CISA Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cisa/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 12 Apr 2026 17:37:55 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg CISA Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cisa/ 32 32 59882712 CISA warns of programmable logic controller exploitation https://intelligencecommunitynews.com/cisa-warns-of-programmable-logic-controller-exploitation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-warns-of-programmable-logic-controller-exploitation Sun, 12 Apr 2026 17:37:55 +0000 https://intelligencecommunitynews.com/?p=44304 On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable...

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.”

Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

U.S. organizations should urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the Mitigations section of the advisory to reduce the risk of compromise.

Source: CISA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
44304
CISA issues cyberattack alert, recommendations https://intelligencecommunitynews.com/cisa-issues-cyberattack-alert-recommendations/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-cyberattack-alert-recommendations Sun, 22 Mar 2026 23:34:54 +0000 https://intelligencecommunitynews.com/?p=44133 On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting...

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.

To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.

To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune; the principles of these recommendations can be applied to Intune and more broadly to other endpoint management software:

  • Use principles of least privilege when designing administrative roles.
  • Enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene.
  • Configure access policies to require Multi Admin Approval in Microsoft Intune.

 

Source: CISA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
44133
CISA releases directive on edge device risk mitigation https://intelligencecommunitynews.com/cisa-releases-directive-on-edge-device-risk-mitigation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-directive-on-edge-device-risk-mitigation Thu, 12 Feb 2026 12:44:04 +0000 https://intelligencecommunitynews.com/?p=43839 The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy...

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy of the American people. These campaigns are often enabled by unsupported devices that physically reside on the edge of an organization’s network perimeter. Unsupported devices – referred to in this Directive as “end of support (EOS)” – are those that are no longer maintained by their vendors.

The imminent threat of exploitation to agency information systems running EOS edge devices is substantial and constant, resulting in a significant threat to federal property. CISA is aware of widespread exploitation campaigns by advanced threat actors targeting EOS edge devices. Recent public reports of campaigns targeting certain vendors highlight actors’ attempts to use these devices as a means to pivot into FCEB information system networks. Edge devices are attractive targets due to their extensive reach into an organization’s network and integrations with identity management systems. These devices are especially vulnerable to cyber exploits targeting newly discovered, unpatched vulnerabilities. Additionally, they no longer receive supported updates from the original equipment manufacturer, exposing federal systems to disproportionate and unacceptable risks. However, unlike many attack vectors, this can be remediated by agencies following proven lifecycle management practices as outlined in the required actions of this Directive.

This Binding Operational Directive, developed in coordination with OMB, implements OMB policy on phasing out unsupported information systems and information system components. BOD 26-02 specifically addresses EOS devices deployed on the “edge” or public-facing areas of federal networks, exposed to external environments such as the internet. However, EOS devices should not reside anywhere on federal networks. This Directive aligns with OMB’s Circular A-1301Managing Information as a Strategic Resource, which establishes policy for the management of federal information resources, emphasizing security, privacy, and the efficient use of resources throughout their lifecycle. A-130 requires that “unsupported information systems and system components are phased out as rapidly as possible, and planning and budgeting activities for all IT systems and services incorporate migration planning and resourcing to accomplish this requirement.”2 Agencies should mature their lifecycle management practices to identify hardware and software nearing their EOS dates, plan for timely replacements, procure vendor-supported alternatives, and develop a plan for decommissioning EOS devices while minimizing disruptions to agency operations. Agencies that do not maintain appropriate lifecycle management processes for edge devices have a greater risk of compromise and an increased overall risk associated with EOS technology.

To support agencies in the initial identification of EOS devices, CISA developed an EOS Edge Device List. This preliminary repository provides information on devices that are already EOS or soon-to-be EOS. This Directive requires federal agencies to use this information to identify and remediate vulnerabilities within the first three months of Directive issuance. This Directive also specifies long-term requirements for managing EOS edge devices across all federal networks.

Review the directive from CISA.

Source: CISA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
43839
Elastic partners with CISA https://intelligencecommunitynews.com/elastic-partners-with-cisa/?utm_source=rss&utm_medium=rss&utm_campaign=elastic-partners-with-cisa Wed, 17 Dec 2025 14:09:52 +0000 https://intelligencecommunitynews.com/?p=43430 On December 16, Elastic announced that it is partnering with the Cybersecurity and Infrastructure Security Agency (CISA) to develop a unified...

The post Elastic partners with CISA appeared first on Intelligence Community News.

