Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/20/2018
03:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Intel Officials Share Their National Cybersecurity Concerns

Leaders in the security sector discuss the most pressing cyberthreats threatening the United States and what can be done to mitigate them.

National Intelligence director Dan Coats put the threat to national cybersecurity into context on July 13, 2018, when he said "the warning lights are blinking red again" in a speech before the Hudson Institute, a Washington, DC-based conservative think tank.

Coats was trying to get our attention, says Tonya Ugoretz, director of the Cyber Threat Intelligence Integration Center at the Office of the Director of National Intelligence. She was one of several national security experts to take the stage today at Cyber Live 202, an event hosted by The Washington Post and focused on modern cyber threats to national security.

The system was also "blinking red" back in 2001, when intelligence and law enforcement agencies detected activity signifying a threat to the United States. Now it's happening again, but it's our digital infrastructure that could be under attack, Ugoretz explained. She cited Russia as the most aggressive foreign actor the department sees in cyberspace, "with good reason."

"Aggression is widespread, it's against multiple sectors, it's against multiple types of networks," she said. If we create a dialogue around sharing information, notifying victims if they're hit with intrusion or influence campaigns, we can better plan our defense.

For example, the DHS and FBI issued alerts this year about Russia's efforts against the US and allies, warning defenders to protect against Russian activity in critical infrastructure. The Justice Department now has a brand-new policy to disclose the existence of information warfare attacks against the US political system when there is high confidence in the foreign actor behind it.

These practices are helpful but ultimately weak without leadership from the top. "The President himself does not take seriously the capability of Russian intelligence services," said Mike Rogers, former chairman of the House Intelligence Committee and national security commentator for CNN. "It's very, very concerning to me."

Rogers was referring to the recent meeting between President Trump and Russian President Vladimir Putin in Helsinki, during which the US President dismissed Russian interference indictments related to activity during the US presidential election. While Putin was prepared for the meeting and knew what he would get out of it, Trump "was not prepared," Rogers said.

The meeting played right into the information operations Russia had been conducting and will continue, he added. "They're getting better at it and they're getting more aggressive about it … this is what I worry about," Rogers emphasized. Intelligence officials monitor Russian bot operations trying to influence different topics every day, and the volume is getting bigger.

Intelligence experts agree a full government approach is needed to tackle the threat. "One of the things no one's really done a good job of so far is imposing a cost on bad state actors for their activities," said Chris Painter, former and first-appointed cyber coordinator for the US State Department. The cost would both punish them and deter them from future activity, he said.

"The President hadn't said, 'If this happens again there will be consequences' … and I think a lot of people in government are waiting for that leadership," Painter continued.

Jason Matheny, director of the Intelligence Advanced Research Projects Activity (IARPA), spoke to the future and said one of cybersecurity's biggest threats "is sort of boring": 70-80% of threats from nation-states and cybercriminals are social engineering attacks, he noted.

Within the next 5- to ten years, both threats and defenses will become more sophisticated due to machine learning, which is being used to detect phishing emails as they arrive. "There's now an arms race," he said, as people developing phishing attacks use the same technology to create subtle attacks that bypass advanced filters.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/23/2020
Modern Day Insider Threat: Network Bugs That Are Stealing Your Data
David Pearson, Principal Threat Researcher,  10/21/2020
Are You One COVID-19 Test Away From a Cybersecurity Disaster?
Alan Brill, Senior Managing Director, Cyber Risk Practice, Kroll,  10/21/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27743
PUBLISHED: 2020-10-26
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
CVE-2020-1915
PUBLISHED: 2020-10-26
An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application usi...
CVE-2020-26878
PUBLISHED: 2020-10-26
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
CVE-2020-26879
PUBLISHED: 2020-10-26
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
CVE-2020-15272
PUBLISHED: 2020-10-26
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has been patched in version ...