Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Monday, July 6, 2026

Launch Your Cyber Career: Department of War Cyber Apprenticeship Applications Now Live!

Earn While You Learn and Defend the Nation's Digital Frontlines on USAJOBS

The U.S. Department of War (DoW) Office of the Chief Information Officer launched today one the most highly anticipated apprenticeship programs in modern defense history: applications for the DoW Cyber Apprenticeship Program (Cyber RAP) are now officially open on USAJOBS.

This groundbreaking initiative represents a critical step in forging a new generation of elite cyber professionals dedicated to defending the nation's digital frontlines and supporting the warfighter.

The application window for this round of applicants is now open and closes on July 17, 2026. Interested candidates will start their journey on USAJobs at: https://www.usajobs.gov/job/875318000.

Following its initial preview in late April, the program went "viral" across social media platforms, capturing the public's imagination and generating an unprecedented 70,000 + inquiries from candidates nationwide. This overwhelming surge highlights a massive, untapped demand for alternative, skills-based training pathways into national security roles.

"To maintain our decisive advantage and support the warfighter on the modern battlefield, the Department of War must recruit differently," said the Honorable Kirsten Davies, Chief Information Officer. "President Trump and Department of War Secretary Hegseth have issued a clear mandate to advance skills-based hiring. This program bypasses traditional academic gatekeeping to value what truly matters: raw aptitude, patriotic drive, and hands-on capability over traditional academic credentials. By unlocking this untapped potential, we are actively forging America's elite cyber workforce of the future from the ground up."

This pilot is a 12-month paid program designed to rapidly develop and employ cyber professionals within the DoW. Apprentices will receive rigorous, competency-based education that blends online learning, immersive hands-on labs, and on-the-job training under the guidance of senior DoW mentors. Successful completion provides industry-recognized certifications and direct pathways into high-demand DoW civilian cyber roles, such as Cyber Defense Analysts and Incident Responders. These professionals will be on the front lines, ensuring the cybersecurity of DoW operations and the broader Defense Industrial Base (DIB).

The Department of War is committed to skills-based hiring, offering pathways for talented Americans from all educational backgrounds. No prior professional cyber experience is required—only the raw aptitude and desire to learn. Applicants must be U.S. citizens, at least 18 years of age, able to obtain and maintain a Secret security clearance, and deeply committed to a cyber career.

To accommodate different agency missions and standards, the program offers two distinct developmental pathways. The core Technical Specialist Pathway focuses on rapid, hands-on technical skill acquisition for general DoW civilian cyber roles and explicitly does not require a college degree. Alternatively, the Defense Manpower Data Center (DMDC) Agency Pathway is tailored for specialized placements within the DMDC and requires candidates to hold an accredited degree to meet that specific agency's qualification standards.

For more information on the program and eligibility requirements, applicants can visit the DoW Cyber Apprenticeship Webpage or contact the program office at osd.mc-alex.dod-cio.mbx.cyber-rap@mail.mil.

Tuesday, June 23, 2026

Securing Global Dominance: DoW Unleashes Quantum Defense Strategy to Harden Networks and Empower the Joint Force

The Department of War (DoW) Chief Information Officer, Honorable Kirsten Davies, today announced the release of the DoW Post Quantum Cryptography (PQC) Strategy. This comprehensive, forward-looking plan addresses the urgent need to secure the Department's communications, data, and command and control systems against the emerging threats posed by future quantum computing capabilities.

The Department of War is driving a rapid, enterprise-wide transition to deploy quantum-resistant cryptography on high-impact systems by 2030 and across the entire force by 2031. This aggressive rollout directly aligns with President Donald J. Trump's Executive Order 14409 "Securing the Nation Against Advanced Cryptographic Attacks", placing the DoW at the forefront of the national mandate to protect our highest-value systems. By accelerating this migration now, the DoW is actively neutralizing quantum threats — preventing adversaries from accessing sensitive data, compromising the integrity of systems, or impersonating warfighters.

"Empowering the warfighter is the relentless objective that drives every program," said Hon. Davies. "To deliver on Secretary Hegseth's vision of the most lethal and dominant military force in the world, our networks must be impenetrable. This strategy secures our tactical edge and the safety of our satellite communications and command systems (SATCOM). It builds the interoperability required to rapidly upgrade our cryptography today while ensuring we can adapt at the speed of innovation to counter the threats of tomorrow."

The strategy prioritizes strengthening industry collaboration to drive efficiency across the enterprise. A key element of this is preparing the Defense Industrial Base (DIB) — the engine of the Secretary of War's "Arsenal of Freedom"— for upcoming Federal Acquisition Regulation (FAR) cryptographic compliance. This proactive partnership includes new approaches to accelerate the integration of commercial-off-the-shelf PQC-enabled solutions, ensuring a unified and resilient defense posture while reducing costs to the nation by streamlining testing.

"As we execute this critical modernization, we remain uncompromisingly focused on delivering value for the American people," added Davies. "We are answering the President's call by establishing centralized governance—ensuring we leverage our buying power, eliminate waste, and secure the best possible value for every taxpayer dollar while moving at speed of innovation."

To execute this complex enterprise-wide transition, the strategy maps out five clear, interconnected Lines of Effort:

1. PQC Governance and Integration: Establishing a centralized oversight structure to streamline acquisition and ensure fiscal accountability.

2. Cryptographic Inventory and Planning: Launching an aggressive campaign to scan for vulnerable systems and coordinate migration roadmaps.

3. Technology Acceleration: Developing, testing, and maturing PQC solutions for unique defense needs while collaborating with standards bodies and industry to advance baseline capabilities.

4. Industry Partnership and Enablement: Lowering barriers for commercial partners through initiatives like the "Preparing for Migration to PQC" memo, which enables the rapid intake and adoption of PQC-enabled industry solutions.

5. PQC Migration and Fielding: Physically deploying quantum-resistance across all warfighting domains to secure our systems without slowing mission operations.