]]>
On December 16, Elastic announced that it is partnering with the Cybersecurity and Infrastructure Security Agency (CISA) to develop a unified Security Information and Event Management as-a-Service (SIEMaaS) offering, using Elastic Security on Elastic Cloud. The new SIEMaaS will help to strengthen the security posture of U.S. federal civilian agencies by standardizing security data collection across agencies, enabling real-time threat detection and rapid incident response.

The commitment with CISA is part of a $26 million base-year contract through ECS, a provider of advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, and an ASGN (NYSE: ASGN Incorporated) brand. This contract has the opportunity to renew under the same terms for up to four additional years, for a total anticipated agreement value of up to $130M.

Building on their long-standing partnership with CISA and Elastic’s leadership in next-gen SIEM, Elastic and ECS will help design, host, and operate a new SIEMaaS on its FedRAMP-certified Elastic Cloud. The program will standardize cybersecurity monitoring across Federal Civilian Executive Branch Agencies (FCEBs) to enhance security with greater speed, scale, and operational consistency, while leveraging Elastic’s standards-based platform to significantly reduce costs associated with data access and retention.

The first tenant to adopt the SIEMaaS platform is a large FCEB agency. This first implementation will serve as the operational blueprint for broader rollout across additional federal entities, to accelerate time-to-protection and create a repeatable, cost-efficient model for shared cyber defense.

With cyber adversaries accelerating their use of supply chain attacks, identity-based intrusions, and zero-day exploits, agencies face mounting pressure to detect, investigate, and respond to threats in real time. Even with the advances spurred by Executive Orders 14028 and M-21-31, which have significantly advanced Zero Trust adoption and enhanced logging practices, gaps persist in achieving whole-of-government cyber visibility.

This SIEMaaS initiative directly addresses those gaps by delivering a shared, unified, cloud-hosted platform for large-scale data ingestion, threat analytics, and incident response, all powered by the Elasticsearch Platform—an open, extensible platform that manages both structured and unstructured data. The program will help break down legacy silos and enable CISA analysts and FCEB agencies to collaborate on accessible, unified cyber defense.

“Federal agencies remain a top target for cyber adversaries, and the current pace and complexity of attacks demand a new operational model,” said Ash Kulkarni, CEO of Elastic. “By consolidating cybersecurity telemetry into a shared, cloud-based SIEM service built on Elastic’s platform, CISA is setting a new standard for speed, scale, and collective defense across civilian agencies.”

Source: Elastic

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Elastic partners with CISA appeared first on Intelligence Community News.

]]>
43430
NSA, FBI warn of pro-Russia Hacktivist threats https://intelligencecommunitynews.com/nsa-fbi-warn-of-pro-russia-hacktivist-threats/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-pro-russia-hacktivist-threats Mon, 15 Dec 2025 13:17:23 +0000 https://intelligencecommunitynews.com/?p=43400 On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and over 20 others to release the Cybersecurity Advisory (CSA), “Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure,” and provide recommended mitigations to reduce the likelihood and impact of related incidents.

The authoring agencies have observed pro-Russia hacktivist groups—attributed to the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—capitalizing on the widespread availability of inadequately secured virtual network computing (VNC) connections to infiltrate operational technology (OT) control devices within critical infrastructure systems and conduct cyber operations against organizations worldwide.

The groups’ ongoing opportunistic targeting methodology can lead to broad targeting and indiscriminate compromise of critical infrastructure entities, including those in Water and Wastewater, Food and Agriculture, and the Energy Sector. Further, their observed lack of strategic focus increases the likelihood of targeting of unintended victims, and tends to result in haphazard attacks with unanticipated damages.

These actors are primarily seeking notoriety with their actions, regularly self-attributing and exaggerating cyberattacks on social media and in group channels to garner attention from peers and the media. Despite this, and their lack of sophisticated ability, actors have been observed willfully causing damage to vulnerable critical infrastructure.

These actors utilize simple, cheap, and easy-to-replicate tactics, techniques, and procedures (TTPs) for the ease of dissemination and replication across various entities, increasing the risk of wide-spread adoption by other cyber actors and escalated frequency of attacks. The authoring agencies warn there is risk that continued attacks may result in further harm or consequences.

Critical infrastructure entities, OT asset owners and operators, and OT device manufactures are encouraged to become familiar with the outlined TTPs and apply the recommended mitigation strategies to reduce the likelihood and impact of incidents related to pro-Russia hacktivists. The report also provides incident response actions organizations should take if compromise is detected.

