endpoint Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/endpoint/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 22 Mar 2026 23:34:54 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg endpoint Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/endpoint/ 32 32 59882712 CISA issues cyberattack alert, recommendations https://intelligencecommunitynews.com/cisa-issues-cyberattack-alert-recommendations/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-cyberattack-alert-recommendations Sun, 22 Mar 2026 23:34:54 +0000 https://intelligencecommunitynews.com/?p=44133 On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting...

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.

To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.

To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune; the principles of these recommendations can be applied to Intune and more broadly to other endpoint management software:

  • Use principles of least privilege when designing administrative roles.
  • Enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene.
  • Configure access policies to require Multi Admin Approval in Microsoft Intune.

 

Source: CISA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
44133
Curtiss-Wright announces expanded IQ-Core product https://intelligencecommunitynews.com/curtiss-wright-announces-expanded-iq-core-product/?utm_source=rss&utm_medium=rss&utm_campaign=curtiss-wright-announces-expanded-iq-core-product Tue, 15 Oct 2024 12:17:04 +0000 https://intelligencecommunitynews.com/?p=39982 On October 14, Curtiss-Wright’s Defense Solutions Division announced the latest addition to its IQ-Core family of software communications solutions with...

The post Curtiss-Wright announces expanded IQ-Core product appeared first on Intelligence Community News.

]]>
On October 14, Curtiss-Wright’s Defense Solutions Division announced the latest addition to its IQ-Core family of software communications solutions with the introduction of the new IQ-Core Endpoint Configuration Assistant (ECA). IQ-Core ECA eliminates the time and complexity required to manually configure and onboard End User Devices (EUDs) for Commercial Solutions for Classified (CSfC) enclaves.

The National Security Agency (NSA) CSfC program defines the requirements for enabling EUDs to transmit and receive classified data over untrusted or vulnerable networks with the use of commercially available encryption technology. A demonstration of IQ-Core ECA will be presented in Curtiss-Wright’s booth (#2143) during the AUSA 2024 Annual Meeting and Exposition, October 14-16, 2024.

“Our range of software solutions is renowned for making otherwise complex and laborious IT processes, such as setting up and managing mobile networks at the tactical edge, fast, intuitive and error-free,” said Brian Perry, senior vice president and general manager, Curtiss-Wright Defense Solutions Division. “Our new software utility, IQ-Core Endpoint Configuration Assistant, onboards EUDs and accurately configures each to meet NSA CSfC standards. IQ-Core ECA was developed in the USA by Curtiss-Wright’s industry-leading PacStar product line software development team.”

IQ-Core ECA helps maintain NSA CSfC compliance by generating keys and certificate signing requests directly on EUDs. Certificates can then be automatically issued and installed on the device using the existing IQ-Core Crypto Manager (CM), which supports all CSfC-certified Certificate Authorities. IQ-Core ECA also supports a manual workflow for environments that require a strict separation of roles.  After the EUD certificates are installed, the IQ-Core ECA helps the operator configure both inner and outer virtual private networks (VPN) to connect to the CSfC infrastructure. IQ-Core ECA ensures that the installation and configuration of VPN clients and EUD Wi-Fi adapters is performed in a secure, NSA-compliant manner. Once the EUD is configured, IQ-Core ECA monitors the VPN tunnels and alerts the operator to any connectivity issues in a simple graphical view.

Source: Curtiss-Wright

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Curtiss-Wright announces expanded IQ-Core product appeared first on Intelligence Community News.

]]>
39982
ECS secures ARCYBER AESS recompete https://intelligencecommunitynews.com/ecs-secures-arcyber-aess-recompete/?utm_source=rss&utm_medium=rss&utm_campaign=ecs-secures-arcyber-aess-recompete Fri, 04 Nov 2022 13:05:21 +0000 https://intelligencecommunitynews.com/?p=33864 On November 3, Fairfax, VA-based ECS announced that it has won a five-year, $430 million, recompete contract to support the...