With these robust foundations, we will accelerate ahead of the timelines set by Executive Order 14409. This strategy stands as a critical milestone in our mission to forge resilient partnerships and institute a new paradigm for cybersecurity, ensuring that the United States maintains its technological and strategic advantage for decades to come.

The DoW Post-Quantum Cryptography Strategy is available here: https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf

Sunday, September 28, 2025

When the Grid Goes Down: The Hidden Risks of Reliance on Smart Homes & IoT

Picture the lights flicker and fail—not just the lamps and the TV, but the door locks, garage opener, thermostat, baby monitor, security cameras, and the CPAP that keeps a loved one breathing safely through the night. What used to be a routine outage now instantaneously becomes a whole-home systems failure. That’s the paradox of our connected lives: the more “smart” our homes become, the more brittle they can be when the larger power and communications systems we depend on are stressed or fail.

Smart homes—bundles of internet-connected devices that automate comfort, convenience, surveillance, and safety—have moved from novelty to normal. Consumers increasingly use cloud-tethered services for lighting and HVAC, keyless entry, food storage and cooking, irrigation, entertainment, and even medical monitoring. Yet this expanding convenience layer rests on two preconditions that are often fragile in crisis: electricity and connectivity. When the grid goes down or networks are degraded, homes designed to be “frictionless” may quickly become difficult to manage, less secure, and—if medical devices are involved—potentially dangerous.

This essay examines how rising blackout risk intersects with growing household reliance on smart devices. It identifies the vulnerabilities that can emerge when electricity or internet service falter, explores psychological and social dynamics that increase risk, and outlines practical steps households can take to build resilience without abandoning technology’s benefits. It also situates the problem in a broader policy context: a modernizing grid facing weather extremes, aging infrastructure, and cyberthreats at the same time consumers are connecting more devices than ever.

The Modern Smart Home, in Brief

“Smart home” is a catch-all for internet-enabled sensors, appliances, and systems managed via apps, voice assistants, or automation routines. Common examples include smart thermostats, door locks, doorbells and cameras, lighting, smoke and CO alarms, refrigerators and ranges, irrigation controllers, leak sensors, robot vacuums, and an array of health and wellness devices. Adoption has accelerated alongside near-universal smartphone ownership and widespread home broadband access, which serve as the control surface for these devices (Pew Research Center, 2024). The connective tissue—the cloud, Wi-Fi routers, and consumer IoT platforms—unlocks remote control and data-driven automation. But connectivity is also the Achilles’ heel.

While there is debate over the exact percentage of U.S. households with one or more smart devices (estimates vary with definitions and methods), the directional trend is clear: households continue to add connected devices and spend real money doing so, integrating them into everyday routines (Deloitte, 2023; Pew Research Center, 2024). As smart devices proliferate, the number of single points of failure multiplies.

A Grid Under Stress

Electric reliability is no longer a background guarantee in many regions. Multiple factors have combined to elevate outage risk: more frequent and intense heat waves and winter storms, drought-driven wildfires, aging infrastructure, changing generation mixes with different flexibility characteristics, soaring peak demand from electrification and data centers, and transmission build-out that has lagged behind need. The North American Electric Reliability Corporation (NERC) has repeatedly warned that large swaths of the U.S. face elevated risks of supply shortfalls during extreme conditions (NERC, 2024a; NERC, 2024b).

The 2021 Texas winter storm (Winter Storm Uri) remains a stark case study: cascading failures across natural gas supply, generation, and demand response contributed to days-long outages affecting millions; hundreds died from associated causes (FERC, NERC & Regional Entity Staff Report, 2021/2021a). In the West, utilities increasingly employ Public Safety Power Shutoffs (PSPS)—deliberate, precautionary outages to avoid ignitions during wind events—placing reliability and safety into direct tension for high-fire-threat areas (California Public Utilities Commission, 2025). Meanwhile, federal auditors have underscored persistent cyber risks to grid operations and the need to improve coordination across agencies responsible for protecting critical infrastructure (U.S. Government Accountability Office, 2024).

The upshot is not panic but prudence: the probability of localized, multi-hour (and sometimes multi-day) outages has risen for many consumers. That risk profile matters more in a home where locks, life safety, and daily functions depend on power and network availability.

Hidden Vulnerabilities of Smart Homes During Outages

1) Power Dependence Beyond the Obvious

In a conventional home, the lights go out and most other systems either fail “open” (you can still use a mechanical key) or fail safely. In a smart home, more everyday actions may become power-dependent: keyless entry, powered deadbolts, automated garage doors, induction cooktops, networked smoke alarms, and refrigerator health notifications are all electricity-reliant. When backup batteries exist, their runtime may be measured in hours, not days. If a refrigerator warms, stored insulin or other temperature-sensitive medications can spoil—an example of a household-level failure with health implications.

2) Cloud and Connectivity Fragility

Many devices degrade significantly without internet access, even when local power is present (e.g., during ISP outages or cell network congestion). Cloud authentication may block local control; camera recordings that rely on cloud storage stop; voice assistants go silent. If the router or modem lacks backup power, the “brain” of the smart home dies even if the utility outage is brief. Because the value of many devices is tied to remote control and alerts, network loss erodes the core benefit at precisely the wrong time.

3) Security Systems That Fail “Dumb”

Door locks and security devices that depend on apps, hubs, or Wi-Fi can become unresponsive during outages. Some locks default to a failsafe state that is less secure; others remain locked but cannot be operated electronically—problematic if residents have come to rely on phone-as-key and don’t carry physical keys. Garages with disabled openers can trap vehicles; exterior cameras go dark, potentially at times of heightened criminal opportunity in darkened neighborhoods.

4) Medical and Assistive Devices

Smart medical devices—from CPAPs and oxygen concentrators to home dialysis and cardiac monitors—are increasingly integrated with apps and cloud dashboards. The FDA has issued preparedness guidance emphasizing power and supply continuity for such equipment (U.S. Food and Drug Administration, 2024a; 2024b). For households depending on powered devices for therapy or monitoring, a grid failure is not merely inconvenient: it can be life-threatening unless backup power and contingency plans are in place.

