anthem hack appeared first on Intelligence Community News.

]]>
5265