The post ECS secures ARCYBER AESS recompete appeared first on Intelligence Community News.

]]>
On November 3, Fairfax, VA-based ECS announced that it has won a five-year, $430 million, recompete contract to support the Army Endpoint Security Solution (AESS). ECS will continue their work providing managed service operations and developing enhanced functionality for AESS 2.0, the next generation of the AESS platform.

Overseen by United States Army Cyber Command (ARCYBER), AESS protects up to 800K endpoints across the Army unclassified and classified networks. As the AESS managed services provider (MSP), ECS provides the Army with traditional and advanced protections (such as data loss prevention, extended detection and response, and machine learning), threat prevention, web control, firewall, and adaptive threat protection. The ECS-designed, cloud-ready platform delivers automatic security, instantaneous visibility, and specialized protections for traditional endpoints as well as public and private clouds.

As part of the recompete contract, ECS will expand the system’s endpoint detection and response capabilities and create a unified asset management system providing increased visibility and management of all network devices managing the Comply to Connect (C2C) systems. AESS 2.0 will provide the Army unified visibility and reporting across the enterprise networks to better optimize compliance, threat detection, investigation, and response.

“Cybersecurity threats continue to evolve, and with AESS 2.0, ECS is collaborating with ARCYBER and the Army’s Network Enterprise Technology Command (NETCOM) to deliver a zero-trust solution to help the Army defend its unified networks against these emerging threats,” said Mark Maglin, vice president of DoD Cybersecurity at ECS. “Our open architecture allows for continuous innovation and integration. We look forward to continuing our strong partnership with ARCYBER and NETCOM.”

“For the past six years, ECS has provided ARCYBER with industry-leading managed IT and cybersecurity services,” said John Heneghan, president of ECS. “AESS 2.0 will not only improve the security of Army networks, but also enhance the Army’s threat intelligence capabilities by enabling the solution to integrate with the Army’s big data platform, GABRIEL NIMBUS, as well as other Department of Defense (DoD) data platforms. We are honored to continue the critical AESS mission.”

Source: ECS

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

 

The post ECS secures ARCYBER AESS recompete appeared first on Intelligence Community News.

]]>
33864
SentinelOne completes Attivo acquisition https://intelligencecommunitynews.com/sentinelone-completes-attivo-acquisition/?utm_source=rss&utm_medium=rss&utm_campaign=sentinelone-completes-attivo-acquisition Thu, 05 May 2022 11:53:49 +0000 https://intelligencecommunitynews.com/?p=32297 SentinelOne, an autonomous cybersecurity platform company based in Mountain View, CA, announced on May 4 that it has completed the...

The post SentinelOne completes Attivo acquisition appeared first on Intelligence Community News.

]]>
SentinelOne, an autonomous cybersecurity platform company based in Mountain View, CA, announced on May 4 that it has completed the acquisition of Attivo Networks. SentinelOne previously announced the agreement to acquire Attivo Networks on March 15, 2022.

Attivo Networks is a leading identity security and lateral movement protection company with a rapidly growing business serving hundreds of global enterprises including Fortune 500 organizations. With this acquisition, SentinelOne extends Singularity XDR capabilities to identity-based threats across endpoint, cloud workloads, IoT devices, mobile, and data wherever it resides, setting the standard for XDR and accelerating enterprise zero trust adoption.

Together, the companies said, SentinelOne and Attivo Networks deliver comprehensive identity security as part of Singularity XDR for autonomous protection including:

  • Singularity Identity: End credential misuse through real-time infrastructure defense for Active Directory and deception-based endpoint protections. Singularity Identity defends Active Directory and Azure AD domain controllers and domain-joined assets from adversaries aiming to gain privilege and move covertly.
  • Singularity Ranger Active Directory Assessor: Uncover vulnerabilities in Active Directory and Azure AD with a cloud-delivered, continuous identity assessment solution. Ranger Active Directory Assessor delivers prescriptive, actionable insight to reduce Active Directory and Azure AD attack surfaces, bringing them in line with security best practices.
  • Singularity Hologram: Lure network and insider threat actors into engaging and revealing themselves with network-based threat deception. Singularity Hologram decoys stand ready, waiting to be engaged by adversaries and insiders. The resulting telemetry supports investigations and contributes to adversary intelligence.