5) Cyber-Physical Complications

A sophisticated cyberattack that degrades parts of the grid or targets internet infrastructure can compound physical outages with network disruptions. Government watchdogs have stressed the need to harden operational technology (OT) and improve information sharing to reduce systemic risk across sectors, including energy (U.S. Government Accountability Office, 2024). Consumer IoT itself has known weaknesses—weak default credentials, inconsistent patching, cloud supply-chain dependencies—that can introduce new attack surfaces in the home. CISA has published acquisition guidance to help buyers evaluate and mitigate these risks before devices enter critical workflows (Cybersecurity and Infrastructure Security Agency, 2022).

Psychological and Social Risk Factors

Technology can create an illusion of control. Routines and automations lull us into believing systems will always work as expected. That confidence can displace analog backups and skills: people stop carrying physical keys, forget manual garage releases exist, and never practice “dark mode” living. Outages then become paralyzing rather than inconvenient. There is also a social dimension: outage-wide darkness increases opportunity for opportunistic crimes, while disabled alarms and cameras degrade deterrence and evidence capture. In this way, highly connected homes can become more attractive targets during blackouts unless households plan for degraded states.

Building Household Resilience Without Abandoning Technology

The goal is not to reject smart homes but to design for graceful degradation—ensuring core functions continue when power or internet fail.

1) Redundancy and “Analog First” Mindset

  • Carry physical keys and confirm every exterior door has a mechanical override. If using smart locks, verify battery life and practice manual operation.

  • Keep a manual garage release tool accessible.

  • Maintain non-networked smoke/CO detectors alongside smart versions or ensure the smart model works fully without cloud and has long-life battery backup.

  • For refrigeration, thermometers with audible alarms provide a power-agnostic check; critically, plan for insulated containers and ice to protect medications during extended outages.

2) Power Resilience Layers

  • Router/ONT backup: a dedicated uninterruptible power supply (UPS) for modem, router, and a central hub can keep local control and LAN-only devices running for hours.

  • Device-level batteries: where available, choose devices with swappable batteries or rechargeable packs and keep spares charged.

  • Portable power stations and inverter generators: size solutions for critical loads (medical devices, refrigeration, communications). Operate generators safely, with proper ventilation and transfer switches.

  • Solar + storage: home battery systems paired with rooftop solar can island during outages if configured with critical-load panels; even modest storage can sustain essentials.

  • Car-to-home options: some EVs and hybrid vehicles support export power for essential circuits; understand limits before an emergency.

3) Connectivity Contingencies

  • Multi-path internet: where feasible, maintain failover from cable/fiber to a cellular hotspot (with its own power bank).

  • Prefer devices that retain local control (e.g., via Bluetooth, Zigbee/Z-Wave, Matter over Thread) even when the cloud is down; verify this in documentation.

  • Local storage for cameras (microSD or local NVR) avoids total loss of security visibility when cloud access fails.

4) Smart Device Procurement with Security in Mind

  • Use CISA’s IoT acquisition considerations to evaluate devices: patchability, SBOM/transparency, secure defaults, and offline functionality (CISA, 2022).

  • Change default passwords, enable MFA where supported, and segment IoT devices on a guest or VLAN network to limit lateral risk.

  • Favor vendors with clear update policies and long support windows; avoid orphaned ecosystems.

5) Medical Device Preparedness

  • Ask your clinician and the manufacturer about battery options, runtime, and generator compatibility.

  • Register with your utility and local fire department if someone in the home depends on powered medical devices; many utilities maintain medical baseline or priority restoration lists (FDA, 2024a).

  • Stock spare consumables and practice switching to backup power to reduce transition risk.

6) Practice “Dark Drills”

  • Twice a year, run a two-hour blackout drill: kill the main breaker (if safe to do so) or simulate by unplugging nonessential circuits. Test door access, lighting, communication, refrigeration plans, and medical device continuity.

  • Document a household outage plan: who does what, in what order, and where backups are stored.

Community and Policy Dimensions

Household resilience sits within broader infrastructure choices. Three themes are especially relevant:

  1. Grid hardening and weatherization. Post-event investigations like the Winter Storm Uri report emphasize weatherization across fuel supply and generation, better winter planning, and improved load shed protocols to prevent catastrophic cascades (FERC/NERC, 2021/2021a). Policymakers and regulators must convert lessons learned into enforceable standards and continuous exercises.

  2. Decentralization and microgrids. Community microgrids, critical-facility islands, and neighborhood-level solar-plus-storage can reduce widespread outages and keep essential services operating. Thoughtful interconnection rules and cost-sharing mechanisms can accelerate deployment, but planning must account for cyber and operational risks so that decentralization doesn’t introduce new fragility.

  3. Cybersecurity across sectors. GAO’s 2024 reviews call for improved coordination between CISA and sector risk management agencies and better measurement of cybersecurity practice adoption—particularly for operational technology (U.S. Government Accountability Office, 2024). As consumer IoT expands, clear labeling, minimum security baselines, and long-term support commitments can reduce household exposure and systemic risk.

Finally, public safety shutoffs present a special case: they can save lives by preventing wildfires, but they also shift risk to households—especially those dependent on powered medical devices. Transparent criteria, granular targeting, robust notification systems, and utility-provided support (e.g., community resource centers, device charging, refrigeration) are essential to make PSPS as safe and tolerable as possible (California Public Utilities Commission, 2025).

Conclusion: Designing for Graceful Degradation

Smart homes are here to stay. They can save energy, enhance safety, and simplify life. But when the grid goes down or networks fail, their very intelligence can turn into brittleness if we haven’t designed for failure. The answer is not to abandon technology—it’s to pair it with redundancy, local control, and practiced contingency plans. Treat internet and power like the critical dependencies they are. Choose devices that still function offline. Keep analog fallbacks for entry, cooking, lighting, and signaling. Plan for medical device continuity. Drill the plan.

