Mobile

5/8/2017
12:06 PM
50%
50%

DHS Report Outlines Feds' Mobile Security Threats

The US Department of Homeland Security sent Congress a study on mobile security threats facing federal government workers as well as recommendations for protection.

Mobile devices used by federal government workers are potentially at a higher risk of attack than those used by consumers, solely for the mere fact that they are public-sector employees, according to a report presented to Congress last week by the US Department of Homeland Security.

Cybercriminals targeting government workers' mobile devices view them as a potential channel to accessing back-end computer systems rich in data containing sensitive federal government information and private information on millions of Americans, according to the DHS.

While federal workers are at risk to many of the same cybersecurity threats that the average consumer faces, such as ransomware, banking fraud, and identity theft, some of the solutions to address the mobile security problem differ than that of consumers.

DHS recommends developing cooperative arrangements with mobile network operators to detect, defend, and respond to threats – and potentially extending the DHS National Protection and Programs Directorate authority to achieve these objectives. The study also calls for more policy and procedural changes that recognize mobile security should be treated differently than desktop architecture security.

Some of DHS' recommendations are similar to those practiced by the private sector, such as adopting a mobile device security framework that uses existing standards and best practices, and including mobility in a continuous security diagnostics and mitigation program similar to that of network devices.

Read more on the DHS study here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11378
PUBLISHED: 2019-04-20
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2019-11372
PUBLISHED: 2019-04-20
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11373
PUBLISHED: 2019-04-20
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11374
PUBLISHED: 2019-04-20
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVE-2019-11375
PUBLISHED: 2019-04-20
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.