Source: SentinelOne

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post SentinelOne completes Attivo acquisition appeared first on Intelligence Community News.

]]>
32297
CISA selects CrowdStrike to support EDR initiative https://intelligencecommunitynews.com/cisa-selects-crowdstrike-to-support-edr-initiative/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-selects-crowdstrike-to-support-edr-initiative Thu, 02 Dec 2021 13:07:35 +0000 https://intelligencecommunitynews.com/?p=31066 On December 1, Sunnyvale, CA-based CrowdStrike Inc. announced that the Cybersecurity and Infrastructure Security Agency (CISA) has worked with multiple...

The post CISA selects CrowdStrike to support EDR initiative appeared first on Intelligence Community News.

]]>
On December 1, Sunnyvale, CA-based CrowdStrike Inc. announced that the Cybersecurity and Infrastructure Security Agency (CISA) has worked with multiple federal agencies to select CrowdStrike as one of the major platforms to support the Executive Order (EO) endpoint detection and response (EDR) initiative. CrowdStrike brings the cloud-native AI-driven power of the CrowdStrike Falcon platform to secure critical endpoints and workloads for CISA and multiple other major civilian agencies and directly operationalize Executive Order (EO) 14028, the landmark guidance that unifies a number of initiatives and policies to strengthen the U.S. national and Federal Government cybersecurity posture.

Through the combination of CrowdStrike’s technology, real-time threat intelligence on shifting adversary tradecraft and elite threat hunting, CISA will significantly strengthen its Continuous Diagnostics and Mitigation (CDM) program and advance its mission of securing civilian “.gov” networks and leading the national effort to understand and manage cyber and physical risk to critical infrastructure.

“CISA is on the front lines when it comes to defending our country’s most critical assets against the endless and evolving threats that nation-state and eCrime adversaries present,” said George Kurtz, co-founder and chief executive officer of CrowdStrike. “Improving our nation’s defenses and cyber resiliency requires strong collaboration between the government and the private sector. This partnership will arm CISA and government agencies with CrowdStrike’s powerful technology and elite human expertise to stop sophisticated attacks and protect our nation’s critical infrastructure.”

CrowdStrike Falcon is FedRAMP authorized and rapidly enables agencies to detect and automatically prevent cyberattacks at the edge. Powered by the Security Cloud and delivered through a single cloud-native agent, CrowdStrike delivers comprehensive protection at scale, reducing complexity and driving down operational costs, while empowering CISA security teams with hyper-accurate detections, automated protection and remediation, and elite threat hunting. Leveraging funds appropriated from The White House’ American Rescue Plan, CISA and CrowdStrike will enhance the value of CDM Defend – the next iteration of Department of Homeland Security’s (DHS) Continuous Diagnostics and Mitigation program – to deliver true operational security capabilities through a single integrated platform.

EO 14028 embraces some concepts which CrowdStrike introduced to the marketplace over the past decade – concepts that have become cybersecurity best practices for the private sector’s most technologically advanced businesses. The Executive Order explicitly calls for the mandating of government entities to embrace cybersecurity tools and concepts such as threat hunting, EDR and IT modernization, and to prioritize the adoption of cloud technologies. The expanded partnership between CISA and CrowdStrike operationalizes these concepts as the two organizations look to rapidly strengthen public-private collaboration and cyber resiliency.

Source: CrowdStrike

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post CISA selects CrowdStrike to support EDR initiative appeared first on Intelligence Community News.