The smartest home is the one that stays functional when the world outside isn’t. Build for that day, and every other day gets better too.


References

California Public Utilities Commission. (2025). Public Safety Power Shutoffs (PSPS). Retrieved September 2025.

Cybersecurity and Infrastructure Security Agency. (2022). Internet of Things (IoT) acquisition guidance document. U.S. Department of Homeland Security.

Deloitte. (2023). 2023 connectivity and mobile trends survey. Deloitte Insights.

Federal Energy Regulatory Commission, North American Electric Reliability Corporation, & Regional Entity Staff. (2021/2021a). The February 2021 cold weather outages in Texas and the South Central United States: FERC, NERC and Regional Entity staff report. Federal Energy Regulatory Commission.

North American Electric Reliability Corporation. (2024a). 2024 Summer Reliability Assessment. NERC.

North American Electric Reliability Corporation. (2024b). 2024 Long-Term Reliability Assessment. NERC.

Pew Research Center. (2024). Internet and broadband fact sheet. Pew Research Center.

U.S. Food and Drug Administration. (2024a). FDA offers tips about medical devices and natural disasters. U.S. Department of Health and Human Services.

U.S. Food and Drug Administration. (2024b). Emergency preparedness and medical devices: Supply chain recommendations. U.S. Department of Health and Human Services.

U.S. Government Accountability Office. (2024). Electricity markets, grid security and resilience: High-risk series highlights (GAO-24-107231). GAO.

Wednesday, September 24, 2025

Department of War Announces New Cybersecurity Risk Management Construct


Sept. 24, 2025

The Department of War (DoW) today announced the implementation of a groundbreaking Cybersecurity Risk Management Construct (CSRMC), a transformative framework to deliver real-time cyber defense at operational speed. This five-phase construct ensures a hardened, verifiable, continuously monitored, and actively defended environment to ensure that U.S. warfighters maintain technological superiority against rapidly evolving and emerging cyber threats.

Addressing Legacy Shortcomings

The previous Risk Management Framework was overly reliant on static checklists and manual processes that failed to account for operational needs and cyber survivability requirements. These limitations left defense systems vulnerable to sophisticated adversaries and slowed the delivery of secure capabilities to the field.

The CSRMC addresses these gaps by shifting from "snapshot in time" assessments to dynamic, automated, and continuous risk management, enabling cyber defense at the speed of relevance required for modern warfare.

The construct is composed of a five-phase lifecycle and ten foundational tenets.

The Five-Phase Lifecycle

The new construct organizes cybersecurity into five phases aligned to system development and operations:

  1. Design Phase – Security is embedded at the outset, ensuring resilience is built into system architecture.
  2. Build Phase – Secure designs are implemented as systems achieve Initial Operating Capability (IOC).
  3. Test Phase – Comprehensive validation and stress testing are performed prior to Full Operating Capability (FOC).
  4. Onboard Phase – Automated continuous monitoring is activated at deployment to sustain system visibility.
  5. Operations Phase – Real-time dashboards and alerting mechanisms provide immediate threat detection and rapid response.

Ten Foundational Tenets

The CSRMC is grounded in ten core principles:

  • Automation – driving efficiency and scale
  • Critical Controls – identifying and tracking the controls that matter most to cybersecurity
  • Continuous Monitoring and ATO – enabling real-time situational awareness to achieve constant ATO posture
  • DevSecOps – supporting secure, agile development and deployment
  • Cyber Survivability – enabling operations in contested environments
  • Training – upskilling personnel to meet evolving challenges
  • Enterprise Services & Inheritance – reducing duplication and compliance burdens
  • Operationalization – ensuring stakeholders near real-time visibility of cybersecurity risk posture
  • Reciprocity – reuse assessments across systems
  • Cybersecurity Assessments – integrating threat-informed testing to validate security

Delivering Cybersecurity at the Speed of War

By institutionalizing this construct across the Department, the DoW is ensuring cyber survivability and mission assurance in every domain: air, land, sea, space, and cyberspace.

"This construct represents a cultural fundamental shift in how the Department approaches cybersecurity," said Kattie Arrington, performing the duties of the DoW CIO. "With automation, continuous monitoring, and resilience at its core, the CSRMC empowers the DoW to defend against today's adversaries while preparing for tomorrow's challenges."

Sunday, August 31, 2025

Silent Sabotage: The Rising Threat of Cyberattacks on Critical Infrastructure

In modern warfare and terrorism, silence can be more lethal than the roar of an explosion. Cyberattacks on critical infrastructure—those systems underpinning energy, healthcare, transportation, finance, and communication—have emerged as one of the most pressing threats of the 21st century. Unlike traditional assaults, cyber operations leave no craters or smoke plumes. Instead, they quietly paralyze hospitals, darken cities, disrupt fuel pipelines, and sow chaos. The vulnerability of societies that rely on complex digital networks makes cyber sabotage both an attractive and underestimated weapon.


Historical Precedents and Case Studies

Cyber warfare and infrastructure sabotage have moved from theoretical to demonstrable reality. Several high-profile incidents underscore how adversaries can reach into the vital organs of modern society:

  • Stuxnet (2010): Widely believed to have been developed jointly by the United States and Israel, the Stuxnet worm targeted Iranian nuclear centrifuges at Natanz. It represented the first known digital weapon to cause real-world physical destruction, proving that code could achieve what bombs once did (Zetter, 2014).

  • Ukraine Power Grid Attacks (2015, 2016): Hackers attributed to Russian groups infiltrated Ukraine’s electrical grid, causing widespread blackouts affecting hundreds of thousands of citizens (Assante & Lee, 2015). These incidents marked the first confirmed cyberattacks to disable a national power system.