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
43400
NSA advises how to detect BRICKSTORM backdoor activity https://intelligencecommunitynews.com/nsa-advises-how-to-detect-brickstorm-backdoor-activity/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-advises-how-to-detect-brickstorm-backdoor-activity Fri, 05 Dec 2025 14:30:03 +0000 https://intelligencecommunitynews.com/?p=43328 On December 4, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre...

The post NSA advises how to detect BRICKSTORM backdoor activity appeared first on Intelligence Community News.

]]>
On December 4, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems.

BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure command and control, remote system control, and long-term persistence.

Organizations—especially those within critical infrastructure, government services and facilities, and the Information Technology sector—are encouraged to use the indicators of compromise (IOCs) and detection signatures outlined in the report to detect BRICKSTORM backdoor activity. If BRICKSTORM, similar malware, or potentially related activity is detected, promptly report the compromise.

Read the full report here.

Source: NSA

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA advises how to detect BRICKSTORM backdoor activity appeared first on Intelligence Community News.

]]>
43328
NSA shares guidance on bulletproof hosting providers risk mitigation https://intelligencecommunitynews.com/nsa-shares-guidance-on-bulletproof-hosting-providers-risk-mitigation/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-shares-guidance-on-bulletproof-hosting-providers-risk-mitigation Fri, 21 Nov 2025 14:49:09 +0000 https://intelligencecommunitynews.com/?p=43232 On November 19, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release...

The post NSA shares guidance on bulletproof hosting providers risk mitigation appeared first on Intelligence Community News.

]]>
On November 19, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release the Cybersecurity Information Sheet (CSI), “Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers,” to provide internet service providers (ISPs) and network defenders recommendations to mitigate potential cybercriminal activity enabled by bulletproof hosting (BPH) providers.

BPH providers are internet infrastructure providers that knowingly and intentionally market and lease their infrastructure to cybercriminals. These providers do not engage in good faith with legal processes or third-party/victim complaints of malicious activity enabled from such infrastructure. Cybercriminals are increasingly utilizing BPH infrastructure as it allows them to evade law enforcement and conduct malicious operations against critical infrastructure, financial institutions, and other high-value targets without fear of losing access to their servers.

The CSI provides information on mitigating cybercriminal activity enabled by BPH providers through a nuanced approach; because BPH infrastructure is integrated into legitimate internet infrastructure systems, certain actions from defenders may impact legitimate activity.

The authoring agencies urge ISPs and network defenders to implement the outlined mitigation strategies to block malicious traffic, decrease the utility of BPH infrastructure, and force cybercriminals onto legitimate infrastructure. Before applying the recommendations, ISPs and network defenders should weigh the associated risks, ensuring that actions taken do not unduly impact legitimate infrastructure.

Also co-sealing are the DoD Cyber Crime Center (DC3); Federal Bureau of Investigation; Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC); Canadian Centre for Cyber Security (Cyber Centre); Netherlands National Cyber Security Centre (NCSC-NL); New Zealand National Cyber Security Centre (NCSC-NZ); and United Kingdom National Cyber Security Centre (NCSC-UK).

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA shares guidance on bulletproof hosting providers risk mitigation appeared first on Intelligence Community News.

]]>
43232
Matt Hartman joins Merlin as CSO https://intelligencecommunitynews.com/matt-hartman-joins-merlin-as-cso/?utm_source=rss&utm_medium=rss&utm_campaign=matt-hartman-joins-merlin-as-cso Wed, 08 Oct 2025 12:10:57 +0000 https://intelligencecommunitynews.com/?p=42882 On October 6, Merlin Group announced the appointment of Matt Hartman as its chief strategy officer (CSO). A seasoned cybersecurity executive and most recently...

The post Matt Hartman joins Merlin as CSO appeared first on Intelligence Community News.

]]>
On October 6, Merlin Group announced the appointment of Matt Hartman as its chief strategy officer (CSO). A seasoned cybersecurity executive and most recently acting head of cyber at the Cybersecurity and Infrastructure Security Agency (CISA), Hartman brings unparalleled expertise and a proven track record of driving innovation to safeguard the United States’ most critical digital assets.