]]>
31066
ARCYBER seeks Endpoint Security Solution as a Service https://intelligencecommunitynews.com/arcyber-seeks-endpoint-security-solution-as-a-service/?utm_source=rss&utm_medium=rss&utm_campaign=arcyber-seeks-endpoint-security-solution-as-a-service Wed, 18 Aug 2021 11:29:20 +0000 https://intelligencecommunitynews.com/?p=30214 On August 16, the Army Cyber Command (ARCYBER) posted a sources sought notice for an endpoint security solution as a...

The post ARCYBER seeks Endpoint Security Solution as a Service appeared first on Intelligence Community News.

]]>
On August 16, the Army Cyber Command (ARCYBER) posted a sources sought notice for an endpoint security solution as a service. Responses are due by 4:00 p.m. Central on September 15.

ARCYBER is seeking information for potential sources for an Army Endpoint Security Solution (AESS) managed service capability.  As the information technology service provider for the Army, Network Enterprise Technology Command (NETCOM) plans, integrates, and protects the Army’s enterprise network. In executing this mission, Army Cyber Command (ARCYBER) seeks to improve visibility in the security of Army endpoints, regardless of operational domain, and to track compliance metrics providing robust asset protection and systems to appropriately detect and respond to cyber threats regardless of location or environments.

Background

As the information technology service provider for the Army, Network Enterprise Technology Command (NETCOM) plans, integrates, and protects the Army’s enterprise network. In executing this mission, Army Cyber Command (ARCYBER) seeks to improve visibility the security of Army endpoint regardless of operational domain, track compliance metrics, provide robust asset protection and systems appropriately detect and respond to cyber threats regardless of location. Environments. Management shall be executed quickly, effectively, with efficiency.

Objectives

The objective of this effort is to provide a managed solution that will deliver capabilities to drive improved security and reduced risk across the Army. This solution must meet the following broad objectives:

1) An Endpoint Protection solution that provides protection for all Army endpoints regardless of operating system

2) A Unified Asset Management solution that provides asset (endpoints and non-endpoints) visibility and management, to include compliance reporting and vulnerability tracking

3) An Extended Endpoint Detection and Response solution that unifies reporting from endpoint protection platforms with telemetry from other security and business tools to optimize threat detection, investigation, and response

4) A Threat Intelligence solution that will allow for ingestion of third-party and Government intelligence and integrated alerts based on that intelligence. All solutions must be able to integrate with the Army’s Big Data Platform, and must be able to provide seamless capability for local (on-premises), cloud, or hybrid environments.

Read the full sources sought notice from ARCYBER.

Source: SAM

The post ARCYBER seeks Endpoint Security Solution as a Service appeared first on Intelligence Community News.

]]>
30214
SolarWinds launches new endpoint detection and response capabilities https://intelligencecommunitynews.com/solarwinds-launches-new-endpoint-detection-and-response-capabilities/?utm_source=rss&utm_medium=rss&utm_campaign=solarwinds-launches-new-endpoint-detection-and-response-capabilities Wed, 18 Mar 2020 13:49:53 +0000 https://intelligencecommunitynews.com/?p=25991 SolarWinds of Durham, NC announced on March 18 the launch of SolarWinds N-central 12.3, offering new features including SolarWinds Endpoint Detection...

The post SolarWinds launches new endpoint detection and response capabilities appeared first on Intelligence Community News.

]]>
SolarWinds of Durham, NC announced on March 18 the launch of SolarWinds N-central 12.3, offering new features including SolarWinds Endpoint Detection and Response (EDR), updated Network Topology Mapping, and capabilities for managing VMware systems.

Now integrated into the N-central platform, SolarWinds Endpoint Detection and Response (powered by SentinelOne) is designed to defend endpoints against nearly every type of attack, in real-time, across the threat lifecycle. It provides SolarWinds partners with the ability to view threat and incident data to help keep them and their customers ahead of threats, providing greater visibility into suspicious activity and advanced attacks from one dashboard. If an attack succeeds and a breach occurs, automated quarantine and rollback help ensure recovery is fast and customer downtime is minimal.