  • WannaCry and NotPetya (2017): While not targeted exclusively at critical infrastructure, these ransomware campaigns spread globally, paralyzing hospitals in the United Kingdom and disrupting logistics companies and shipping giants, leading to billions in damages (Greenberg, 2018).

  • Colonial Pipeline Ransomware (2021): In the United States, a ransomware attack forced the shutdown of a major fuel pipeline, creating panic buying, shortages, and significant economic loss along the East Coast (CISA, 2021).

These cases reveal a trajectory: cyberattacks are growing in frequency, sophistication, and direct impact on civilian life.


Why Infrastructure Is an Attractive Target

Critical infrastructure provides a uniquely vulnerable and symbolically powerful target for adversaries. Unlike military facilities, which are hardened against attack, infrastructure is largely operated by private companies or local governments with limited resources for cybersecurity.

  • High Impact: Interrupting electricity, fuel, or water causes immediate disruptions to millions of people.

  • Psychological Effect: Infrastructure failures undermine public confidence in government and industry, creating fear disproportionate to the actual damage.

  • Geopolitical Leverage: Cyberattacks can serve as coercive tools, allowing hostile states to exert pressure without firing a shot.

  • Low Visibility: Unlike kinetic warfare, cyber sabotage can be cloaked in plausible deniability, complicating retaliation.

In short, infrastructure represents both the lifeblood of modern society and a soft underbelly ripe for exploitation.


Methods of Attack

Cyber operations against infrastructure exploit both technical vulnerabilities and human weakness:

  • Ransomware and Malware: Malicious code encrypts or disrupts systems until ransom is paid, as seen in Colonial Pipeline.

  • Phishing and Social Engineering: Attackers exploit human error to gain access credentials, often the weakest link in the chain.

  • Supply Chain Compromise: Adversaries infiltrate third-party vendors to insert vulnerabilities, as in the SolarWinds breach.

  • Insider Threats: Disgruntled or coerced employees with system access can inflict catastrophic damage.

  • Zero-Day Exploits: Attackers exploit previously unknown software flaws, striking before patches exist.

The methods may differ, but the commonality is disruption through invisibility and stealth.


Potential Consequences of a Major Cyberattack

The cascading consequences of cyberattacks on infrastructure can equal or exceed those of traditional attacks:

  • Energy Grid Failures: Prolonged blackouts could paralyze communication, healthcare, and commerce. A widespread outage during winter could prove deadly.

  • Water Systems: Hackers could manipulate treatment processes, either shutting down supply or contaminating it, creating a public health crisis.

  • Healthcare Systems: Hospitals rely on digital infrastructure for patient care, medical records, and devices. An attack could delay surgeries, disable emergency services, and cost lives.

  • Transportation: Airports, rail systems, and shipping routes all depend on digital coordination. Sabotage could halt supply chains or cause accidents.

  • Financial Systems: Attacks on banks or markets could trigger mass economic panic, collapsing trust in currency and trade.

Thus, cyber sabotage offers adversaries the ability to achieve widespread paralysis without conventional weapons.


Obstacles in Defense and Mitigation

Defending against cyberattacks on infrastructure presents unique challenges:

  • Attribution Difficulties: Determining who launched an attack is often difficult, allowing adversaries to deny involvement.

  • Aging Infrastructure: Much of the world’s grid, water, and transport systems run on outdated technology never designed for cybersecurity.

  • Public-Private Divide: Most infrastructure is privately owned, creating uncertainty about which entities are responsible for defending it.

  • Talent Shortage: There are not enough trained cybersecurity professionals to meet the growing demand.

  • Regulatory Gaps: Standards are inconsistent across industries and nations, leaving critical vulnerabilities unaddressed.

These weaknesses leave societies in a precarious position: highly dependent on technology yet insufficiently protected against those who would weaponize it.


Strategies for Protection

Despite the challenges, meaningful steps can be taken to reduce the risk:

  • Strengthening Public-Private Partnerships: Governments and private companies must share intelligence, resources, and training.

  • Investment in Cyber Hygiene: Regular updates, patches, and system hardening are low-cost but critical measures.

  • Artificial Intelligence and Analytics: AI-driven monitoring systems can detect anomalies and intrusions faster than human analysts.

  • Red Team/Blue Team Exercises: Simulated attacks help organizations stress-test their defenses and identify weaknesses.

  • Legislation and Standards: National governments must enforce minimum cybersecurity standards for industries managing critical systems.

  • International Cooperation: Norms, treaties, and cooperative defense mechanisms must evolve to address globalized cyber threats.

Without such measures, societies risk continuing to lag behind adversaries who innovate faster than defenders can respond.


The Future of Cyber Threats

Looking forward, cyberattacks against infrastructure will likely evolve alongside technological innovation:

  • Hybrid Warfare Integration: Cyber operations will increasingly complement kinetic warfare, creating multi-domain battlefields.

  • AI-Powered Attacks: Just as AI aids defenders, it will empower attackers with self-adaptive malware.

  • Deepfake and Social Engineering: Advanced digital manipulation will compromise decision-makers and disrupt response coordination.

  • Quantum Computing Risks: Once operational, quantum systems could break today’s encryption standards, rendering existing defenses obsolete.

  • Expanding Target List: The rise of smart cities, Internet of Things (IoT) devices, and autonomous systems offers new vulnerabilities to exploit.

The battlefield of the future may be silent, digital, and ubiquitous.


Conclusion

Cyberattacks on critical infrastructure represent one of the most insidious threats of our time. They are silent, deniable, and potentially catastrophic, capable of crippling entire societies without a single bullet fired. The threat is not hypothetical—incidents like Stuxnet, Ukraine’s power grid attacks, and the Colonial Pipeline hack prove that silent sabotage is already here.

To counter this threat, governments, industries, and citizens must acknowledge cyberattacks as a matter of national survival. Investment, vigilance, and international cooperation are paramount. In an age when society’s heartbeat is digital, silence may be the deadliest sound of all.