Hartman brings more than two decades of leadership in strengthening the nation’s cybersecurity posture. At CISA, Hartman played a pivotal role in shaping the nation’s cybersecurity strategy and strengthening collaboration between the federal government and private sector technology innovators. His deep understanding of the cybersecurity landscape and ability to work across the public and private sectors will help Merlin Group amplify its impact and strengthen its role as a trusted partner, both to technology companies and to government agencies.

“Matt’s appointment marks a significant milestone for Merlin Group,” said David Phelps, founder, CEO, and chairman of Merlin Group. “His leadership at CISA and his ability to navigate the needs of both government and industry align seamlessly with our mission. Matt’s insight will accelerate the vision I started more than 30 years ago: delivering practical, game-changing solutions to protect our nation’s critical systems.”

Merlin Group’s mission is to bridge the gap between cyber technology manufacturers and the public sector and regulated commercial markets, ensuring that cutting-edge technologies reach the markets where they are needed most. With Hartman’s leadership, the company will expand its efforts to help companies bring their products into high-stakes markets.

“After nearly two decades at CISA, I’m thrilled to have the opportunity to remain focused on this critically important mission,” said Hartman. “A significant challenge the government consistently faces is gaining rapid access to emerging technologies that our nation’s cyber defenders need to stay ahead of threats. The opportunity to work with a team dedicated to identifying, accelerating, and scaling the delivery of transformative technologies to our nation’s first-line defenders is incredibly exciting.”

Source: Merlin Group

Keep up with your competitors by following notable executive moves across the IC contracting space — become a paid subscriber to IC News.

The post Matt Hartman joins Merlin as CSO appeared first on Intelligence Community News.

]]>
42882
NSA, CISA, and partners release SBOM information https://intelligencecommunitynews.com/nsa-cisa-and-partners-release-sbom-information/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-cisa-and-partners-release-sbom-information Thu, 04 Sep 2025 12:31:05 +0000 https://intelligencecommunitynews.com/?p=42603 On September 3, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release...

The post NSA, CISA, and partners release SBOM information appeared first on Intelligence Community News.

]]>
On September 3, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release the Cybersecurity Information Sheet (CSI), “A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity,” to inform producers, choosers, and operators of software of the advantages of integrating SBOM generation, analysis, and sharing into existing security processes and practices.

Understanding the risks in a software’s supply chain, including the risks of the software components, is fundamental for a more secure software ecosystem. SBOM enables greater visibility across an organization’s supply chain and enterprise system by documenting information about software dependencies.

The CSI outlines the value of increased software component and supply chain transparency in addressing these risks and securing the software ecosystem.

Further, the report provides risk management practices for organizations to leverage the transparency associated with SBOMs and mitigate software supply chain vulnerabilities, along with examples of how they can be used to reduce risk. The CSI also explains the importance of SBOM as a part of the Secure by Design initiative.

The authoring agencies urge the adoption of a joint vision of SBOM throughout the cybersecurity community to improve effectiveness, while reducing costs and complexities, as differing implementations could hinder the widespread and sustainable implementation of SBOM.

Read the full report here.

Source: NSA

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

 

The post NSA, CISA, and partners release SBOM information appeared first on Intelligence Community News.

]]>
42603
NSA shares OT asset inventory guidance https://intelligencecommunitynews.com/nsa-shares-ot-asset-inventory-guidance/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-shares-ot-asset-inventory-guidance Thu, 14 Aug 2025 02:26:16 +0000 https://intelligencecommunitynews.com/?p=42428 On August 13, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release...

The post NSA shares OT asset inventory guidance appeared first on Intelligence Community News.

]]>
On August 13, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and others to release the Cybersecurity Technical Report (CTR), “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators.”

As a vital part of critical infrastructure, operational technology (OT) is often targeted by malicious cyber actors seeking to degrade our way of life, disrupt or destroy systems and services, or conduct nefarious activities such as extortion. This guidance outlines the process to create an OT asset inventory, develop a taxonomy of OT systems, and create a modern defensible architecture by providing net defenders with digestible foundational elements and best practices.

Using the processes outlined, organizations are encouraged to build an asset inventory to aid in risk identification, vulnerability management, and incident response. Additionally, the CTR details steps OT owners and operators should take to best use, maintain, and improve their asset inventory to protect vital assets, enhance their overall security posture, and ensure the safety of their OT environments.

This is especially relevant in defending the operation OT systems and services across National Security Systems (NSS), the Department of Defense (DoD), and the Defense Industrial Base (DIB).

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post NSA shares OT asset inventory guidance appeared first on Intelligence Community News.

]]>
42428