Other new features are focused on continuing the commitment to deliver market-leading network management solutions. Existing Network Topology Mapping has been updated to accelerate and improve customer device information access with enhancements including a new node filtering widget and easier viewing of node asset and device warranty details. In addition, users can now ramp up their automation workflows with new VMware objects that help discover, monitor, and manage VMware systems including Host-, Storage-, Guest-, and Snapshot-related objects. The new release also makes it easier to discover and monitor VMware vCenter systems.

“Security threats multiply and morph daily, and once a new threat is resolved, cybercriminals find another angle to exploit. One of the main reasons MSPs lose business today is due to cybersecurity concerns and attacks,” said Mav Turner, group vice president of products, SolarWinds MSP. “SolarWinds EDR is a game-changing feature designed for MSPs to help prevent cyberattacks, detect threats and if a threat is successful, deliver resources to respond and recover quickly. EDR integration with SolarWinds N-central quickly and easily allows MSPs to add security services to their portfolio and protect customer endpoints from a single dashboard. The newest features within N-central are designed with one thing in mind—to arm our partners with the tools they need to solve today’s IT management challenges quickly and securely, helping make their business—and their customers—successful.”

Source: SolarWinds

The post SolarWinds launches new endpoint detection and response capabilities appeared first on Intelligence Community News.

]]>
25991
DISA posts EDR sources sought https://intelligencecommunitynews.com/disa-posts-edr-sources-sought/?utm_source=rss&utm_medium=rss&utm_campaign=disa-posts-edr-sources-sought Mon, 27 Jan 2020 13:48:33 +0000 https://intelligencecommunitynews.com/?p=25455 On January 24, the Defense Information Systems Agency (DISA) posted a sources sought notice for Endpoint Detection and Response (EDR)....

The post DISA posts EDR sources sought appeared first on Intelligence Community News.

]]>
On January 24, the Defense Information Systems Agency (DISA) posted a sources sought notice for Endpoint Detection and Response (EDR). Responses are due by 4:00 p.m. Eastern on February 17.

The Endpoint Security Portfolio is seeking information for potential sources for Endpoint Detection and Response (EDR) capability allowing cyber defenders to quickly detect and investigate security incidents and automatically detect malicious system activities and behaviors.  EDR capabilities continuously record significant events occurring on managed systems for the purpose of identifying, reporting, and investigating malicious activity; thereby reducing and adversary’s dwell time on DoD networks.  Recorded data accessible through a management console query interface.  The EDR capability complements other endpoint security measures and capabilities; the ability to restrict execution of high-risk applications and computer processing. 

For the purposes of this Sources Sought, endpoints are described as follows:

  • Thick Client – Network clients running on fully-capable systems – Local storage and processing capability; can operate independently if not connected to a network.
  • Thin Client – Network client running on minimally-capable system – Minimal local storage and processing capability.
  • Zero Client – Client with no capability outside of network context.
  • Server – Respond to client requests; provide enterprise services (typically in data centers). Users are System Administrators.
  • Virtual Client – Client running virtually on a host platform; no physical resources.

The target is an endpoint (excluding devices like phones and tablets) security and management solution that mitigates prevalent adversary attack vectors, tactics, and techniques used to compromise a system.  The proposed solution must automatically isolate the execution of high risk applications interacting with untrusted content from more trusted portions of the endpoint (e.g. host operating system); and/or the solution must facilitate incident detection, investigation, response and threat hunting. 

Any proposed solution must continue to be effective in disconnected, virtual, intermittent, and low bandwidth network conditions without a dependence upon regularly recurring (e.g. daily, weekly, monthly) content updates.  The proposed solution must be capable of scaling to millions of endpoints and provide information in near real-time.  Any proposed solution must be ready for testing and subsequent deployment.

Full information is available here.

Source: SAM

The post DISA posts EDR sources sought appeared first on Intelligence Community News.

]]>
25455