References

Assante, M. J., & Lee, R. M. (2015). The industrial control system cyber kill chain. SANS Institute.

CISA. (2021). DarkSide ransomware: Best practices for preventing business disruption from ransomware attacks. Cybersecurity and Infrastructure Security Agency.

Greenberg, A. (2018). Sandworm: A new era of cyberwar and the hunt for the Kremlin’s most dangerous hackers. Doubleday.

Zetter, K. (2014). Countdown to Zero Day: Stuxnet and the launch of the world’s first digital weapon. Crown.


Do you want me to also prepare a companion infographic (like the pathogen profiles chart you liked) that maps infrastructure sectors vs. attack types for quick visual impact?

Monday, March 25, 2024

Seven Hackers Associated with Chinese Government Charged with Computer Intrusions Targeting Perceived Critics of China and U.S. Businesses and Politicians

An indictment was unsealed today charging seven nationals of the People’s Republic of China (PRC) with conspiracy to commit computer intrusions and conspiracy to commit wire fraud for their involvement in a PRC-based hacking group that spent approximately 14 years targeting U.S. and foreign critics, businesses, and political officials in furtherance of the PRC’s economic espionage and foreign intelligence objectives.

The defendants are Ni Gaobin (倪高彬), 38; Weng Ming (翁明), 37; Cheng Feng (程锋), 34; Peng Yaowen (彭耀文), 38; Sun Xiaohui (孙小辉), 38; Xiong Wang (熊旺), 35; and Zhao Guangzong (赵光宗), 38. All are believed to reside in the PRC.

“The Justice Department will not tolerate efforts by the Chinese government to intimidate Americans who serve the public, silence the dissidents who are protected by American laws, or steal from American businesses,” said Attorney General Merrick B. Garland. “This case serves as a reminder of the ends to which the Chinese government is willing to go to target and intimidate its critics, including launching malicious cyber operations aimed at threatening the national security of the United States and our allies.”

“Over 10,000 malicious emails, impacting thousands of victims, across multiple continents. As alleged in today’s indictment, this prolific global hacking operation – backed by the PRC government – targeted journalists, political officials, and companies to repress critics of the Chinese regime, compromise government institutions, and steal trade secrets,” said Deputy Attorney General Lisa Monaco. “The Department of Justice will relentlessly pursue, expose, and hold accountable cyber criminals who would undermine democracies and threaten our national security.” 

"Today's announcement exposes China's continuous and brash efforts to undermine our nation's cybersecurity and target Americans and our innovation,” said FBI Director Christopher Wray. "As long as China continues to target the US and our partners, the FBI will continue to send a clear message that cyber espionage will not be tolerated, and we will tirelessly pursue those who threaten our nation’s security and prosperity. This indictment underscores our unwavering commitment to disrupt and deter malicious cyber activity, and safeguard our citizens, businesses, and critical infrastructure from threats in cyberspace."

“The indictment unsealed today, together with statements from our foreign partners regarding related activity, shed further light on the PRC Ministry of State Security’s aggressive cyber espionage and transnational repression activities worldwide,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division. “Today’s announcements underscore the need to remain vigilant to cybersecurity threats and the potential for cyber-enabled foreign malign influence efforts, especially as we approach the 2024 election cycle. The Department of Justice will continue to leverage all tools to disrupt malicious cyber actors who threaten our national security and aim to repress fundamental freedoms worldwide.”

“These allegations pull back the curtain on China’s vast illegal hacking operation that targeted sensitive data from U.S. elected and government officials, journalists, and academics; valuable information from American companies; and political dissidents in America and abroad. Their sinister scheme victimized thousands of people and entities across the world, and lasted for well over a decade,” said U.S. Attorney Breon Peace for the Eastern District of New York. “America’s sovereignty extends to its cyberspace. Today’s charges demonstrate my office’s commitment to upholding and protecting that jurisdiction, and to putting an end to malicious nation state cyber activity.”

“The recent indictments against the Chinese actors reaffirm the FBI’s relentless dedication to combating cyber threats,” said Assistant Director Bryan Vorndran of the FBI Cyber Division. “They serve as a reminder that cyber adversaries who seek to compromise our nation’s systems and target US officials cannot rely on the cloak of anonymity and will face consequences for their actions.”

“APT31 Group’s practices further demonstrate the size and scope of the PRC’s state-sponsored hacking apparatus,” said Special Agent in Charge Robert W. “Wes” Wheeler Jr. of the FBI Chicago Field Office. “FBI Chicago worked tirelessly to uncover this complex web of alleged foreign intelligence and economic espionage crimes. Thanks to these efforts, as well as our partnerships with the U.S. Attorneys’ Offices and fellow Field Offices, the FBI continues to be successful in holding groups accountable and protecting national security.”

Overview

As alleged in the indictment and court filings, the defendants, along with dozens of identified PRC Ministry of State Security (MSS) intelligence officers, contractor hackers, and support personnel, were members of a hacking group operating in the PRC and known within the cybersecurity community as Advanced Persistent Threat 31 (the APT31 Group). The APT31 Group was part of a cyberespionage program run by the MSS’s Hubei State Security Department, located in the city of Wuhan. Through their involvement with the APT31 Group, since at least 2010, the defendants conducted global campaigns of computer hacking targeting political dissidents and perceived supporters located inside and outside of China, government and political officials, candidates, and campaign personnel in the United States and elsewhere and American companies.

The defendants and others in the APT31 Group targeted thousands of U.S. and foreign individuals and companies. Some of this activity resulted in successful compromises of the targets’ networks, email accounts, cloud storage accounts, and telephone call records, with some surveillance of compromised email accounts lasting many years.

