Risk
2/2/2010
04:35 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

U.S. 'Severely Threatened' By Cyber Attacks

The U.S. intelligence chief is urging greater cooperation and funding to defend against online threats.

Testifying before the Senate Intelligence Committee on Tuesday, the top U.S. intelligence official warned that U.S. critical infrastructure is "severely threatened" and called the recent cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

"Sensitive information is stolen daily from both government and private sector networks, undermining confidence in our information systems, and in the very information these systems were intended to convey," said Dennis C. Blair, Director of National Intelligence, in prepared remarks outlining the U.S. intelligence community's annual assessment of threats.

While Blair's testimony covered terrorism, nuclear proliferation, geo-political conflicts, global economic problems, risks associated with climate change, and global health challenges, it addressed cyber threats first.

"Malicious cyber activity is occurring on an unprecedented scale with extraordinary sophistication," he said, citing as an example the emergence in 2009 of malware that modifies itself to avoid detection.

Cyber criminals' capabilities presently exceed the response capabilities of those defending networks, Blair said, and urged companies to promptly report attacks to help the government understand and address the full range of cyber threats. He warned that cyber-facilitated bank fraud and credit fraud have serious implications for the economy and national security.

Looking ahead, he said that voice and data networks will converge over the next five years and that this convergence amplifies the potential disruption from cyber attacks.

To protect cyberspace, the U.S. government will need to collaborate more effectively with private sector partners and international authorities, said Blair.

He also urged Congress to fully fund the U.S. government's cyber security initiatives, noting that Congress had funded most, but not all, of the Administration's request last year.

Blair's comments come just days after the emergence of a leaked report from MI5, the U.K.'s counter-intelligence agency, about the risk of Chinese cyber-espionage and malware-infected electronic gifts.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.