Hacking Scheme

The more than 10,000 malicious emails that the defendants and others in the APT31 Group sent to these targets often appeared to be from prominent news outlets or journalists and appeared to contain legitimate news articles. The malicious emails contained hidden tracking links, such that if the recipient simply opened the email, information about the recipient, including the recipient’s location, internet protocol (IP) addresses, network schematics, and specific devices used to access the pertinent email accounts, was transmitted to a server controlled by the defendants and those working with them. The defendants and others in the APT31 Group then used this information to enable more direct and sophisticated targeted hacking, such as compromising the recipients’ home routers and other electronic devices.

The defendants and others in the APT31 Group also sent malicious tracking-link emails to government officials across the world who expressed criticism of the PRC government. For example, in or about 2021, the conspirators targeted the email accounts of various foreign government individuals who were part of the Inter-Parliamentary Alliance on China (IPAC), a group founded in 2020 on the anniversary of the 1989 Tiananmen Square protests whose stated purpose was to counter the threats posed by the Chinese Communist Party to the international order and democratic principles. The targets included every European Union member of IPAC, and 43 United Kingdom parliamentary accounts, most of whom were members of IPAC or had been outspoken on topics relating to the PRC government.

To gain and maintain access to the victim computer networks, the defendants and others in the APT31 Group employed sophisticated hacking techniques including zero-day exploits, which are exploits that the hackers became aware of before the manufacturer, or the victim were able to patch or fix the vulnerability. These activities resulted in the confirmed and potential compromise of economic plans, intellectual property, and trade secrets belonging to American businesses, and contributed to the estimated billions of dollars lost every year as a result of the PRC’s state-sponsored apparatus to transfer U.S. technology to the PRC.

Targeting of U.S. Government Officials and U.S. and Foreign Politicians and Campaigns

The targeted U.S. government officials included individuals working in the White House, at the Departments of Justice, Commerce, Treasury, and State, and U.S. Senators and Representatives of both political parties. The defendants and others in the APT31 Group targeted these individuals at both professional and personal email addresses. Additionally in some cases, the defendants also targeted victims’ spouses, including the spouses of a high-ranking Department of Justice official, high-ranking White House officials, and multiple U.S. Senators. Targets also included election campaign staff from both major U.S. political parties in advance of the 2020 election.

The allegations in the indictment regarding the malicious cyber activity targeting political officials, candidates, and campaign personnel are consistent with the March 2021 Joint Report of the Department of Justice and the Department of Homeland Security on Foreign Interference Targeting Election Infrastructure or Political Organization, Campaign, or Candidate Infrastructure Related to the 2020 US Federal Elections. That report cited incidents when Chinese government-affiliated actors “materially impacted the security of networks associated with or pertaining to U.S. political organizations, candidates, and campaigns during the 2020 federal elections.” That report also concluded that “such actors gathered at least some information they could have released in influence operations,” but which the Chinese actors did not ultimately deploy in such a manner. Consistent with that conclusion, the indictment does not allege that the hacking furthered any Chinese government influence operations against the United States. The indictment’s allegations nonetheless serve to underscore the need for U.S. (and allied)

 olitical organizations, candidates, and campaigns to remain vigilant in their cybersecurity posture and in otherwise protecting their sensitive information from foreign intelligence services, particularly in light of the U.S. Intelligence Community’s recent “[t]he PRC may attempt to influence the U.S. elections in 2024 at some level because of its desire to sideline critics of China and magnify U.S. societal divisions.”

Targeting of U.S. Companies

The defendants and others in the APT31 Group also targeted individuals and dozens of companies operating in areas of national economic importance, including the defense, information technology, telecommunications, manufacturing and trade, finance, consulting, legal, and research industries. The defendants and others in the APT31 Group hacked and attempted to hack dozens of companies or entities operating in these industries, including multiple cleared defense contractors who provide products and services to the U.S. military, multiple managed service providers who managed the computer networks and security for other companies, a leading provider of 5G network equipment, and a leading global provider of wireless technology, among many others.

Targeting for Transnational Repression of Dissidents

The defendants and the APT31 Group also targeted individual dissidents around the world and other individuals who were perceived as supporting such dissidents. For example, in 2018, after several activists who spearheaded Hong Kong’s Umbrella Movement were nominated for the Nobel Peace Prize, the defendants and the APT31 Group targeted Norwegian government officials and a Norwegian managed service provider. The conspirators also successfully compromised Hong Kong pro-democracy activists and their associates located in Hong Kong, the United States, and other foreign locations with identical malware.

The charged defendants’ roles in the conspiracy consisted of testing and exploiting the malware used to conduct these intrusions, managing infrastructure associated with these intrusions, and conducting surveillance and intrusions against specific U.S. entities. For example:

  • Cheng Feng, Sun Xiaohui, Weng Ming, Xiong Wang, and Zhao Guangzong were involved in testing and exploiting malware, including malware used in some of these intrusions.
  • Cheng and Ni Gaobin managed infrastructure associated with some of these intrusions, including the domain name for a command-and-control server that accessed at least 59 unique victim computers, including a telecommunications company that was a leading provider of 5G network equipment in the United States, an Alabama-based research corporation in the aerospace and defense industries, and a Maryland-based professional support services company.
  • Sun and Weng operated the infrastructure used in an intrusion into a U.S. company known for its public opinion polls. Sun and Peng Yaowen conducted research and reconnaissance on several additional U.S. entities that were later the victims of the APT31 Group’s intrusion campaigns.
  • Ni and Zhao sent emails with links to files containing malware to PRC dissidents, specifically Hong Kong legislators and democracy advocates, as well as targeting U.S. entities focusing on PRC-related issues.

Assistant U.S. Attorneys Douglas M. Pravda, Saritha Komatireddy, and Jessica Weigel for the Eastern District of New York are prosecuting the case, with valuable assistance from Matthew Anzaldi and Matthew Chang of the National Security Division’s National Security Cyber Section.

An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Thursday, June 22, 2023

Unveiling the Threat: Social Engineering and its Impact on Cybersecurity


In today's interconnected world, where technology permeates every aspect of our lives, the threat landscape has expanded beyond traditional cybersecurity measures. Social engineering has emerged as a potent weapon in the hands of cybercriminals, exploiting human psychology to bypass technical defenses and gain unauthorized access to sensitive information. In this article, we explore the concept of social engineering, its various techniques, and the critical role it plays in compromising cybersecurity. By understanding the tactics employed by cyber attackers, we can better equip ourselves to recognize and counter social engineering attempts, safeguarding our personal and organizational security.

Understanding Social Engineering:

Social engineering refers to the manipulation of human behavior, often through psychological manipulation or deception, to gain unauthorized access to information or systems. Unlike traditional hacking methods that exploit technical vulnerabilities, social engineering exploits human vulnerabilities, such as trust, curiosity, or fear. It relies on the fact that individuals can be the weakest link in the security chain, making them susceptible to manipulation and trickery.

Common Techniques of Social Engineering:

  1. Phishing: Phishing is one of the most prevalent social engineering techniques. Attackers send deceptive emails, messages, or fake websites that appear legitimate, aiming to trick users into revealing sensitive information such as passwords, financial details, or login credentials. Phishing attacks often employ urgency, fear, or enticing offers to manipulate users into taking action without suspicion.

  2. Pretexting: Pretexting involves creating a fictional scenario or pretext to manipulate individuals into divulging sensitive information. Attackers may pose as legitimate entities, such as technical support personnel, law enforcement officers, or trusted colleagues, to gain trust and extract confidential data or access to systems.

  3. Baiting: Baiting involves enticing individuals with an appealing offer or reward in exchange for their personal information or access. Cybercriminals may use physical devices, such as infected USB drives labeled as "free giveaways" or attractive download links, to lure victims into compromising their security unwittingly.

  4. Tailgating: Tailgating, also known as piggybacking, involves unauthorized individuals gaining physical access to restricted areas by closely following authorized personnel. By exploiting human courtesy or assuming false identities, attackers gain entry to secure environments without proper authentication.

The Impact on Cybersecurity:

Social engineering attacks can have severe consequences, both for individuals and organizations. They can lead to data breaches, financial loss, identity theft, and damage to reputation. Beyond immediate losses, successful social engineering attacks can also serve as gateways for more extensive cyberattacks, allowing hackers to penetrate deeper into systems, steal intellectual property, or disrupt critical infrastructure.

Defending Against Social Engineering Attacks:

  1. Awareness and Education: Training individuals on social engineering techniques and raising awareness about common attack vectors are crucial. By understanding the tactics used by attackers, individuals can develop a healthy skepticism, verify requests, and practice cautious online behavior.

  2. Vigilance in Communication: Verifying the authenticity of communication sources, especially in unsolicited emails, messages, or phone calls, is essential. Independent verification through trusted channels, using contact information from official sources, helps to avoid falling victim to impersonation or deceptive tactics.

  3. Implementing Multifactor Authentication: Enforcing strong and unique passwords combined with multifactor authentication adds an extra layer of security, making it more challenging for attackers to gain unauthorized access.

  4. Regular Software Updates and Security Patches: Keeping software, operating systems, and security tools up to date minimizes the risk of known vulnerabilities that can be exploited by social engineering attacks.

Conclusion:

As the digital landscape continues to evolve, social engineering remains a persistent threat to cybersecurity. By understanding the techniques employed by cyber attackers, individuals and organizations can enhance their defenses and protect against these manipulative tactics. A combination of awareness, education, and robust security measures is crucial in mitigating the risks associated with social engineering. By staying vigilant and fostering a security-conscious culture, we can fortify our digital resilience and safeguard against the ever-evolving social engineering landscape.

Friday, October 30, 2015

Cybersecurity program shapes mission assurance for AF core missions



Task Force Cyber Secure / Published October 29, 2015

WASHINGTON (AFNS) -- Task Force Cyber Secure has made progress in addressing mission assurance and cybersecurity challenges for Air Force core missions, according to Air Force leaders.

The initiative, originally enacted by Air Force Chief of Staff Gen. Mark A. Welsh III, aims to synchronize cybersecurity efforts across the Air Force enterprise to improve the security of information and warfighting systems with a special focus on the five core missions.

“With close partnership from key cyber and core mission stakeholders across the Air Force, we've jump started, and will continue to lead, many efforts that will eventually provide Air Force commanders with the personnel and TTPs (tactics, techniques and procedures) who will assure their missions in and through cyberspace," said Peter Kim, the TFCS director.

Although October’s National Cyber Security Awareness Month is coming to a close, it is still important to keep in mind the majority of cybersecurity breaches within the Air Force systems due to poor cyber hygiene habits.

TFCS and the Air Force are measuring cyber hygiene to identify how Airmen can better protect themselves and the mission. Providing commanders with the tools to understand their cyberspace readiness and make necessary changes is an important part of this process.

The task force developed a process to fund and execute critical short-term projects focused on assuring core missions in, through and from cyberspace. TFCS has fully funded and executed the first round of these investments, called near-term initiatives (NTIs), which deliver cyber capabilities focused on enhancing cybersecurity of mission systems.

These investments included improvements to cyber force development, enhancements to the communications infrastructure for rapid global mobility at Scott Air Force Base, Illinois, and an insider threat project for user activity monitoring and pilot programs at Air Force Material Command that would improve the cybersecurity of operational flight programs and portable maintenance aids.

The second round resulted in additional NTIs being fully funded. Some of the initiatives included a cyber-defense operating concept for space superiority that will be applied across all Air Force missions, development of team cyber assure and the cyber awareness assessment, development of the cyber squadron of the future, development of the director of cyber forces concept, and initiatives to protect industrial control systems and pave the way for AFMC to increase the cyber resiliency of weapons systems.

"We must continue to focus on enhancing the security of our Air Force core missions and weapon systems, not just the traditional networks, and continue to institute that culture change in our Airmen to understand the cybersecurity impacts to mission,” said Air Force Chief Information Officer Lt. Gen. William J. Bender.